Authorizing base station flows to and from ThingPark
This topic describes the required flows to authorize in your base station deployment environment, such as proxies, firewalls... These flows allow base stations to exchange traffic with ThingPark core network, as well as external time-synchronization servers.
For ThingPark SaaS deployments
Tip
For more information about the FQDN of SaaS nodes (SLRC, SLRC (LNS-BRIDGE), LRC, SUPPORT and PROXY_HTTP servers), see Per-platform FQDN list.
LRR flows when IPsec is used
# | From (system) | From (application) | Type | Protocol | Dest. Port | To (system) | To (application) | Description |
---|---|---|---|---|---|---|---|---|
i6 | BASE STATION | strongswan (client) | Bidirectional | IKE v2 (secure) MOBIKE v2 (secure) | UDP/500 UDP/4500 | SLRC | strongswan | IPsec IKE (UDP) / MOBIKE (UDP) ike=aes128-sha256-ecp256,aes128-sha384-ecp384,aes256-sha512-ecp521 |
i7 | BASE STATION | strongswan (client) | Bidirectional | ESP (secure) | - | SLRC | strongswan | ESP (protocol 50) ike=aes128-sha256-ecp256,aes128-sha384-ecp384,aes256-sha512-ecp521 esp=aes128gcm128,aes256gcm128 |
i7a | BASE STATION | openssl | Unidirectional | TLS | TCP/3001 TCP/3002 TCP/3003 | SLRC | haproxy | Check certificate validity on server side (only applicable to LRR version ≥ 2.8) |
i8a | BASE STATION | OS | Unidirectional | ICMP | - | SLRC | OS | Ping (SLRC) |
i10 | BASE STATION | OS | Unidirectional | DNS | UDP/53 | DNS service | service | DNS request. Note OPTIONAL, to be evaluated according to the access network. |
i11 | BASE STATION | OS | Unidirectional | DHCP | - | DHCP service | service | DHCP request. Note OPTIONAL, to be evaluated according to the access network. |
i11b | BASE STATION | Key installer (client) | Unidirectional | SFTP | TCP/22 | SLRC | key-installer (openssh) | SFTP access to download X.509 certificate |
i9 | BASE STATION | OS | Unidirectional | SSH v2 (secure) | TCP/22 | SUPPORT | OS | Reverse LRR administration |
i17 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | NTP service | OS | LRR NTP request |
LRR flows when TLS is used
# | From (system) | From (application) | Type | Protocol | Dest. Port | To (system) | To (application) | Description |
---|---|---|---|---|---|---|---|---|
i7a | BASE STATION | stunnel | Unidirectional | TLS | TCP/3001 TCP/3002 TCP/3003 | SLRC | haproxy | TLS tunnels to respectively LRC:2404 (i14), LRC:22 (i15b), SUPPORT:22 (i17d) |
i8a | BASE STATION | OS | Unidirectional | ICMP | - | SLRC | OS | Ping (SLRC) |
i10 | BASE STATION | OS | Unidirectional | DNS | UDP/53 | DNS service | service | DNS request. Note OPTIONAL, to be evaluated according to the access network. |
i11 | BASE STATION | OS | Unidirectional | DHCP | - | DHCP service | service | DHCP request. Note OPTIONAL, to be evaluated according to the access network. |
i11b | BASE STATION | Key installer (client) | Unidirectional | SFTP | TCP/22 | SLRC | key-installer (openssh) | SFTP access to download X.509 certificate |
i9 | BASE STATION | OS | Unidirectional | SSH v2 (secure) | TCP/22 | SUPPORT | OS | Reverse LRR administration |
i17 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | NTP service | OS | LRR NTP request |
Basics Station flows (always with TLS)
# | From (system) | From (application) | Type | Protocol | Dest. Port | To (system) | To (application) | Description |
---|---|---|---|---|---|---|---|---|
i10 | BASE STATION | OS | Unidirectional | DNS | UDP/53 | DNS service | service | DNS request. Note OPTIONAL, to be evaluated according to the access network. |
i11 | BASE STATION | OS | Unidirectional | DHCP | - | DHCP service | service | DHCP request. Note OPTIONAL, to be evaluated according to the access network. |
i11c | BASE STATION | Semtech Basics Station | Unidirectional | HTTPS/WSS | TCP/443 | SLRC (LNS-BRIDGE) | haproxy | LNS interface to LRC LNS-BRIDGE |
i11d | BASE STATION | Semtech Basics Station | Unidirectional | HTTPS / TLS v1.2 (secure) | TCP/443 | PROXY_HTTP | proxy | CUPS interface to AS_RCA |
i17 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | NTP service | service | LRR NTP request |
Per-platform FQDN list
SaaS platform | SLRC FQDN | SLRC (LNS-BRIDGE) FQDN | LRC FQDN | SUPPORT FQDN | PROXY_HTTP FQDN |
---|---|---|---|---|---|
EU-PROD | slrc1.eu.thingpark.com slrc2.eu.thingpark.com | lns.eu.thingpark.com | lrc1-tpe-eu.thingpark.com lrc2-tpe-eu.thingpark.com | support1.eu.thingpark.com support2.eu.thingpark.com | thingparkenterprise.eu.actility.com |
AU-PROD | slrc1-au1.thingpark.com slrc2-au1.thingpark.com | lns.au.thingpark.com | lrc1-tpe-au1.thingpark.com lrc2-tpe-au1.thingpark.com | support1-au1.thingpark.com support2-au1.thingpark.com | thingparkenterprise.au.actility.com |
US-PROD | slrc1-us.thingpark.com slrc2-us.thingpark.com | lns.us.thingpark.com | lrc1-tpe-us.thingpark.com lrc2-tpe-us.thingpark.com | support1-us.thingpark.com support2-us.thingpark.com | thingparkenterprise.us.actility.com |
ThingPark Community | slrc1-poc.thingpark.com slrc2-poc.thingpark.com | lns.thingpark.com | lrc1-dev.thingpark.com lrc2-dev.thingpark.com | support1-poc.thingpark.com support2-poc.thingpark.com | community.thingpark.io |
EU-PREPROD | slrc1.eu-preprod.thingpark.com slrc2.eu-preprod.thingpark.com | lns.eu-preprod.thingpark.com | lrc1-eu-preprod.thingpark.com lrc2-eu-preprod.thingpark.com | support1-eu-preprod.thingpark.com support2-eu-preprod.thingpark.com | thingparkenterprise-preprod.eu.actility.com |
AU-PREPROD | slrc1-au1-preprod.thingpark.com slrc2-au1-preprod.thingpark.com | lns.au-preprod.thingpark.com | lrc1-au1-preprod.thingpark.com lrc2-au1-preprod.thingpark.com | support1-au1-preprod.thingpark.com support2-au1-preprod.thingpark.com | thingparkenterprise-preprod.au.actility.com |
For self-hosted deployments
LRR flows when IPsec is used
# | From (system) | From (application) | Type | Protocol | Dest. Port | To (system) | To (application) | Description | STANDALONE | HIGH AVAILABILITY |
---|---|---|---|---|---|---|---|---|---|---|
i1 | BASE STATION | strongswan (client) | Bidirectional | IKE v2 (secure) MOBIKE v2 (secure) | UDP/500 UDP/4500 | TPE | strongswan | IPsec IKE (UDP) / MOBIKE (UDP) ike=aes128-sha256-ecp256,aes128-sha384-ecp384,aes256-sha512-ecp521 | MUST | MUST |
i2 | BASE STATION | strongswan (client) | Bidirectional | ESP (secure) | - | TPE | strongswan | ESP (protocol 50) ike=aes128-sha256-ecp256,aes128-sha384-ecp384,aes256-sha512-ecp521 esp=aes128gcm128,aes256gcm128 | MUST | MUST |
i3 | BASE STATION | OS | Unidirectional | ICMP | - | TPE | OS | Ping (TPE) | MUST | MUST |
i4 | BASE STATION | Key installer (client) | Unidirectional | SFTP | TCP/22 | TPE | Key installer (server) | SFTP protocol | MUST | MUST |
i5 | BASE STATION | OS | Unidirectional | SSH v2 (secure) | TCP/22 | TPE | OS | LRR admin (Reverse SSH) | MUST | MUST |
i38 | BASE STATION | OS | Unidirectional | TLS | TCP/3001 | TPE | server | Check certificate validity on server side (only applicable to LRR version ≥ 2.8) | MUST | MUST |
i39 | BASE STATION | OS | Unidirectional | TLS | TCP/3002 | TPE | server | Check certificate validity on server side (only applicable to LRR version ≥ 2.8) | MUST | MUST |
i40 | BASE STATION | OS | Unidirectional | TLS | TCP/3003 | TPE | OS | Check certificate validity on server side (only applicable to LRR version ≥ 2.8) | MUST | MUST |
n1 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | NTP service | service | NTP requests when TPE is not used for NTP | OPTIONAL | OPTIONAL |
n2 | BASE STATION | OS | Unidirectional | DNS | UDP/53 | DNS service | service | DNS requests | OPTIONAL | OPTIONAL |
n3 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | TPE | NTP service | NTP requests when TPE is used for NTP | OPTIONAL | OPTIONAL |
n4 | BASE STATION | OS | Unidirectional | DHCP | - | DHCP service | service | DHCP request | OPTIONAL | OPTIONAL |
LRR flows when TLS is used
# | From (system) | From (application) | Type | Protocol | Dest. Port | To (system) | To (application) | Description | STANDALONE | HIGH AVAILABILITY |
---|---|---|---|---|---|---|---|---|---|---|
i3 | BASE STATION | OS | Unidirectional | ICMP | - | TPE | OS | Ping (TPE) | MUST | MUST |
i4 | BASE STATION | Key installer (client) | Unidirectional | SFTP | TCP/22 | TPE | Key installer (server) | SFTP protocol | MUST | MUST |
i5 | BASE STATION | OS | Unidirectional | SSH v2 (secure) | TCP/22 | TPE | OS | LRR admin (Reverse SSH) | MUST | MUST |
i38 | BASE STATION | OS | Unidirectional | IEC 104 over TLS (secure) | TCP/3001 | TPE | server | LRR IEC 104 link: LRR commands and LoRa uplink/donwlink data and metadata exchange. | MUST | MUST |
i39 | BASE STATION | OS | Unidirectional | SFTP over TLS (secure) | TCP/3002 | TPE | server | LRR sofware download LRR sofware configuration download | MUST | MUST |
i40 | BASE STATION | OS | Unidirectional | SFTP over TLS (secure) | TCP/3003 | TPE | OS | LRR rf scan upload LRR software configuration upload | MUST | MUST |
n1 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | NTP service | service | NTP requests when TPE is not used for NTP | OPTIONAL | OPTIONAL |
n2 | BASE STATION | OS | Unidirectional | DNS | UDP/53 | DNS service | service | DNS requests | OPTIONAL | OPTIONAL |
n3 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | TPE | NTP service | NTP requests when TPE is used for NTP | OPTIONAL | OPTIONAL |
n4 | BASE STATION | OS | Unidirectional | DHCP | - | DHCP service | service | DHCP request | OPTIONAL | OPTIONAL |
LRR flows when neither IPsec nor TLS is used
# | From (system) | From (application) | Type | Protocol | Dest. Port | To (system) | To (application) | Description | STANDALONE | HIGH AVAILABILITY |
---|---|---|---|---|---|---|---|---|---|---|
i3 | BASE STATION | OS | Unidirectional | ICMP | - | TPE | OS | Ping (TPE) | MUST | MUST |
i5 | BASE STATION | OS | Unidirectional | SSH v2 (secure) | TCP/22 | TPE | OS | LRR admin (Reverse SSH) | MUST | MUST |
i6 | BASE STATION | OS | Unidirectional | IEC 104 | TCP/2404 | TPE | server | LRR IEC 104 link: LRR commands and LoRa uplink/donwlink data and metadata exchange. | MUST | MUST |
i7 | BASE STATION | OS | Unidirectional | FTP | TCP/21 | TPE | server | LRR sofware download LRR sofware configuration download. | MUST | MUST |
i8 | BASE STATION | OS | Unidirectional | FTP | TCP/21 | TPE | OS | LRR rf scan upload LRR software configuration upload | MUST | MUST |
n1 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | NTP service | service | NTP requests when TPE is not used for NTP | OPTIONAL | OPTIONAL |
n2 | BASE STATION | OS | Unidirectional | DNS | UDP/53 | DNS service | service | DNS requests | OPTIONAL | OPTIONAL |
n3 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | TPE | NTP service | NTP requests when TPE is used for NTP | OPTIONAL | OPTIONAL |
n4 | BASE STATION | OS | Unidirectional | DHCP | - | DHCP service | service | DHCP request | OPTIONAL | OPTIONAL |
Basics Station flows (always with TLS)
# | From (system) | From (application) | Type | Protocol | Dest. Port | To (system) | To (application) | Description | STANDALONE | HIGH AVAILABILITY |
---|---|---|---|---|---|---|---|---|---|---|
i42 | BASE STATION | Semtech Basics Station | Unidirectional | HTTPS/WSS | TCP/4443 | TPE | haproxy | LNS interface | MUST | MUST |
i43 | BASE STATION | Semtech Basics Station | Unidirectional | HTTP+TLS v1.2 (secure) | TCP/443 | TPE | RCA | CUPS interface | MUST | MUST |
n1 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | NTP service | service | NTP requests when TPE is not used for NTP | OPTIONAL | OPTIONAL |
n2 | BASE STATION | OS | Unidirectional | DNS | UDP/53 | DNS service | service | DNS requests | OPTIONAL | OPTIONAL |
n3 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | TPE | NTP service | NTP requests when TPE is used for NTP | OPTIONAL | OPTIONAL |
n4 | BASE STATION | OS | Unidirectional | DHCP | - | DHCP service | service | DHCP request | OPTIONAL | OPTIONAL |