In separate network mode, the Connect gateway communicates with the cloud via the WAN port internet connection. The firewall of the WAN port allows outgoing connections only, and so the inbound port list and firewall configuration apply to the LAN port(s).
During the installation of an app, the relevant firewall settings are appended to the existing ones, which normally do not have to be modified manually. When it is necessary to open a range of ports, these are specified in Network > Firewall in the fields for UDP and TCP ports, respectively.
Open ports are listed in the top pane. The bottom left pane lists ports reserved for EdgeOS communication - these ports cannot be open by the application or the web UI. The bottom right pane lists the port ranges required and opened by the installed applications. Ports that are in the allow-list (with the exception of reserved system ports) can be opened from applications or via the web UI.
For firewall recommendations and general settings, see Connect Gateway Cybersecurity guidelines, https://siemens.com/bt/download → ID: A6V12604901 (requires login).