36000 to 36011 – are used). The previous default range of 50000 - 54999 still applies to earlier releases that
have upgraded to X8.1.
Note that:
n
Ports 8191/8192 TCP and 8883/8884 TCP are used internally within the VCS Control and the VCS
Expressway applications. Therefore these ports must not be allocated for any other purpose. The VCS
Expressway listens externally on port 8883; therefore we recommend that you create custom firewall rules
on the external LAN interface to drop TCP traffic on that port.
n
The VCS Expressway listens on port 2222 for SSH tunnel traffic. The only legitimate sender of such traffic
is the VCS Control (cluster). Therefore we recommend that you create the following firewall rules for the
SSH tunnels service:
l
one or more rules to allow all of the VCS Control peer addresses (via the internal LAN interface, if
appropriate)
l
followed by a lower priority (higher number) rule that drops all traffic for the SSH tunnels service (on the
internal LAN interface if appropriate, and if so, another rule to drop all traffic on the external interface)
Cisco VCS Administrator Guide (X8.1.1)
Page 396 of 507
Reference material
Unified Communications port reference