Establish an LE-LEM connection from Litmus Edge Manager
An Litmus Edge (LE)-Litmus Edge Manager (LEM) connection is the persistent, secure channel between Litmus Edge and Litmus Edge Manager. It enables centralized remote management of the gateway, including activation, credential provisioning, and forwarding of metrics and events to Litmus Edge Manager.
The connection uses two ports for establishment: port 443/TCP for the initial activation handshake, and port 51820/UDP for the permanent bi-directional remote access tunnel. An optional third port (8883/TCP) supports ongoing MQTT data transmission after the connection is in place.
Note: For details on the Litmus Edge Manager port customization for this connection, see Establishing an LE-LEM Connection from Litmus Edge.
Core Components
Component | Role |
|---|---|
Litmus Edge | The edge gateway. Initiates all connections outbound to Litmus Edge Manager |
Litmus Edge Manager | The centralized management platform. Receives and approves connections |
Port 443/TCP (HTTPS) | Initial activation channel |
Port 51820/UDP (Remote Access) | Permanent bidirectional management tunnel |
Port 8883/TCP (MQTT SSL) | Ongoing metrics and event data transmission (optional) |
Connection Sequence
The following steps describe how Litmus Edge initiates and establishes its connection with Litmus Edge Manager. From the Litmus Edge side, the key actions are entering the activation URL and code (step 1) and confirming the permanent connection after it is established (step 7).
- Litmus Edge user enters activation URL and activation code. See Step 2: Create an Activation Request in Litmus Edge section of Activate an Edge Device for details.
- Litmus Edge attempts to establish an initial connection with inbound port 443/TCP (HTTPS) of Litmus Edge Manager.
- Litmus Edge Manager receives the connection at its inbound port 443/TCP (HTTPS).
- Litmus Edge sends an activation request that is received and approved by Litmus Edge Manager. See Step 3: Approve the Activation Request in Litmus Edge Manager section of Activate an Edge Device for details.
- Litmus Edge sends activation requests on port 443/TCP of Litmus Edge Manager.
- Litmus Edge Manager user accepts the activation request in UI.
- Litmus Edge Manager responds to the activation request with Litmus Remote credentials.
- Litmus Edge attempts to establish a permanent connection with inbound port 51820/UDP (Remote Access) of Litmus Edge Manager.
- Litmus Edge Manager receives the connection at inbound port 51820/UDP (Remote Access).
- Litmus Edge confirms the permanent connection with Litmus Edge Manager.
- The permanent connection becomes a secure two-way (bi-directional) connection. Both Litmus Edge and Litmus Edge Manager use Litmus Edge Manager's inbound port 51820/UDP (Remote Access) to communicate with each other.
Port Requirements: Litmus Edge Manager
Configure the following ports:
- Open 443 (HTTPS) inbound/Ingress to receive the initial contact from Litmus Edge (activation).
- Open 51820 (Remote Access) inbound/ingress to receive the permanent connection from Litmus Edge.
- Ensure all outbound communication is available to be able to reach Litmus Edge.
Data Transmission: Default MQTT SSL Connector
After a Litmus Edge-Litmus Edge Manager connection has been established, Litmus Edge Manager can receive metrics data or events data (enable event forwarding separately) from a Litmus Edge instance. For Litmus Edge Manager to receive the data, the Litmus Edge instance must enable its Default Generic MQTT SSL Connector (Integration). After the connector is enabled, the Litmus Edge instance attempts to reach a connection at Litmus Edge Manager's inbound port 8883/TCP.

Note: Ports 443 and 51820 are required for establishing the initial connection. Port 8883 is used for ongoing data transmission when the connection is in place. For additional details about each port, refer to the Firewall Port Configuration Requirements.
Port Customization For Litmus Edge Manager
Open 8883 (MQTT) inbound/ingress to receive the metrics or events data from Litmus Edge.
Limitations and Considerations
- Ports 443 and 51820 must be reachable outbound before activation can begin. The connection cannot be established if either port is blocked.
- The MQTT data channel (port 8883) is independent from the management connection and must be explicitly enabled via the Default Generic MQTT SSL Connector.
- Litmus Edge does not require any inbound ports for its management connection with Litmus Edge Manager.
Related Topics
- Integration