# FLEET capabilities

**URL:** <https://forums.suse.com/t/fleet-capabilities/17429>\
**Category:** SUSE Rancher Prime\
**Created:** [May 11, 2020, 9:45am UTC](https://forums.suse.com/t/fleet-capabilities/17429 "2020-05-11T09:45:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akito](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/akito/32/5805_2.png) [@Akito](https://forums.suse.com/u/Akito)\
**Post date:** [May 11, 2020, 9:45am UTC](https://forums.suse.com/t/fleet-capabilities/17429/1 "2020-05-11T09:45:14Z")

</div>

I’m trying to understand how Fleet works, so I’ve digged through available resources regarding this topic and yet I can’t seem to find a clear answer for the following question:

Can I manage clusters locked behind a NAT or corporate Firewall by using Fleet?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [May 11, 2020, 10:34am UTC](https://forums.suse.com/t/fleet-capabilities/17429/2 "2020-05-11T10:34:55Z")

</div>

Yes, the cluster agent opens an outbound connection to the management server; the clusters do not need to be directly reachable from anywhere.

---

<div class="post-metadata">

**Author:** ![Akito](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/akito/32/5805_2.png) [@Akito](https://forums.suse.com/u/Akito)\
**Post date:** [May 11, 2020, 10:56am UTC](https://forums.suse.com/t/fleet-capabilities/17429/3 "2020-05-11T10:56:50Z")

</div>

Thank you for the quick response!

So there’s absolutely never the need for an inbound connection to the agent? All ports closed on the agent and it will work?
