APX320 and APX530 using undocumented port 2713 to Heartbeat IP


I'm following https://support.sophos.com/support/s/article/KB-000036137?language=en_US to register new APs in Central.

This was not working until we allowed  Port tcp:2713 to Heartbeat IP. This is undocumented in that KB article.

I cannot even find a Sophos KB about that Port 2713, only some posts in forums. Some have information that there was a bug that APs connected to central on a wrong port and had to be replaced.

Please bring some light into this.

Also NTP was not working until we allowed NTP outgoing to any (!).

openwrt.pool.ntp.org unresolvable... and so is prod.hydra.sophos.com and others from that KB. You should eventually add information that it may be wildcards: *.prod.hydra.sophos.com

