Skip to main content

Private Networking with SGA (AHV)

Customers using Nutanix AHV infrastructure can create a Frame account using Customer-managed networking, Private Networking with Streaming Gateway Appliance (SGA) so users can access the Frame workload VMs through the public IP address of the SGA VM. The Internet-accessible SGA VM serves as a reverse proxy for Frame sessions between the end users and their Frame workload VMs in the private network. The Frame workload VMs only have private IP addresses. Customers will need to ensure these workload VMs can communicate to the Frame control plane on the Internet.

FRP7 Networking

FRP7 is a tcp-based protocol for all communication between the end user and the Frame workload VMs.

Nutanix AHV - Private Networking with SGA (FRP7)

Nutanix AHV - Private Networking with SGA (FRP7)

The following table describes the required protocols and ports for Frame accounts using Private Networking with SGA and FRP7 with the commercial Frame control plane.

Source to DestinationSource IP addressDestination FQDN(s)Protocol/port
Cloud Connector Appliance (CCA) to Frame PlatformPublic IP addressconsole.nutanix.com
cpanel-backend.console.nutanix.com
gateway-external-api.console.nutanix.com
tcp/443 (HTTPS)
Cloud Connector Appliance (CCA) to Frame PlatformPublic IP addresscch.console.nutanix.comtcp/443 (HTTPS, WSS)
Prism Central to Frame PlatformPublic IP addressdownloads.console.nutanix.comtcp/443 (HTTPS)
CCA to Prism CentralPrivate IP addressPrism Central IP addresstcp/443 (HTTPS), tcp/9440 (HTTPS)
CCA to Prism ElementPrivate IP addressPrism Element IP addresstcp/443 (HTTPS), tcp/9440 (HTTPS)
Workload VMs to Frame PlatformPublic IP addressgateway-external-api-prod.frame.nutanix.com
img.console.nutanix.com
img.frame.nutanix.com
prod-kds-5683567dcbd60804cb34.s3.us-east-1.amazonaws.com
assets.console.nutanix.com
downloads.console.nutanix.com
logging.console.nutanix.com
download.visualstudio.microsoft.com
tcp/443 (HTTPS)
Workload VMs to Frame PlatformPublic IP addresscch.console.nutanix.comtcp/443 (HTTPS, WSS)
End user to Frame PlatformPublic IP addressconsole.nutanix.com
img.frame.nutanix.com
img.console.nutanix.com
cpanel-backend.console.nutanix.com
terminal-prod.frame.nutanix.com
logging.console.nutanix.com
login.console.nutanix.com (for Frame IdP, if used)
tcp/443 (HTTPS)
SGA VMs to Frame PlatformPublic IP addresscpanel-backend.console.nutanix.com
gateway-external-api-prod.frame.nutanix.com
tcp/443 (HTTPS)
End user to SGA VMPublic IP address*.<CUSTOMER SGA FQDN> resolving to public IP (or private IP) addresstcp/443 (HTTPS, WSS)
SGA VM to Workload VMPrivate IP addressDynamic private IP address within VPC/VNETtcp/443 (HTTPS, WSS)

FRP8 Networking

FRP8 is a udp-based protocol for all communication between the end user and the Frame workload VMs.

Nutanix AHV - Private Networking with SGA (FRP8)

Nutanix AHV - Private Networking with SGA (FRP8)

The following table describes the required protocols and ports for Frame accounts using Private Networking with SGA and FRP8 with the commercial Frame control plane.

Source to DestinationSource IP addressDestination FQDN(s)Protocol/port
Cloud Connector Appliance (CCA) to Frame PlatformPublic IP addressconsole.nutanix.com
cpanel-backend.console.nutanix.com
gateway-external-api.console.nutanix.com
tcp/443 (HTTPS)
Cloud Connector Appliance (CCA) to Frame PlatformPublic IP addresscch.console.nutanix.comtcp/443 (HTTPS, WSS)
Prism Central to Frame PlatformPublic IP addressdownloads.console.nutanix.comtcp/443 (HTTPS)
CCA to Prism CentralPrivate IP addressPrism Central IP addresstcp/443 (HTTPS)
CCA to Prism ElementPrivate IP addressPrism Element IP addresstcp/443 (HTTPS)
Workload VMs to Frame PlatformPublic IP addressgateway-external-api-prod.frame.nutanix.com
img.console.nutanix.com
img.frame.nutanix.com
prod-kds-5683567dcbd60804cb34.s3.us-east-1.amazonaws.com
assets.console.nutanix.com
downloads.console.nutanix.com
logging.console.nutanix.com
download.visualstudio.microsoft.com
tcp/443 (HTTPS)
Workload VMs to Frame PlatformPublic IP addresscch.console.nutanix.com
messaging.console.nutanix.com
tcp/443 (HTTPS, WSS)
End user to Frame PlatformPublic IP addressconsole.nutanix.com
img.frame.nutanix.com
img.console.nutanix.com
cpanel-backend.console.nutanix.com
terminal-prod.frame.nutanix.com
logging.console.nutanix.com
login.console.nutanix.com (for Frame IdP, if used)
tcp/443 (HTTPS)
End user to Frame PlatformPublic IP addressmessaging.console.nutanix.comtcp/443 (HTTPS, WSS)
SGA VMs to Frame PlatformPublic IP addresscpanel-backend.console.nutanix.com
gateway-external-api-prod.frame.nutanix.com
tcp/443 (HTTPS)
SGA VMs to Frame PlatformPublic IP addressmessaging.console.nutanix.comtcp/443 (HTTPS, WSS)
SGA VMs to Frame PlatformPublic IP addressstun.console.nutanix.comudp/3478
End user to SGA VMPublic IP address*.<CUSTOMER SGA FQDN> resolving to public IP (or private IP) addresstcp/443 (HTTPS)
End user to SGA VMPublic IP addressSGA VM-specific public IP (or private IP) addressudp/3478 and tcp/3478 (optional)
SGA VM to End userPublic IP addressEnd user-specific public IP addressudp/49152-65535
SGA VM to Workload VMPrivate IP addressDynamic private IP address within VPC/VNETudp/4503-4509
Workload VM to SGA VMPrivate IP addressSGA VM-specific private IP addressudp/49152-65535