Establishing an LE-LEM Connection from Litmus Edge
A Litmus Edge (LE)-Litmus Edge Manager (LEM) connection is a persistent, secure channel between Litmus Edge and Litmus Edge Manager. It enables centralized remote management of the gateway, including activation, credential provisioning, and forwarding of metrics and events to Litmus Edge Manager.
The connection uses two ports for establishment: port 443/TCP for the initial activation handshake and port 51820/UDP for the permanent bi-directional remote access tunnel. An optional third port (8883/TCP) supports ongoing MQTT data transmission after the connection is in place.
Note: For details on the Litmus Edge Manager port customization for this connection, see Establishing a Litmus Edge-Litmus Edge Manager Connection: From the Litmus Edge Manager Side.
Core Components
Component | Role |
|---|---|
Litmus Edge | The edge gateway. Initiates all connections outbound to Litmus Edge Manager |
Litmus Edge Manager | The centralized management platform. Receives and approves connections |
Port 443/TCP (HTTPS) | Initial activation channel |
Port 51820/UDP (Remote Access) | Permanent bidirectional management tunnel |
Port 8883/TCP (MQTT SSL) | Ongoing metrics and event data transmission (optional) |
Connection Sequence
The following steps describe how Litmus Edge initiates and establishes its connection with Litmus Edge Manager. From the Litmus Edge side, the key actions are entering the activation URL and code (step 1) and confirming the permanent connection once it is established (step 7).
- Litmus Edge user enters activation URL and activation code. See Step 2: Create an Activation Request in Litmus Edge section of Activate an Edge Device for details.
- Litmus Edge attempts to establish an initial connection with inbound port 443/TCP (HTTPS) of Litmus Edge Manager.
- Litmus Edge Manager receives the connection at its inbound port 443/TCP (HTTPS).
- Litmus Edge sends an activation request that is received and approved by Litmus Edge Manager. See Step 3: Approve the Activation Request in Litmus Edge Manager section of Activate an Edge Device for details.
- Litmus Edge sends activation requests on port 443/TCP of Litmus Edge Manager.
- Litmus Edge Manager user accepts the activation request in UI.
- Litmus Edge Manager responds to the activation request with Litmus Remote credentials.
- Litmus Edge attempts to establish a permanent connection with inbound port 51820/UDP (Remote Access) of Litmus Edge Manager.
- Litmus Edge Manager receives the connection at inbound port 51820/UDP (Remote Access).
- Litmus Edge confirms the permanent connection with Litmus Edge Manager.
- The permanent connection becomes a secure two-way (bi-directional) connection. Both Litmus Edge and Litmus Edge Manager use Litmus Edge Manager's inbound port 51820/UDP (Remote Access) to communicate with each other.
Port Requirements: Litmus Edge
Configure the following outbound ports on Litmus Edge:
- Open outbound port 443/TCP to reach Litmus Edge Manager (activation).
- Open outbound port 51820/UDP to reach Litmus Edge Manager (permanent connection).
- Open outbound port 8883/TCP to reach Litmus Edge Manager (MQTT data, if enabled).
Data Transmission: Default MQTT SSL Connector
After a Litmus Edge-Litmus Edge Manager connection has been established, Litmus Edge Manager can receive metrics data or events data (enabling event forwarding is needed) from a Litmus Edge instance. For Litmus Edge Manager to receive the data, the Litmus Edge instance must enable its Default Generic MQTT SSL Connector (Integration). Once the connector is enabled, the Litmus Edge instance attempts to reach a connection at Litmus Edge Manager's inbound port 8883/TCP.

Note: Ports 443 and 51820 are required for establishing the initial connection. Port 8883 is used for ongoing data transmission once the connection is in place. For additional details about each port, see Firewall Port Configuration Requirements.
Limitations and Considerations
- Ports 443 and 51820 must be reachable outbound before activation can begin. The connection cannot be established if either port is blocked.
- The MQTT data channel (port 8883) is independent from the management connection and must be explicitly enabled via the Default Generic MQTT SSL Connector.
- Litmus Edge does not require any inbound ports for its management connection with Litmus Edge Manager.
Related Topics
- Integration