---
title: Generic Upstream Firewall Guide
slug: generic-upstream-firewall-guide
docTags: 
createdAt: 2025-06-13T05:12:36.533Z
---

**For Integrating with the Nile Service Block (NSB)**



## 1. Prerequisites

| Requirement               | Description                                                                                                    |
| ------------------------- | -------------------------------------------------------------------------------------------------------------- |
| Four /30 subnets          | Required to establish four routed point-to-point interfaces from the NSB to the firewall (two per NSB gateway) |
| Static or Dynamic Routing | Choose either static routes with ECMP or OSPF, depending on your firewall capabilities                         |
| Internet uplinks          | One or two WAN-facing interfaces with static default routes toward the ISP                                     |

## &#x20;

::Image[]{src="https://api.archbee.com/api/optimize/6swSwg1BT-BlfEPtYJhxM/kj3VeQp92nQK97Z3e35JU_image.png" size="70" width="834" height="996" position="center" showCaption="false"}

## 2. Interface Configuration

Configure four Layer 3 point-to-point interfaces using /30 subnets between the NSB and the firewall.

**Example Interface Mapping:**

| NSB Gateway | Firewall Interface | Subnet (/30)   |
| ----------- | ------------------ | -------------- |
| GW-1        | eth1/1             | 172.16.7.0/30  |
| GW-2        | eth1/2             | 172.16.7.4/30  |
| GW-1        | eth1/3             | 172.16.7.8/30  |
| GW-2        | eth1/4             | 172.16.7.12/30 |

Each interface should be configured as Layer 3 with static IPs assigned from the /30 ranges.

## &#x20;3. Routing Configuration

### Option 1: Static Routing with ECMP

Use ECMP by configuring **multiple static routes to the same subnet**, one for each NSB uplink:

:::BlockQuote
plaintextCopyEditset route 172.16.8.0/21 next-hop 172.16.7.1
set route 172.16.8.0/21 next-hop 172.16.7.5
set route 172.16.8.0/21 next-hop 172.16.7.9
set route 172.16.8.0/21 next-hop 172.16.7.13
:::

- The /21 subnet aggregates all **NSB, sensor, and client** subnets defined in the Nile Portal.
- ECMP should be **enabled** (if required) in the firewall’s routing engine to allow load sharing across the four next hops.

Also, configure **default routes to the ISP(s)**:

:::BlockQuote
plaintextCopyEditset route 0.0.0.0/0 next-hop \<ISP1-GW> metric 10
set route 0.0.0.0/0 next-hop \<ISP2-GW> metric 100
:::

### Option 2: OSPF Routing

Enable **OSPF on all four NSB uplink interfaces**, and configure the firewall as follows:

:::BlockQuote
plaintextCopyEditrouter ospf 1
&#x20; router-id 10.10.10.1
&#x20; default-information originate
&#x20; network 172.16.7.0 0.0.0.3 area 0
&#x20; network 172.16.7.4 0.0.0.3 area 0
&#x20; network 172.16.7.8 0.0.0.3 area 0
&#x20; network 172.16.7.12 0.0.0.3 area 0
:::

- Ensure **default-information originate** is present to advertise default route to NSB.
- All subnets behind the NSB (client, sensor, NSB) will be reachable via OSPF-learned paths.

## 🔒 4. Firewall Rules

Create explicit firewall policies for traffic between NSB and external/internal zones.

| Rule Type       | From Zone | To Zone  | Action                                     |
| --------------- | --------- | -------- | ------------------------------------------ |
| NSB to Internet | NSB       | Internet | Allow                                      |
| Internet to NSB | Internet  | NSB      | Allow *(only if hosting services)*         |
| NAT             | NSB       | Internet | Source NAT using public IP *(if required)* |

**Example NAT Configuration:**

- Source: NSB subnet
- Destination: Internet
- NAT Mode: Dynamic IP & Port (using WAN interface IP)

## 🌐 5. Firewall Port Requirements

Ensure the following outbound ports are **open from the NSB to the Internet**:

| Service            | Cloud                        | Protocol/Port  | Destination                                                                                                                             |
| ------------------ | ---------------------------- | -------------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| HTTPS              | Nile Global Cloud (U1 / AWS) | TCP 443        | u1.nilesecure.com, ne-u1.nile-global.cloud, nilesw-us-west-2.s3.us-west-2.amazonaws.com, nile-prod-us-west-2.s3.us-west-2.amazonaws.com |
| HTTPS              | Nile KSA Cloud (M1 / GCP)    | TCP 443        | ne-m1.nile-global.cloud, m1.nilesecure.com, storage.googleapis.com                                                                      |
| DNS                | Both                         | UDP 53         | 8.8.8.8, 8.8.4.4 (or your internal DNS servers)                                                                                         |
| NTP                | Both                         | UDP 123        | time.google.com, pool.ntp.org                                                                                                           |
| RADIUS             | Both                         | UDP 1812, 1813 | Your RADIUS servers                                                                                                                     |
| DHCP               | Both                         | UDP 67, 68     | Your DHCP servers                                                                                                                       |
| Nile Guest Service | Both                         | UDP 6081       | Required for Nile Guest Service (GuestPop) if enabled                                                                                   |

## 📌 Final Checklist

- All four NSB-to-firewall interfaces are configured with /30 IPs
- Static or OSPF routes to the NSB, sensor, and client subnets are configured
- Default route(s) to ISP configured
- Firewall rules allow bidirectional traffic between NSB and Internet zones
- NAT applied for outbound access from the NSB subnet
- Required ports opened for Nile to communicate with cloud and identity services

