Generic Upstream Firewall Guide
For Integrating with the Nile Service Block (NSB)
1. Prerequisites
Requirement | Description |
|---|---|
Four /30 subnets | Required to establish four routed point-to-point interfaces from the NSB to the firewall (two per NSB gateway) |
Static or Dynamic Routing | Choose either static routes with ECMP or OSPF, depending on your firewall capabilities |
Internet uplinks | One or two WAN-facing interfaces with static default routes toward the ISP |

2. Interface Configuration
Configure four Layer 3 point-to-point interfaces using /30 subnets between the NSB and the firewall.
Example Interface Mapping:
NSB Gateway | Firewall Interface | Subnet (/30) |
|---|---|---|
GW-1 | eth1/1 | 172.16.7.0/30 |
GW-2 | eth1/2 | 172.16.7.4/30 |
GW-1 | eth1/3 | 172.16.7.8/30 |
GW-2 | eth1/4 | 172.16.7.12/30 |
Each interface should be configured as Layer 3 with static IPs assigned from the /30 ranges.
3. Routing Configuration
Option 1: Static Routing with ECMP
Use ECMP by configuring multiple static routes to the same subnet, one for each NSB uplink:
- The /21 subnet aggregates all NSB, sensor, and client subnets defined in the Nile Portal.
- ECMP should be enabled (if required) in the firewall’s routing engine to allow load sharing across the four next hops.
Also, configure default routes to the ISP(s):
Option 2: OSPF Routing
Enable OSPF on all four NSB uplink interfaces, and configure the firewall as follows:
- Ensure default-information originate is present to advertise default route to NSB.
- All subnets behind the NSB (client, sensor, NSB) will be reachable via OSPF-learned paths.
🔒 4. Firewall Rules
Create explicit firewall policies for traffic between NSB and external/internal zones.
Rule Type | From Zone | To Zone | Action |
|---|---|---|---|
NSB to Internet | NSB | Internet | Allow |
Internet to NSB | Internet | NSB | Allow (only if hosting services) |
NAT | NSB | Internet | Source NAT using public IP (if required) |
Example NAT Configuration:
- Source: NSB subnet
- Destination: Internet
- NAT Mode: Dynamic IP & Port (using WAN interface IP)
🌐 5. Firewall Port Requirements
Ensure the following outbound ports are open from the NSB to the Internet:
Service | Cloud | Protocol/Port | Destination |
|---|---|---|---|
HTTPS | Nile Global Cloud (U1 / AWS) | TCP 443 | u1.nilesecure.com, ne-u1.nile-global.cloud, nilesw-us-west-2.s3.us-west-2.amazonaws.com, nile-prod-us-west-2.s3.us-west-2.amazonaws.com |
HTTPS | Nile KSA Cloud (M1 / GCP) | TCP 443 | ne-m1.nile-global.cloud, m1.nilesecure.com, storage.googleapis.com |
DNS | Both | UDP 53 | 8.8.8.8, 8.8.4.4 (or your internal DNS servers) |
NTP | Both | UDP 123 | time.google.com, pool.ntp.org |
RADIUS | Both | UDP 1812, 1813 | Your RADIUS servers |
DHCP | Both | UDP 67, 68 | Your DHCP servers |
Nile Guest Service | Both | UDP 6081 | Required for Nile Guest Service (GuestPop) if enabled |
📌 Final Checklist
- All four NSB-to-firewall interfaces are configured with /30 IPs
- Static or OSPF routes to the NSB, sensor, and client subnets are configured
- Default route(s) to ISP configured
- Firewall rules allow bidirectional traffic between NSB and Internet zones
- NAT applied for outbound access from the NSB subnet
- Required ports opened for Nile to communicate with cloud and identity services