For AI agents: a documentation index is available at the root level at /llms.txt and /llms-full.txt. Append /llms.txt to any URL for a page-level index, or .md for the markdown version of any page.
    • NVIDIA Switch Infrastructure
    • I want to...
  • Quick Start
    • Start Here
    • Getting Started with Config Manager
    • TUI Wizard Reference
    • Configuration Samples
    • Interfaces
    • Local Development Quick Start
    • First Run Tour
  • Config Manager Overview
    • Config Manager Concepts
    • Getting Started with Nautobot
  • User Guides
    • New Site Bringup
    • Workflow Lifecycle
  • Deployment
    • Hosting Options
    • Network Topology Requirements
    • Firewall Ports
    • Airgapped Deployment
    • Troubleshooting
  • Services
NVIDIANVIDIA
Developer-friendly docs for your API
Privacy Policy | Your Privacy Choices | Terms of Service | Accessibility | Corporate Policies | Product Security | Contact

Copyright © 2026, NVIDIA Corporation.

LogoLogo
Deployment

Firewall Ports

||View as Markdown|

Firewalls, security groups, and ACLs between the device network and Config Manager must permit the traffic below for the Config Manager DHCP and ZTP services to function correctly. DHCP and HTTPS are required for every deployment; the others are conditional on how ZTP and image distribution are configured.

Protocol / PortDirectionPurpose
UDP 67Bidirectional (DHCP relay ↔ Config Manager)Relayed DHCP requests and server responses (DISCOVER / REQUEST / OFFER / ACK)
TCP 443Device → Config ManagerHTTPS download of ZTP boot scripts, rendered configs, and images
TCP 80Device → Config ManagerHTTP fallback for ZTP boot scripts, where HTTPS is not used
TCP 22Device → Config ManagerSFTP image downloads, where SFTP is used instead of HTTPS
UDP/TCP 53Device → DNS resolverDNS resolution when ZTP/DHCP targets are referenced by hostname (e.g. ztp.<hostname>, dhcp.<hostname>)
Previous

Network Topology Requirements

Next

Deploy Config Manager in an Airgapped Environment