Skip to main content

Aerflex Network Prerequisites - Firewall Configuration and AP subnets

List of known ports & URLs that need to be opened for the Celona network

Team Celona avatar
Written by Team Celona
Updated this week

Celona Access Points, Cloud core and Celona Orchestrator must communicate over the existing enterprise LAN/WAN infrastructure to enable zero-touch provisioning and cloud-based management of the Private Wireless network. For seamless Day 0 & Day N operations of the Celona Private Wireless network, enterprise firewalls must be configured to allow specific discovery, management, provisioning, and troubleshooting functions.

Please refer to the following tables for detailed firewall configurations to allow communication between Celona AP, Cloud core, and Orchestrator.

Outbound Access Point to Internet

URL (DNS) / IP Address

Port

Protocol

Purpose

cso.celona.io
54.176.31.199
54.177.170.84

443

TCP

Discovery, Configuration & Reporting

500

UDP

AP to Aerflex Cloud
(US-East)

4500

UDP

AP to Aerflex Cloud
(US-East)

500

UDP

AP to Aerflex Cloud

(US-West)

4500

UDP

AP to Aerflex Cloud

(US-West)

500

UDP

AP to Aerflex Cloud

(Europe)

4500

UDP

AP to Aerflex Cloud

(Europe)

aerdiag.celona.io
54.177.198.17

443

TCP

AP Troubleshooting

Dataplane Subnet Ranges

Celona Access Points (APs) make use of dedicated internal dataplane subnets as part of establishing secure tunnels and enabling end-to-end traffic handling between the AP and the Celona Aerflex cluster. These subnets are used strictly for internal AP functions and must remain unblocked within the local network.

The following subnet ranges are used internally by the AP:

Subnet

Purpose

192.168.111.0/24

Primary AP dataplane subnet

192.168.112.0/24

Primary AP dataplane subnet

192.168.113.0/24

Primary AP dataplane subnet

192.168.169.0/24

AP fallback subnet used when DHCP is unavailable

172.213.0.0/16

Used by Aerflex cloud

Do NOT use these subnet ranges anywhere in your network

To avoid conflicts with Celona AP operation, these subnet ranges must not be used for:

  • AP management IP addressing

  • Any enterprise device VLANs (network domain)

  • DHCP scopes at any site

If these subnets exist anywhere in the customer environment, AP onboarding and dataplane tunnel establishment will fail or behave unpredictably.

Did this answer your question?