Cisco Spaces Firewall Traffic Matrix for Spaces OS and Outcome Services

Overview

Use this knowledge article as the single firewall reference for Cisco Spaces OS and outcome services. It identifies and validates the firewall rules required between customer-managed clients, Cisco Spaces infrastructure, wireless infrastructure, and outcome-specific services.

Apply only the rule groups for the components and outcomes in your deployment. Cisco Spaces cloud addresses can change, so use FQDN-based destination objects when your firewall supports them. If your security policy requires static IP objects, compare the addresses in this article with the current Cisco documentation and the values displayed in your Cisco Spaces tenant before implementing a change.


Prerequisites

Before you begin:

  1. Identify your Cisco Spaces tenant region:

    • IO: dnaspaces.io and ciscospaces.io

    • EU: dnaspaces.eu and ciscospaces.eu

    • SG: ciscospaces.sg

  2. Inventory the components in scope:

    • Cisco Spaces Connector

    • Cisco AireOS or Catalyst 9800 wireless controllers

    • Catalyst access points with IoT Services

    • Catalyst Center

    • Meraki Dashboard integration

    • Kiosk or Space Explorer clients

    • Captive Portal

    • OpenRoaming

    • Smart Rooms gateway and building management system

    • Sensor Connect Wireless IoT Orchestrator and registered external applications

  3. Confirm that DNS, NTP, proxy, and TLS inspection policies are available for the relevant source networks.

  4. Record the Cisco Spaces tenant, region, source subnets, and firewall change identifier.

  5. For Captive Portal, open Cisco Spaces > Captive Portal > SSIDs, select the SSID, and use Configure Manually or View Config Guide to obtain the tenant-specific splash URL, RADIUS server addresses, and shared secret.

Do not copy RADIUS server addresses or secrets from another tenant. Use the values generated for the SSID in your own Cisco Spaces tenant.


How to read the traffic matrix

Each rule separates the source and destination ports. Unless a row explicitly states otherwise, Source port is Any (ephemeral): the initiating client selects a temporary source port, while the firewall rule matches the listed service Destination port. Stateful firewalls should permit the associated return traffic. Do not configure the destination service port as a fixed source port.


Select the required rule groups

Deployment component or outcome

Required rule groups

Spaces Connector with AireOS or Catalyst 9800

A, B

IoT Services on Catalyst wireless

A, B, C

Meraki wireless integration, including Scanning API and MQTT

E

Catalyst Center integration

D

Meraki Dashboard API synchronization only

E1

Smart Workspaces kiosk or signage

F

Space Explorer browser or PWA

G

Captive Portal

H

OpenRoaming with Connector

A, B, I

OpenRoaming with Meraki

I

Smart Rooms gateway

J

Sensor Connect for IoT Services

K

Asset Tracking, Occupancy, or Indoor Navigation

A, B, and C when IoT Services is used


A. Allow the Cisco Spaces Connector to reach Cisco Spaces cloud


A. Allow the Cisco Spaces Connector to reach Cisco Spaces cloud

Allow each Connector to initiate the following traffic to the endpoint for the tenant region.

Region

Source

Destination FQDN

Published IP addresses

Protocol

Source port

Destination port

Use

IO current

Cisco Spaces Connector

connector.ciscospaces.io

75.2.50.127, 99.83.199.229

TCP/TLS

Any (ephemeral)

443

Cloud control and data

IO existing

Cisco Spaces Connector

connector.dnaspaces.io

52.20.144.155, 34.231.154.95

TCP/TLS

Any (ephemeral)

443

Cloud control and data

IO disaster recovery

Cisco Spaces Connector

Regional recovery service

54.176.92.81, 54.183.58.225

TCP/TLS

Any (ephemeral)

443

Disaster-recovery cloud connectivity

EU

Cisco Spaces Connector

connector.dnaspaces.eu

63.33.127.190, 63.33.175.64

TCP/TLS

Any (ephemeral)

443

Cloud control and data

EU disaster recovery

Cisco Spaces Connector

Regional recovery service

3.122.15.26, 3.122.15.7

TCP/TLS

Any (ephemeral)

443

Disaster-recovery cloud connectivity

SG

Cisco Spaces Connector

connector.ciscospaces.sg

13.228.159.49, 54.179.105.241

TCP/TLS

Any (ephemeral)

443

Cloud control and data

SG disaster recovery

Cisco Spaces Connector

Regional recovery service

13.214.251.223, 54.255.57.46

TCP/TLS

Any (ephemeral)

443

Disaster-recovery cloud connectivity

For IO tenants using static address objects, include the current and existing published addresses during the Cisco Spaces domain transition. Prefer the regional FQDN when possible.

Expected result: The Connector dashboard shows healthy control and data channels to Cisco Spaces cloud.

B. Allow Connector and wireless controller communication


B. Allow Connector and wireless controller communication

Where the Connector and wireless infrastructure are separated by a firewall, permit the applicable traffic between their assigned addresses.

Source

Destination

Protocol

Source port

Destination port

Use

Wireless controller

Cisco Spaces Connector

TCP

Any (ephemeral)

16113

NMSP location telemetry

Cisco Spaces Connector

Catalyst 9800

TCP

Any (ephemeral)

830

NETCONF

Cisco Spaces Connector

Wireless controller

TCP

Any (ephemeral)

22

SSH management used by Connector workflows

Wireless infrastructure

Cisco Spaces Connector

UDP

Any (ephemeral)

2003, optional

FastLocate

If the firewall policy requires a single initiating direction and the local implementation does not make it clear, validate the direction against the current Connector open-port diagram before applying the rule. Do not expose these management ports to the public internet.

Expected result: The controller is active in Cisco Spaces and Connector connectivity tests succeed.

C. Allow IoT Services communication


C. Allow IoT Services communication

Apply these rules only when Cisco Spaces IoT Services are enabled on Catalyst wireless infrastructure.

Source

Destination

Protocol

Source port

Destination port

Use

Catalyst 9800

Cisco Spaces Connector

TCP

Any (ephemeral)

8004

Telemetry Data Logger stream

Catalyst 9800

Cisco Spaces Connector

TCP

Any (ephemeral)

8184

Telemetry Data Logger stream

Cisco Spaces Connector

Access points

TCP

Any (ephemeral)

8443

IOx application installation and management

Access points

Cisco Spaces Connector

TCP

Any (ephemeral)

8000

gRPC and REST communication

Expected result: IoT Services > About > View Detailed Status shows successful deployment, and the selected access points show an enabled gateway and an up IOx channel.

For Meraki wireless telemetry, use rule group E. It separates the Meraki Dashboard API, Scanning API, and TLS-protected MQTT flows.

D. Allow Catalyst Center activation and certificate checks


D. Allow Catalyst Center activation and certificate checks

Allow Catalyst Center to initiate the following traffic:

Source

Destination

Protocol

Source port

Destination port

Use

Catalyst Center

dnaspaces.io

TCP/TLS

Any (ephemeral)

443

IO tenant activation

Catalyst Center

dnaspaces.eu

TCP/TLS

Any (ephemeral)

443

EU tenant activation

Catalyst Center

ciscospaces.sg

TCP/TLS

Any (ephemeral)

443

SG tenant activation

Catalyst Center

validation.identrust.com

TCP

Any (ephemeral)

80

Certificate revocation check

Catalyst Center

commercial.ocsp.identrust.com

TCP

Any (ephemeral)

80

Certificate revocation check

Expected result: In Catalyst Center, System > Settings > CMX Servers/Cisco Spaces shows the Cisco Spaces integration as activated.

E. Allow the seamless Meraki integration


E. Allow the seamless Meraki integration

The native Meraki integration can exchange organization and network information, maps, devices, SSIDs, Scanning API subscriptions, MQTT broker configuration, and Wi-Fi or BLE location information. Apply the flows used by your deployment.

E1. Dashboard API synchronization

Allow Cisco Spaces to initiate the following API connection:

Source

Destination

Protocol

Source port

Destination port

Use

Cisco Spaces regional services

Meraki Dashboard API

TCP/TLS

Any (ephemeral)

443

Organization, network, device, map, SSID, Scanning API, and MQTT configuration synchronization

When Organization > Settings > Login IP ranges restricts Dashboard API access by source address, add the applicable regional Cisco Spaces source addresses to the API policy:

Region

Cisco Spaces source IP addresses

IO

34.192.26.106, 52.206.67.43, 3.208.52.128

EU

52.208.15.59, 54.220.148.167, 54.220.45.63

SG

3.1.251.174, 13.215.110.252

Review all existing integrations before enabling or tightening an IP restriction so that other authorized API clients are not blocked.

E2. Scanning API location data

Allow Meraki cloud to deliver Scanning API location observations to the tenant-generated Cisco Spaces Post URL:

Source

Destination

Protocol

Source port

Destination port

Use

Meraki cloud

Tenant-generated Cisco Spaces Scanning API Post URL

TCP/TLS

Any (ephemeral)

443

HTTPS validation and JSON POST delivery of Wi-Fi and BLE location data

Use the Post URL and secret generated for the organization in Cisco Spaces. Do not substitute a URL from another tenant or region.

E3. Wireless MQTT

Allow the Meraki wireless networks that send data to Cisco Spaces to establish a TLS MQTT session:

Source

Destination

Protocol

Source port

Destination port

Use

Meraki wireless network

Cisco Spaces account- and region-specific MQTT broker configured by the integration

TCP/TLS (MQTT)

Any (ephemeral)

8883

Encrypted wireless MQTT telemetry

To support this configuration and ensure the seamless flow of MQTT traffic, please make sure that the TLS port 8883 is open between Meraki and Spaces for all the networks sending data to Spaces.

Expected result: The Meraki organization and selected networks synchronize with Cisco Spaces, the Scanning API Post URL validates and receives observations, and MQTT clients establish TLS sessions on destination port 8883.

F. Allow Smart Workspaces kiosk and signage clients


F. Allow Smart Workspaces kiosk and signage clients

Allow outbound TCP 443 from kiosk and signage client networks. Where wildcard destinations are permitted, the regional wildcards are recommended:

  • IO: *.ciscospaces.io, *.dnaspaces.io

  • EU: *.ciscospaces.eu, *.dnaspaces.eu

  • SG: *.ciscospaces.sg

If explicit FQDN objects are required, use the applicable regional list. Every row uses TCP/TLS, source port Any (ephemeral), and destination port 443.

Source

Service

IO destination

EU destination

SG destination

Protocol

Source port

Destination port

Kiosk or signage client

Kiosk

kiosk.ciscospaces.io

kiosk.ciscospaces.eu

kiosk.ciscospaces.sg

TCP/TLS

Any (ephemeral)

443

Kiosk or signage client

Signage

signage.dnaspaces.io

signage.dnaspaces.eu

signage.ciscospaces.sg

TCP/TLS

Any (ephemeral)

443

Kiosk or signage client

Workspaces

workspaces.dnaspaces.io, workspaces.ciscospaces.io

workspaces.dnaspaces.eu, workspaces.ciscospaces.eu

workspaces.ciscospaces.sg

TCP/TLS

Any (ephemeral)

443

Kiosk or signage client

Webex API WebSocket

webex-api-server.dnaspaces.io

webex-api-server.dnaspaces.eu

webex-api-server.ciscospaces.sg

TCP/TLS

Any (ephemeral)

443

Kiosk or signage client

Workspace WebSocket

swsjetstreams.dnaspaces.io

swsjetstreams.dnaspaces.eu

sgswsjetstreams.ciscospaces.sg

TCP/TLS

Any (ephemeral)

443

Kiosk or signage client

RMS

rms.dnaspaces.io, rms.ciscospaces.io

rms.dnaspaces.eu, rms.ciscospaces.eu

rms.ciscospaces.sg

TCP/TLS

Any (ephemeral)

443

Kiosk or signage client

Maps

maps.ciscospaces.io

maps.ciscospaces.eu

maps.ciscospaces.sg

TCP/TLS

Any (ephemeral)

443

Also allow the following third-party traffic:

Source

Destination

Protocol

Source port

Destination port

Use

Kiosk or signage client

api.mapbox.com

TCP/TLS

Any (ephemeral)

443

Map content

Kiosk or signage client

events.mapbox.com

TCP/TLS

Any (ephemeral)

443

Map events

Kiosk or signage client

fonts.googleapis.com

TCP/TLS

Any (ephemeral)

443

Web fonts

*.amazonaws.com is currently identified as temporary for Smart Rooms and custom logos. Use it only when the selected feature requires it and narrow the rule when a more specific published destination becomes available. *.pendo.com is optional and non-blocking.

Expected result: The kiosk or signage application loads its maps and live state without missing content or WebSocket errors.

G. Allow Space Explorer browser and PWA clients


G. Allow Space Explorer browser and PWA clients

Allow the following traffic from the end-user or managed-device network:

Source

Destination

Protocol

Source port

Destination port

Use

Space Explorer browser or PWA client

ciscospaces.app

TCP/TLS

Any (ephemeral)

443

Space Explorer application

Space Explorer browser or PWA client

maps.ciscospaces.io

TCP/TLS

Any (ephemeral)

443

Cisco Spaces maps

Space Explorer browser or PWA client

sws-jetstreams.dnaspaces.io

TCP/TLS

Any (ephemeral)

443

Live application data

Space Explorer browser or PWA client

workspaces-preprod.dnaspaces.io

TCP/TLS

Any (ephemeral)

443

Temporary published dependency

Space Explorer browser or PWA client

api.mapbox.com

TCP/TLS

Any (ephemeral)

443

Map content

Space Explorer browser or PWA client

events.mapbox.com

TCP/TLS

Any (ephemeral)

443

Map events

Space Explorer browser or PWA client

fonts.googleapis.com

TCP/TLS

Any (ephemeral)

443

Web fonts

The current Space Explorer publication identifies IO as supported and marks some EU and SG endpoints as roadmap. Confirm regional availability before using this rule group outside IO. Also allow the identity-provider destinations selected for Webex, Microsoft, or Google sign-in.

Expected result: Users can sign in, load the building map, and complete the licensed room or desk workflow.

H. Allow Captive Portal splash and RADIUS traffic


H. Allow Captive Portal splash and RADIUS traffic

H1. Allow splash traffic

Allow TCP 443 from the client or controller path that presents the portal to the tenant-specific splash URL shown in the Cisco Spaces dashboard. For firewalls or controller ACLs that also require static addresses, use the addresses for the tenant domain:

Region

Source

Splash destination FQDN

Published IP addresses

Protocol

Source port

Destination port

Use

IO existing

Client or controller portal path

splash.dnaspaces.io

34.235.248.212, 52.55.235.39

TCP/TLS

Any (ephemeral)

443

Captive Portal splash

IO current

Client or controller portal path

splash.ciscospaces.io

3.33.232.255, 15.197.234.109

TCP/TLS

Any (ephemeral)

443

Captive Portal splash

EU existing

Client or controller portal path

splash.dnaspaces.eu

54.77.207.183, 34.252.175.120

TCP/TLS

Any (ephemeral)

443

Captive Portal splash

EU current

Client or controller portal path

splash.ciscospaces.eu

35.71.129.209, 52.223.8.107

TCP/TLS

Any (ephemeral)

443

Captive Portal splash

SG

Client or controller portal path

splash.ciscospaces.sg

13.250.197.154

TCP/TLS

Any (ephemeral)

443

Captive Portal splash

Add only the domains required by the authentication methods configured for the portal. For example, a portal that offers a social sign-in option also needs the current domains published by that identity provider.

H2. Allow RADIUS traffic when authentication is enabled

Source

Destination

Protocol

Source port

Destination port

Use

Wireless controller or Meraki network

Tenant-specific Cisco Spaces RADIUS servers

UDP

Any (ephemeral)

1812

Authentication

Wireless controller or Meraki network

Tenant-specific Cisco Spaces RADIUS servers

UDP

Any (ephemeral)

1813, conditional

Accounting when required by the selected design

Use both tenant-specific server addresses displayed in the dashboard. RADIUS accounting is not required for the base Catalyst 9800 captive portal flow; enable it only when the selected feature requires it.

Expected result: A test client is redirected to the tenant splash page, completes the configured authentication, and receives the intended network access.

I. Allow OpenRoaming traffic


I. Allow OpenRoaming traffic

Apply the Spaces OS base rules plus the rules for the selected architecture.

Connector-based OpenRoaming

Source

Destination

Protocol

Source port

Destination port

Use

Cisco AireOS wireless controller

Connector

UDP and TCP

Any (ephemeral)

1812 and 1813

OpenRoaming RADIUS messages

Connector

ANY

TCP

Any (ephemeral)

2083

RADSEC - OpenRoaming Identity Providers

Connector

ANY

TCP/TLS

Any (ephemeral)

443

Certificate signing and membership - OpenRoaming Membership service

Meraki-based OpenRoaming

Allow Meraki access points to initiate the following traffic:

Region

Source

Destination

Protocol

Source port

Destination port

Use

IO

Meraki access points

184.73.46.220

TCP

Any (ephemeral)

2083

RADSEC

EU

Meraki access points

63.33.180.45

TCP

Any (ephemeral)

2083

RADSEC

SG

Meraki access points

54.169.186.118

TCP

Any (ephemeral)

2083

RADSEC

Expected result: A supported OpenRoaming client authenticates and connects without a captive portal prompt.

J. Allow Smart Rooms gateway traffic


J. Allow Smart Rooms gateway traffic

WAN

Allow the Smart Rooms gateway to initiate the following traffic:

Source

Destination

Protocol

Source port

Destination port

Use

Smart Rooms gateway

nodev3.iotium.io, checkip.amazonaws.com, *.google.com, docker.com, *.docker.io, 44.202.124.117

TCP/TLS

Any (ephemeral)

443

Published Smart Rooms cloud services

Smart Rooms gateway

Published Smart Rooms tunnel service

TCP

Any (ephemeral)

7422

Secure cloud tunnel

Building management system

Between the Smart Rooms gateway LAN interface and the building management system, allow the following traffic, or use the customer-specific BACnet destination port when it differs:

Source

Destination

Protocol

Source port

Destination port

Use

Smart Rooms gateway LAN interface

Building management system

UDP

Any (ephemeral)

47808 or customer-specific BACnet port

BACnet

Building management system

Smart Rooms gateway LAN interface

UDP

Any (ephemeral)

47808 or customer-specific BACnet port

BACnet return or initiated traffic

Expected result: The gateway establishes its secure cloud tunnel and the gateway and building management system report a healthy connection.

K. Allow Sensor Connect for IoT Services traffic


K. Allow Sensor Connect for IoT Services traffic

Apply this rule group when the Cisco Sensor Connect Wireless IoT Orchestrator application is deployed on a supported Cisco Catalyst 9800 Wireless Controller.

The Wireless IoT Orchestrator uses a unique application IP address. When access points cannot reach that address directly, such as when the controller is behind a firewall or located in a remote data center, configure the Sensor Connect NAT IP on the controller and use that reachable address as the firewall destination.

Access points to Wireless IoT Orchestrator

Source

Destination

Protocol

Source port

Destination port

Use

Cisco access points

Wireless IoT Orchestrator IP or configured NAT IP

TCP

Any (ephemeral)

50221

Initial HTTP connection to the Wireless IoT Orchestrator

Cisco access points

Wireless IoT Orchestrator IP or configured NAT IP

TCP

Any (ephemeral)

43626

Establish and maintain the application connection

External applications to Wireless IoT Orchestrator

Apply only the interfaces used by the registered application.

Source

Destination

Protocol

Source port

Destination port

Use

Registered external application

Wireless IoT Orchestrator IP

TCP/TLS

Any (ephemeral)

8081

HTTPS REST API interface

Registered external application

Wireless IoT Orchestrator IP

TCP

Any (ephemeral)

41883

MQTT publisher listening interface

Restrict these rules to the access point and registered application source ranges. Do not expose the Wireless IoT Orchestrator interfaces directly to the public internet. The REST interface uses authentication and HTTPS. Ensure clients trust the configured server certificate, and install an organization-approved certificate when required by security policy.

Expected result:

  • Configuration > Services > IoT Services shows the IoT Orchestrator application in the Running state.

  • The IoT Orchestrator reports that its connection to the controller was established successfully.

  • Inventory > Access Points lists the expected access points as connected.

  • Registered external applications can use the required REST or MQTT interface.


Validate the deployment

Complete the checks for every applied rule group:

  1. From the actual source segment, confirm that each required FQDN resolves.

  2. Confirm that the permitted TCP or UDP session reaches the intended destination without an unexpected proxy, TLS inspection, or NAT policy failure.

  3. Review firewall logs for denied sessions from the Connector, controller, access points, Meraki cloud or wireless networks, client devices, Catalyst Center, Smart Rooms gateway, Wireless IoT Orchestrator, or registered external applications. Confirm that the session uses an ephemeral source port and the destination port listed in the applicable rule.

  4. Confirm the corresponding platform status:

    • Connector control and data channels are healthy.

    • Controllers are active.

    • IoT Services deployment is successful.

    • Catalyst Center integration is activated.

    • Meraki Dashboard synchronization completes, the Scanning API receiver validates and receives observations, and wireless MQTT sessions establish over TLS 8883.

    • Kiosk, signage, or Space Explorer loads all content.

    • Captive Portal redirect and optional RADIUS authentication succeed.

    • OpenRoaming authentication succeeds.

    • Smart Rooms cloud and BACnet connections are healthy.

    • Sensor Connect shows the IoT Orchestrator running, the expected access points connected, and the required external application interface reachable.

  5. Record the test result and the date on which the FQDN and IP list was verified.


Troubleshooting

FQDN resolves but the application remains offline

  • Confirm the rule permits the resolved IPv4 or IPv6 address actually selected by the client.

  • Check whether the firewall supports dynamic FQDN objects and refreshes DNS answers.

  • Review proxy authentication and TLS inspection policies. WebSocket services must remain usable for kiosk and Space Explorer live data.

Connector cloud channels are down

  • Confirm outbound TCP 443 to the correct regional Connector FQDN.

  • For IO static policies, confirm that both current and existing migration addresses are present.

  • Check DNS, NTP, default route, proxy, and firewall logs from the Connector subnet.

Controller or IoT Services remains inactive

  • Confirm that rules B and C are applied between the correct Connector, controller, and access point addresses.

  • Confirm that TCP 830 is used only for Catalyst controllers.

  • Confirm that optional UDP 2003 is required before enabling FastLocate.

  • In Cisco Spaces, review the detailed IoT Services deployment status and retry only after the denied path is corrected.

Captive Portal does not redirect or authenticate

  • Reopen Configure Manually or View Config Guide and compare the deployed splash FQDN, IPs, RADIUS server addresses, ports, and shared secret with the tenant-generated values.

  • Confirm DNS and DHCP are available to unauthenticated clients.

  • Confirm the pre-authentication or walled-garden policy permits the splash destination and the identity providers configured for the portal.

  • Do not add UDP 1813 unless accounting is required by the selected workflow.

Meraki integration is incomplete

  • Confirm the regional Cisco Spaces source addresses are in the Dashboard API allowlist.

  • Confirm the restriction applies to API access without unintentionally excluding administrators or other authorized integrations.

  • For Scanning API, confirm that Meraki cloud can reach the tenant-generated Cisco Spaces Post URL over TCP/TLS destination port 443 and that the configured secret matches.

  • For wireless MQTT, confirm that every participating Meraki network can reach the account- and region-specific broker over TCP/TLS destination port 8883.

  • Confirm the firewall is not incorrectly requiring 443 or 8883 as a fixed source port; the initiating client uses an ephemeral source port.

Sensor Connect access points or applications cannot connect

  • Confirm that the IoT Orchestrator application is in the Running state before testing connectivity.

  • If the access points cannot route directly to the IoT Orchestrator application IP, confirm that the controller has the correct Sensor Connect NAT IP and that rules target that address.

  • For access point connectivity, confirm TCP 50221 and TCP 43626 from the access point source ranges.

  • For registered external applications, confirm TCP 8081 for REST and TCP 41883 for MQTT as applicable.

  • In Inventory > Access Points, compare the expected controller access points with the access points reported as connected.

  • If the REST connection reaches TCP 8081 but authentication fails, verify the registered application's API key or certificate and the configured server/client certificate trust model.


Supplementary information