# Downstream clusters behind firewall

**URL:** <https://forums.suse.com/t/downstream-clusters-behind-firewall/36579>\
**Category:** SUSE Rancher Prime\
**Created:** [December 28, 2021, 10:49am UTC](https://forums.suse.com/t/downstream-clusters-behind-firewall/36579 "2021-12-28T10:49:23Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![romanvg](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/romanvg/32/3759_2.png) [@romanvg](https://forums.suse.com/u/romanvg)\
**Post date:** [December 28, 2021, 10:49am UTC](https://forums.suse.com/t/downstream-clusters-behind-firewall/36579/1 "2021-12-28T10:49:23Z")

</div>

Hi,

trying to verify some information about network connectivity between rancher-ui and downstream clusters:

According to [Rancher Docs: Port Requirements](https://rancher.com/docs/rancher/v2.5/en/installation/requirements/ports/) it is possible to have downsteram-clusters / edge devices behind a (closed) firewall and still be used by the rancher-ui?  
Because the rancher-agent works much like a reverse tunnel?

Assuming that is correct - can i just add an edge-device locally, ship it somewhere by mail and it will appear as online as soon as it is plugged in?

regards,  
strowi
