Skip to content
    Securly Learn DocsSign in
    All documentation

    Filter › Filter Deployment

    Securly IPs and network requirements

    Filter

    Securly's IPs are cluster-specific. We also have different ranges depending on which filtering method you use.

    DNS

    Cluster Direction IPs Protocol Port
    USWest Outbound 50.18.216.174, 50.18.216.175 tcp and udp 53
    USEast Outbound 184.72.238.58, 184.72.238.71 tcp and udp 53
    USEast2 Outbound 18.220.192.95, 18.220.192.111 tcp and udp 53
    Canada Outbound 35.182.41.111, 52.60.36.138 tcp and udp 53
    EUWest Outbound 54.217.222.125, 54.217.222.126 tcp and udp 53
    APSE Outbound 13.55.55.222, 13.54.54.237 tcp and udp 53
    UK Outbound 3.10.96.65,  3.10.73.55 tcp and udp 53

     

    DNS Proxy

    Cluster Direction IPs Protocol Port
    USWest Outbound 204.110.220.0/22 tcp 80, 443
    USEast Outbound 67.226.220.0/22 tcp 80, 443
    USEast2 Outbound 67.226.220.0/22 tcp 80, 443
    Canada Outbound 15.222.216.148,15.222.199.159 tcp 80, 443
    EUWest Outbound 52.209.63.176/28 tcp 80, 443
    APSE Outbound 3.105.5.81,3.105.5.82 tcp 80, 443
    UK Outbound 3.10.184.103, 3.9.7.162 tcp 80, 443

     

    SmartPAC

    Cluster Directions IPs Protocol Port
    USWest Outbound 52.52.63.0/24, 204.110.220.11 tcp 80, 443
    USEast Outbound 52.206.255.0/24, 67.226.220.10 tcp 80, 443
    USEast2 Outbound 3.19.0.0/16 & 67.226.220.0/22, 67.226.222.2 tcp 80, 443
    Canada Outbound 15.222.216.148,15.222.199.159, 35.182.7.190 tcp 80, 443
    EUWest Outbound

    52.209.63.176, 52.209.63.185, 99.80.88.225

    tcp 80, 443
    APSE Outbound 3.105.5.81, 3.105.5.82, 3.105.5.84 tcp 80, 443
    UK Outbound 3.10.184.103, 3.9.7.162, 35.176.229.223 tcp 80, 443

     

    Destination Based Guest Network Policy

    Cluster Directions IPs Protocol Port
    USWest Outbound 52.9.127.56, 52.52.89.151 tcp and udp 53
    USEast Outbound 18.206.0.166, 3.226.219.211 tcp and udp 53
    USEast2 Outbound 18.219.22.71, 13.59.234.13 tcp and udp 53
    Canada Outbound 35.183.218.234, 35.182.94.148 tcp and udp 53
    EUWest Outbound 3.248.136.77, 3.248.126.133 tcp and udp 53
    APSE Outbound 13.236.78.12, 13.210.121.137 tcp and udp 53
    UK Outbound 3.10.89.14, 3.10.101.46 tcp and udp 53

    Classroom

    If Share Screen is not working, please make sure that the following port and access to the following URL is open.

    Port: 3478

    Streaming Service Server address: http://streaming.deviceconsole.securly.com/

    MDM

    For Apple devices to work properly with Securly MDM, devices need to be able to Communicate with Securly Device Console and receive Apple Push Notifications (APN)

    Securly MDM Communication

    To allow communication with Securly MDM, please allow traffic to and from the following IP addresses on ports 80 and 443:

    54.164.36.33

    52.73.26.101

    54.165.240.169 (needed for device enrollment)

    18.205.10.56 (needed for device enrollment)

    Apple Push Notifications

    If Apple devices don't seem to be communicating with MDM when issuing MDM commands, it could be because they are not receiving Apple Push Notifications due to your firewall. You may need to unblock certain ports for APN to work. You can find details in this Apple KB article: https://support.apple.com/en-us/HT210060

    Apple DEP Enrollment

    DEP Enrollment needs IP resolution for mdmenrollment.apple.com. In order to make sure there are no connectivity issues to mdmenrollment.apple.com, please verify connectivity to the below IP ranges in addition to the current ACLs:

    17.248.128.0/17

    17.248.192.0/19

    2620:149:a40::/46

    2a01:b740:a41::/48

    2403:300:a41::/48

    2403:300:a50::/48

    You may need to whitelist a number of servers in order for Apple devices to properly communicate with iTunes and DEP enrollment. You can find a list of these servers in the Apple KB article: https://support.apple.com/en-us/HT201999.

    Intruder Detection: Some Firewalls provide intruder detection systems or IDS. This looks for patterns of traffic that might indicate an attack and can temporarily shut down communication with the suspected offending IP address for a given number of minutes before clearing the alert. This can explain situations where things seem to be working fine, then devices suddenly stop communicating or receiving commands from MDM for some length of time, like an hour, before working again. It's possible that your system could see a flood of push notifications on your devices as a threat and trigger a false positive pattern, thinking it's an attempted attack. You may want to temporarily disable intruder detection when troubleshooting these types of issues.

    Troubleshooting Tip #1 - Try another network: If devices are not communicating properly, one of the best first steps in troubleshooting is to determine if it's related to your network by taking a couple of devices OUTSIDE of your network and putting them on a mobile hotspot, phone tether, or home network. If the device works properly in that environment, then you know you need to work on your network's firewall or filtering. This is one of the first things a Securly support technician will ask you to verify when troubleshooting issues that might be related to connectivity.

    Troubleshooting Tip #2 - Feature disable: Temporarily disable different types of filtering offered by your firewall until you find which one is detecting something that it doesn’t like. For example, your firewall might have intruder alert detection of various types or different types of filtering and blocking. Turn it off just one at a time. Once you find the one that’s the problem, you may be able to configure it to skip checking for just our URL or IP address only so that you don’t have to leave the feature off completely.

    Other:

    Barracuda Firewalls: Try using "IP Bypass" for the sites and ports above

    Sonicwall Firewalls: Look for "CFS exclusion" under Security Services

     

    You're viewing the text-only version of the Securly Learn help center. Sign in for search, the AI assistant, images, audio, and downloads.