| Protocol | Port | Description |
| ICMP | N/A | Network reachability tests |
| TCP | 1936 | Metrics |
| 9000-9999 | Host level services, including the node exporter on ports 9100-9101 and the Cluster Version Operator on port 9099. |
| 10250-10259 | The default ports that Kubernetes reserves |
| 22623 | The port handles traffic from the Machine Config Server and directs the traffic to the control plane machines. |
| UDP | 6081 | Geneve |
| 9000-9999 | Host level services, including the node exporter on ports 9100-9101. |
| 500 | IPsec IKE packets |
| 4500 | IPsec NAT-T packets |
| 123 | Network Time Protocol (NTP) on UDP port 123. If an external NTP time server is configured, you must open UDP port 123. |
| TCP/UDP | 30000-32767 |
| Kubernetes node port | ESP | N/A |
| Protocol | Port | Description |
| TCP | 2379-2380 | etcd server and peer ports |