When configuring firewall rules to secure communication between Deployments and service networks, identification of specific ports required for Tanzu Application Service/Elastic Application Runtime service broker registration is necessary. Difficulty arises because communication ports used by the Cloud Controller/Router for registration are not universal and vary depending on the specific service.
Tanzu Platform
Communication ports for service broker registration are defined by the specific service tile. Requirements differ based on the service architecture. Some registration processes involve dynamic port allocation, preventing the establishment of a single, definitive, global list of ports.
To define firewall rules, consult the official documentation for each specific service tile installed in the environment. Follow these steps to locate required port information:
Important: Do not assume a static list of ports. Always verify requirements per tile to ensure network integrity.
The following resources provide examples of where to locate network configuration details for specific services:
If specific port documentation is missing for a service tile, open a support case to request clarification on the required firewall configuration for that component.