ZyXEL Vantage CNM Quick Start Guide - Page 9

Example Deployment Scenario

Page 9 highlights

ENGLISH 3.1 Example Deployment Scenario In most network environments the Vantage CNM server is deployed on a LAN behind a NAT router with firewall enabled. Port forwarding must be enabled on the NAT router and firewall rules must be configured between the LAN and WAN. In the following figure the managed device (A) and the Vantage CNM client (B) are both communicating with Vantage CNM (and the other servers it uses) from the WAN via the NAT router (C). A B C If Vantage CNM is behind a firewall, you must setup firewall rules to allow traffic to flow to/from Vantage CNM to the ZyXEL devices. You must also configure NAT port forwarding to allow the following traffic to be forwarded to Vantage CNM via the following ports: Vantage CNM Server: FTP Server (FTP): Mail Server (SMTP): UDP 1864, UDP 11864, TCP 443, TCP 8080 TCP 20, TCP 21 TCP 25 If you choose to install Vantage Report (VRPT) on the same server as the Vantage CNM server, you also need to setup firewall rules and NAT port forwarding on the NAT router for the following ports: Vantage Report: UDP 514, TCP 8088 " You also need to enable NAT loopback on the NAT router if both your Vantage CNM client and server are in the LAN network. 8

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127

ENGLISH
8
3.1 Example Deployment Scenario
In most network environments the Vantage CNM server is deployed on a LAN behind a NAT
router with firewall enabled. Port forwarding must be enabled on the NAT router and firewall rules
must be configured between the LAN and WAN. In the following figure the managed device (
A
)
and the Vantage CNM client (
B
) are both communicating with Vantage CNM (and the other
servers it uses) from the WAN via the NAT router (
C
).
If Vantage CNM is behind a firewall, you must setup firewall rules to allow traffic to flow to/from
Vantage CNM to the ZyXEL devices. You must also configure NAT port forwarding to allow the
following traffic to be forwarded to Vantage CNM via the following ports:
If you choose to install Vantage Report (VRPT) on the same server as the Vantage CNM server,
you also need to setup firewall rules and NAT port forwarding on the NAT router for the following
ports:
You also need to enable NAT loopback on the NAT router if both your Vantage
CNM client and server are in the LAN network.
Vantage CNM Server:
UDP 1864, UDP 11864, TCP 443,
TCP 8080
FTP Server (FTP):
TCP 20, TCP 21
Mail Server (SMTP):
TCP 25
Vantage Report:
UDP 514, TCP 8088
A
B
C