Network & Firewall Requirements
Firewall, port and allowlist requirements for Xyte Connect+ (cloud and Edge).
Firewall & port rulesEvery URL, subdomain, and port you need to allow through your firewall for Xyte Connect+ — for both the cloud platform and a self-hosted Edge agent. Also covers: whitelist / allowlist, egress, MQTT ports.
Cloud & Connect+ connectivity
All communication is outbound only — from within the customer network to the internet. No incoming ports are required. Add the following to your firewall allowlist (whitelist):
| Purpose | Destination | Port |
|---|---|---|
| Access the interface | app.xyte.io (or your OEM custom domain) | 443 |
| Devices connecting to the cloud | *.xyte.io subdomains | 443 (HTTPS), 8883 (MQTTS) |
| Devices with remote tunneling | eu1.tunnel.xyte.com | 49152–65534 |
Where an Edge agent is used, configure each managed device to route through the Edge agent, and allow the Edge agent the access above.
Edge agent connectivity
If you run a self-hosted Edge agent, its host machine also needs outbound access to the Xyte Edge endpoints and Docker Hub, plus local access to the devices it monitors (SNMP, HTTP(s), IPMI, etc.). See the full list in Edge Requirements → Networking requirements.
Related terms: firewall, ports, network, allowlist, whitelist, egress, connectivity, MQTT, proxy.
Updated about 2 hours ago
