From / To Rancher Nodes Hosted / Imported Cluster External Load Balancer Internet
Rancher Nodes (1) Kubernetes API
Endpoint Port (2)
git.rancher.io (3):
35.160.43.145:32
35.167.242.46:32
52.33.59.17:32
Hosted / Imported Cluster 443 TCP (4)(5) 443 TCP (5)
External Load Balancer (5) 80 TCP
443 TCP (6)
API / UI Clients 80 TCP (4)
443 TCP (4)
80 TCP
443 TCP
Workload Client Cluster / Provider Specific (7)
Notes:

1. Nodes running standalone server or Rancher HA deployment.
2. Only for hosted clusters.
3. Required to fetch Rancher chart library.
4. Only without external load balancer.
5. From worker nodes.
6. Only if SSL is not terminated at external load balancer.
7. Usually Ingress backed by infrastructure load balancer and/or nodeport.