Celona Access Points, Cloud core and Celona Orchestrator must communicate over the existing enterprise LAN/WAN infrastructure to enable zero-touch provisioning and cloud-based management of the Private Wireless network. For seamless Day 0 & Day N operations of the Celona Private Wireless network, enterprise firewalls must be configured to allow specific discovery, management, provisioning, and troubleshooting functions.
Please refer to the following tables for detailed firewall configurations to allow communication between Celona AP, Cloud core, and Orchestrator.
Outbound Access Point to Internet
URL (DNS) / IP Address | Port | Protocol | Purpose |
cso.celona.io | 443 | TCP | Discovery, Configuration & Reporting |
aerflex-us-east.celona.io | 500 | UDP | AP to Aerflex Cloud |
aerflex-us-east.celona.io | 4500 | UDP | AP to Aerflex Cloud |
aerflex-us-west.celona.io | 500 | UDP | AP to Aerflex Cloud (US-West) |
aerflex-us-west.celona.io | 4500 | UDP | AP to Aerflex Cloud (US-West) |
aerflex-europe-southwest.celona.io | 500 | UDP | AP to Aerflex Cloud (Europe) |
aerflex-europe-southwest.celona.io | 4500 | UDP | AP to Aerflex Cloud (Europe) |
aerdiag.celona.io | 443 | TCP | AP Troubleshooting |
Dataplane Subnet Ranges
Celona Access Points (APs) make use of dedicated internal dataplane subnets as part of establishing secure tunnels and enabling end-to-end traffic handling between the AP and the Celona Aerflex cluster. These subnets are used strictly for internal AP functions and must remain unblocked within the local network.
The following subnet ranges are used internally by the AP:
Subnet | Purpose |
192.168.111.0/24 | Primary AP dataplane subnet |
192.168.112.0/24 | Primary AP dataplane subnet |
192.168.113.0/24 | Primary AP dataplane subnet |
192.168.169.0/24 | AP fallback subnet used when DHCP is unavailable |
172.213.0.0/16 | Used by Aerflex cloud |
Do NOT use these subnet ranges anywhere in your network
To avoid conflicts with Celona AP operation, these subnet ranges must not be used for:
AP management IP addressing
Any enterprise device VLANs (network domain)
DHCP scopes at any site
If these subnets exist anywhere in the customer environment, AP onboarding and dataplane tunnel establishment will fail or behave unpredictably.
