Network & Firewall Requirements

Firewall, port and allowlist requirements for Xyte Connect+ (cloud and Edge).

📘

Firewall & port rules

Every URL, subdomain, and port you need to allow through your firewall for Xyte Connect+ — for both the cloud platform and a self-hosted Edge agent. Also covers: whitelist / allowlist, egress, MQTT ports.

Cloud & Connect+ connectivity

All communication is outbound only — from within the customer network to the internet. No incoming ports are required. Add the following to your firewall allowlist (whitelist):

PurposeDestinationPort
Access the interfaceapp.xyte.io (or your OEM custom domain)443
Devices connecting to the cloud*.xyte.io subdomains443 (HTTPS), 8883 (MQTTS)
Devices with remote tunnelingeu1.tunnel.xyte.com49152–65534

Where an Edge agent is used, configure each managed device to route through the Edge agent, and allow the Edge agent the access above.

Edge agent connectivity

If you run a self-hosted Edge agent, its host machine also needs outbound access to the Xyte Edge endpoints and Docker Hub, plus local access to the devices it monitors (SNMP, HTTP(s), IPMI, etc.). See the full list in Edge Requirements → Networking requirements.

Related terms: firewall, ports, network, allowlist, whitelist, egress, connectivity, MQTT, proxy.


Did this page help you?