There is currently no comprehensive section in the Rancher documentation that outlines the firewall rules or network access requirements needed for Rancher and Rancher-managed clusters (RKE1, RKE2, K3s) to function correctly in environments with restricted egress or ingress.
Users deploying Rancher in secure networks (with firewalls, proxies, or air-gapped setups) frequently encounter:
Downstream clusters repeatedly showing as “Disconnected” and “Connected”
These problems often trace back to firewall restrictions and missing allowlist entries, but there is no place in the documentation that helps identify or resolve these.
Proposed Documentation Addition
**Add a new section under Installation > Prerequisites/Configuration titled:**
Configuring your firewall
ex: Set the following registry URLs for your firewall’s allowlist:
registry.rancher.com :
registry.suse.com :
*.suse.com :