Peter Stuge wrote:
The Gerrit server communicates directly with your OpenID provider,
To clarify, this is in addition to you communicating with the Gerrit web interface and you communicating with the OpenID provider's web interface.
so you do not have to consider this part in the firewall configuration.
Access to the OpenID provider's web interface is also needed, because you will log in there when you want to sign in to Gerrit.
//Peter