Skip to main content

Authorizing base station flows to and from ThingPark core network

If using a SaaS platform, this topic describes the required flows to authorize in your base station deployment environment, such as proxies, firewalls... These flows allow base stations to exchange traffic with ThingPark core network, as well as external time-synchronization servers.

LRR flows when IPsec is used

#From (system)From (application)TypeProtocolDest. PortTo (system)To (application)Description
i6BASE STATIONstrongswan (client)BidirectionalIKE v2 (secure) MOBIKE v2 (secure)UDP/500 UDP/4500SLRCstrongswanIPsec IKE (UDP) / MOBIKE (UDP) ike=aes128-sha256-ecp256,aes128-sha384-ecp384,aes256-sha512-ecp521
i7BASE STATIONstrongswan (client)BidirectionalESP (secure)-SLRCstrongswanESP (protocol 50) ike=aes128-sha256-ecp256,aes128-sha384-ecp384,aes256-sha512-ecp521 esp=aes128gcm128,aes256gcm128
i7aBASE STATIONstunnelUnidirectionalTLSTCP/3001 TCP/3002 TCP/3003SLRChaproxyCheck certificate validity on server side (only applicable to LRR version >= 2.8)
i8aBASE STATIONOSUnidirectionalICMP-SLRCOSPing (SLRC)
i10BASE STATIONOSUnidirectionalDNSUDP/53DNS serviceserviceDNS request.
Note OPTIONAL, to be evaluated according to the access network.
i11BASE STATIONOSUnidirectionalDHCP-DHCP serviceserviceDHCP request.
Note OPTIONAL, to be evaluated according to the access network.
i11bBASE STATIONKey installer (client)UnidirectionalSFTPTCP/22SLRCkey-installer (openssh)SFTP access to download X.509 certificate
i9BASE STATIONOSUnidirectionalSSH v2 (secure)TCP/22SUPPORTOSReverse LRR administration
i17BASE STATIONOSUnidirectionalNTPUDP/123NTP serviceOSLRR NTP request

LRR flows when TLS is used

#From (system)From (application)TypeProtocolDest. PortTo (system)To (application)Description
i7aBASE STATIONstunnelUnidirectionalTLSTCP/3001 TCP/3002 TCP/3003SLRChaproxyTLS tunnels to respectively LRC:2404 (i14), LRC:22 (i15b), SUPPORT:22 (i17d)
i8aBASE STATIONOSUnidirectionalICMP-SLRCOSPing (SLRC)
i10BASE STATIONOSUnidirectionalDNSUDP/53DNS serviceserviceDNS request.
Note OPTIONAL, to be evaluated according to the access network.
i11BASE STATIONOSUnidirectionalDHCP-DHCP serviceserviceDHCP request.
Note OPTIONAL, to be evaluated according to the access network.
i11bBASE STATIONKey installer (client)UnidirectionalSFTPTCP/22SLRCkey-installer (openssh)SFTP access to download X.509 certificate
i9BASE STATIONOSUnidirectionalSSH v2 (secure)TCP/22SUPPORTOSReverse LRR administration
i17BASE STATIONOSUnidirectionalNTPUDP/123NTP serviceOSLRR NTP request

LRR flows when neither IPsec nor TLS is used

#From (system)From (application)TypeProtocolDest. PortTo (system)To (application)Description
i10BASE STATIONOSUnidirectionalDNSUDP/53DNS serviceserviceDNS request. Note Optional, to be evaluated according to the access network.
i11BASE STATIONOSUnidirectionalDHCP-DHCP serviceserviceDHCP request Note OPTIONAL, to be evaluated according to the access network.
i9BASE STATIONOSUnidirectionalSSH v2 (secure)TCP/22SUPPORTOSReverse LRR administration
i14BASE STATIONOSUnidirectionalIEC 104TCP/2404LRCserverLRR IEC 104 link: LRR commands and LoRa uplink/donwlink data and metadata exchange.
i15BASE STATIONOSUnidirectionalFTPTCP/21LRCserverLRR sofware download LRR sofware configuration download.
i15bBASE STATIONOSUnidirectionalSFTP (secure)TCP/22LRCserverLRR sofware download LRR sofware configuration download.
i17BASE STATIONOSUnidirectionalNTPUDP/123NTP serviceserviceLRR NTP request
i17bBASE STATIONOSUnidirectionalICMP-LRCOSLRR Ping
i17cBASE STATIONOSUnidirectionalFTPTCP/21SUPPORTOSLRR rf scan upload LRR software configuration upload
i17dBASE STATIONOSUnidirectionalSFTP (secure)TCP/22SUPPORTOSLRR rf scan upload LRR software configuration upload

Basics™ Station flows (always with TLS)

#From (system)From (application)TypeProtocolDest. PortTo (system)To (application)Description
i10BASE STATIONOSUnidirectionalDNSUDP/53DNS serviceserviceDNS request. Note OPTIONAL, to be evaluated according to the access network.
i11BASE STATIONOSUnidirectionalDHCP-DHCP serviceserviceDHCP request. Note OPTIONAL, to be evaluated according to the access network.
i11cBASE STATIONSemtech Basics StationUnidirectionalHTTPS/WSSTCP/443SLRChaproxyLNS interface to LRC LNS-BRIDGE
i11dBASE STATIONSemtech Basics StationUnidirectionalHTTPS / TLS v1.2 (secure)TCP/443PROXY_HTTPproxyCUPS interface to AS_RCA
i17BASE STATIONOSUnidirectionalNTPUDP/123NTP serviceserviceLRR NTP request