---
title: "Firewall Requirements for Infoblox Cloud Services"
canonical: "https://docs.infoblox.com/space/BloxOneInfrastructure/873660456/Firewall%20Requirements%20for%20Infoblox%20Cloud%20Services"
format: markdown
---
Infoblox provides a defined set of IP addresses and domains that must be allowed through your network firewall to ensure uninterrupted connectivity to Infoblox Cloud services and the Infoblox Portal. Whether your environment is deployed in the cloud, in a hybrid architecture, or on‑premises, Infoblox recommends following modern security best practices—such as explicit allowlisting and controlled outbound access—to maintain reliable communication with Infoblox Cloud while protecting your environment.

Before deploying NIOS-X or NIOS servers and Infoblox services, prepare your environment to meet supported platform requirements and open all necessary ports. 

A complete list of IP addresses used by the Infoblox Portal and other cloud services is available in a JSON file by clicking this [link](https://infoblox-allowlist.s3.amazonaws.com/infoblox-hostnames-ips.json). All listed IP addresses require **TCP 443** port be open when being used.

> 📝 **Important Note**
> 📝 
> 📝 When deploying NIOS-X servers as a virtual machine or container, the minimum system resources specified for NIOS-X server deployment must be fully dedicated to the server you are deploying. These resources cannot be shared with or used for other non-Infoblox applications. Sharing resources will degrade performance and negatively affect Infoblox services. For more information, see *[Minimum System Requirements for Servers](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneInfrastructure/pages/873758806)**.*

# NIOS-X and NIOS Server Connectivity to Infoblox Portal

This section details the base connectivity required for NIOS-X and NIOS servers to communicate with the Infoblox Portal. All communicate is initiated from the NIOS-X or NIOS server to the Infoblox Portal. The Infoblox Portal never initiates connectivity to NIOS-X or NIOS servers.

To ensure reliable connectivity from NIOS-X or NIOS servers to the Infoblox Portal, observe the following:

- **DO NOT enable SSL inspection** on your firewall for any of the domains or IP addresses.
- **NIOS-X servers** typically use a single port for both cloud connectivity (control plane) and service delivery (data plane). If multiple interfaces are available, the interface with the lowest routing metric is used to connect to the Infoblox Portal.
- **NIOS servers** typically use the LAN1 port for standalone appliances and the HA port for nodes in an HA pair. The source IP for HA deployment is the **dedicated HA IP** for each node, not the shared HA VIP. If static routes are configured, connectivity to the Infoblox Portal may instead use LAN2 or MGMT, depending on routing.

The table below outlines the connectivity required for NIOS-X and NIOS servers to establish connectivity to the Infoblox Portal for management. Communication detailed in this table can pass through a web proxy but cannot be decrypted.

> 📝 If you configure proxy on NIOS-X server, the Universal DDI DNS service destination (dns.bloxone.infoblox.com:443 for US regions, or dns.bloxone.eu.infoblox.com:443 for EU regions) bypasses the proxy settings because it cannot be proxied.

Note the following when reviewing the table:

- Configure allowlist rules only for the region‑specific portal endpoint:  
**US Region:** csp.infoblox.com   
**EU Region:** csp.eu.infoblox.com
- **Infoblox Server IP** shown in the **Source IP** column refers to the interface on the NIOS‑X or NIOS server that initiates traffic to the Infoblox Portal.
- **Platform Management** manages communication between NIOS‑X and the Infoblox Portal and oversees the operating system and containers.
- **Application Management** manages the services running on NIOS‑X, including service updates.

| **Portal Region** | **Source IP** | **Destination Domain and IP** | **Destination Port** | **Description** |
| --- | --- | --- | --- | --- |
| US | Infoblox Server IP | dns.bloxone.infoblox.com<br>- 18.235.106.26
- 54.224.108.101
- 34.194.149.196 | TCP 443 | Universal DDI service destination |
| csp.infoblox.com<br>- 18.235.149.1
- 18.209.243.220
- 18.233.189.178 | TCP 443 | Infoblox Portal |
| cp.noa.infoblox.com<br>- 3.209.116.255
- 3.210.226.54
- 3.212.42.44 | TCP 443 | Platform Management |
| grpc.csp.infoblox.com<br>- 3.209.116.255
- 3.210.226.54
- 3.212.42.44 | TCP 443 | Platform Management |
| app.noa.infoblox.com<br>- 3.213.214.20
- 3.214.194.152
- 3.214.29.106 | TCP 443 | Application Management |

| **Portal Region** | **Source IP** | **Destination Domain and IP** | **Destination Port** | **Description** |
| --- | --- | --- | --- | --- |
| EU | Infoblox Server IP | dns.bloxone.eu.infoblox.com<br>- 18.153.44.29
- 18.197.230.152
- 18.184.150.241 | TCP 443 | Universal DDI service destination |
| csp.eu.infoblox.com<br>- 3.70.109.229
- 3.73.182.10
- 3.66.44.28 | TCP 443 | Infoblox Portal |
| cp.noa.eu.infoblox.com<br>- 3.124.178.19
- 3.64.74.162
- 3.73.242.251 | TCP 443 | Platform Management |
| grpc.csp.eu.infoblox.com<br>- 3.124.178.19
- 3.64.74.162
- 3.73.242.251 | TCP 443 | Platform Management |
| app.noa.eu.infoblox.com<br>3.71.171.160<br>3.123.100.200<br>18.193.177.184 | TCP 443 | Application Management |
| provision.ib-hub.na.csp.infoblox.com<br>- 44.209.64.78
- 44.218.80.45
- 54.165.131.7 | TCP 443 |  |
| cp.noa.infoblox.com<br>- 3.209.116.255
- 3.210.226.54
- 3.212.42.44 | TCP 443 | Platform Management: Only needed for EU portal connectivity when running on NIOS 8.6.4 or earlier or 9.0.2 or earlier. |
| grpc.csp.infoblox.com<br>- 3.209.116.255
- 3.210.226.54
- 3.212.42.44 |  | Platform Management: Only needed for EU portal connectivity when running on NIOS 8.6.4 or earlier or 9.0.2 or earlier. |

| **Portal Region** | **Source IP** | **Destination Domain and IP** | **Destination Port** | **Description** |
| --- | --- | --- | --- | --- |
| Any Region (US or EU) | Infoblox Server IP | Any DNS server that can resolve these domains: dns.bloxone.infoblox.com<br>- csp.infoblox.com
- cp.noa.infoblox.com
- grpc.csp.infoblox.com
- app.noa.infoblox.com
- dns.bloxone.eu.infoblox.com
- csp.eu.infoblox.com
- cp.noa.eu.infoblox.com
- grpc.csp.eu.infoblox.com
- app.noa.eu.infoblox.com<br>By default, NIOS-X and NIOS servers use the Infoblox Threat Defense Global Anycast Resolver:<br>- 52.119.41.100
- 52.119.40.100 | TCP 53<br>UDP 53 | DNS Server to resolve the domains listed. |
| A reliable NTP server. When deployed on ESXi, the VM will sync to ESXi rather than used the configured value. By default NIOS-X uses:<br>- ntp.ubuntu.com | UDP 123 | NTP server to ensure server time is accurate. |

# Universal DDI Services

The following table describes the specific connectivity requirements for Universal DDI services on NIOS‑X and NIOS servers.

Note the following when reviewing the table:

- Configure allowlist rules only for the region‑specific portal endpoint:  
**US Region:** csp.infoblox.com     
**EU Region:** csp.eu.infoblox.com
- **Infoblox Server IP** shown in the **Source IP** column refers to the interface on the NIOS‑X or NIOS server that initiates traffic to the Infoblox Portal.

| **Portal Region** | **Source IP** | **Destination Domain and IP** | **Destination Port** | **Description** |
| --- | --- | --- | --- | --- |
| US | Infoblox Server IP | dns.bloxone.infoblox.com<br>- 18.235.106.26
- 54.224.108.101
- 34.194.149.196<br>csp.infoblox.com<br>- 18.235.149.1
- 18.209.243.220
- 18.233.189.178<br>cp.noa.infoblox.com<br>- 3.209.116.255
- 3.210.226.54
- 3.212.42.44<br>grpc.csp.infoblox.com<br>- 3.209.116.255
- 3.210.226.54
- 3.212.42.44<br>app.noa.infoblox.com<br>- 3.213.214.20
- 3.214.194.152
- 3.214.29.106 | TCP 443 | Allow these domains and IP addresses on your firewall to enable Infoblox Portal connectivity and ensure that Universal DDI services operate correctly in each region.<br>All listed IP addresses require TCP 443 port be open when being used. |
| EU | Infoblox Server IP | dns.bloxone.eu.infoblox.com<br>- 18.153.44.29
- 18.197.230.152
- 18.184.150.241<br>csp.eu.infoblox.com<br>- 3.70.109.229
- 3.73.182.10
- 3.66.44.28<br>cp.noa.eu.infoblox.com  
grpc.csp.eu.infoblox.com<br>- 3.124.178.19
- 3.64.74.162
- 3.73.242.251<br>app.noa.eu.infoblox.com<br>- 3.71.171.160
- 3.123.100.200
- 18.193.177.184 | TCP 443 |

# Infoblox Threat Defense Connectivity to Infoblox Portal - DNS Forwarding Proxy and External Networks

When deploying DNS Forwarding Proxy (DFP) and external networks on NIOS‑X or NIOS servers, the following connectivity requirements apply.

### **General Connectivity Behavior**

- DFP traffic cannot be sent through a web proxy and cannot be decrypted.
- If a proxy is configured on the NIOS‑X or NIOS server for management communication with the Infoblox Portal, that proxy configuration is **ignored by DFP** when connecting to its required destinations.
- Communication with destination domains bypasses any proxy server setting. If you configure a proxy, the DFP service (threatdefense.infoblox.com:443) bypasses the proxy. Similarly, the Universal DDI service destination ([dns.bloxone.infoblox.com:443](http://dns.bloxone.infoblox.com:443) for US regions, or [dns.bloxone.eu.infoblox.com:443](http://dns.bloxone.eu.infoblox.com:443) for EU regions) bypasses the proxy.
- When a **HTTP proxy is configured on NIOS-X server**, Data Connector is able to pull the log data from Infoblox Cloud through configured proxy. However, do note that as of now the logs sent from data connector to the configured destination will still bypass the proxy.

### **Required Ports**

- DFP must have access to **TCP 443** for all listed IP addresses.
- Access to **UDP 53 and TCP 53** is **strongly recommended** for troubleshooting.
- **UDP 53 and TCP 53 are required** when DNS forwarding flows from known public IP addresses into Infoblox Threat Defense—for example, when forwarding from a BIND server or a Microsoft DNS server.

### **Anycast and Geo‑Specific IP Requirements**

- As a general rule, DFP must be allowed to access the **Global Anycast** IP addresses.
- Access to **geo‑specific Anycast IP addresses** is recommended but not required unless your environment explicitly needs to direct traffic to a specific geographic point of presence (for example, forcing traffic to a specific region).

For more information on geo‑specific IP addresses, see the **Infoblox Geo‑Based Anycast IPs for POPs** table in *[Forwarding DNS Traffic to Infoblox Platform](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35408116)*.

### **NIOS Servers Considerations**

- For NIOS versions less than or equal to 8.6.4, or for NIOS versions less than or equal to 9.0.2:
  - Allow US domains grpc.csp.infoblox.com (3.210.226.54, 3.209.116.255, 3.212.42.44) and csp.infoblox.com (18.233.189.178, 18.235.149.1, 18.209.243.220), along with all EU region IP addresses.
- For NIOS versions greater than or equal to 8.6.5, or for NIOS versions greater than or equal to 9.0.3:
  - For NIOS DNS resolver: Allow external domain lookup and all EU region IP addresses.
  - For NIOS running behind HTTPS Proxy and if external domain lookup is denied: Allow domain `provision.ib-hub.na.csp.infoblox.com` and this IP address `44.218.80.45`, along with all EU region IP addresses.

The following table describes the specific connectivity requirements for DFP and external networks on NIOS‑X and NIOS servers.

Note the following when reviewing the table:

- The portal region for all entries in the following table is for **Any Region**, either the US or EU region. Configure allowlist rules for any of the region‑specific portal endpoints:  
**US Region:** csp.infoblox.com    
**EU Region:** csp.eu.infoblox.com
- **Infoblox Server IP** shown in the **Source IP** column refers to the interface on the NIOS‑X or NIOS server that initiates traffic to the Infoblox Portal.

| **Source IP** | **Destinations Domain and IP** | **Destination Port** | **Description** |
| --- | --- | --- | --- |
| Infoblox Server IP | threatdefense.infoblox.com<br>Anycast IPs (IPv4 and IPv6)<br>- 52.119.40.100 (default resolver)
- 52.119.41.100
- 103.80.5.100
- 103.80.6.100
- 2620:129:6000::100
- 2400:4840::100 | TCP 443<br>UDP 53<br>TCP 53 | Infoblox uses 52.119.40.100 as the default local resolver for all NIOS-X servers.<br>However, you can use your own local resolver to resolve the destination domains. |
| Infoblox Server IP | us-west-1-geo.threatdefense.infoblox.com<br>- 52.119.41.51
- 103.80.6.51 | TCP-443<br>UDP-53<br>TCP-53 | California (USA) |
| Infoblox Server IP | us-east-1-geo.threatdefense.infoblox.com<br>- 52.119.41.52
- 103.80.6.52 | TCP-443<br>UDP-53<br>TCP-53 | Virginia (USA) |
| Infoblox Server IP | eu-west-2-geo.threatdefense.infoblox.com<br>- 52.119.41.53
- 103.80.6.53 | TCP-443<br>UDP-53<br>TCP-53 | London (England) |
| Infoblox Server IP | eu-central-1-geo.threatdefense.infoblox.com<br>- 52.119.41.54
- 103.80.6.54 | TCP-443<br>UDP-53<br>TCP-53 | Frankfurt (Germany) |
| Infoblox Server IP | ap-south-1-geo.threatdefense.infoblox.com<br>- 52.119.41.55
- 103.80.6.55 | TCP-443<br>UDP-53<br>TCP-53 | Mumbai (India) |
| Infoblox Server IP | ap-northeast-1-geo.threatdefense.infoblox.com<br>- 52.119.41.56
- 103.80.6.56 | TCP-443<br>UDP-53<br>TCP-53 | Tokyo (Japan) |
| Infoblox Server IP | ap-southeast-1-geo.threatdefense.infoblox.com<br>- 52.119.41.57
- 103.80.6.57 | TCP-443<br>UDP-53<br>TCP-53 | Singapore |
| Infoblox Server IP | ca-central-1-geo.threatdefense.infoblox.com<br>- 52.119.41.58
- 103.80.6.58 | TCP-443<br>UDP-53<br>TCP-53 | Toronto (Canada) |
| Infoblox Server IP | ap-southeast-2-geo.threatdefense.infoblox.com<br>- 52.119.41.59
- 103.80.6.59 | TCP-443<br>UDP-53<br>TCP-53 | Sydney (Australia) |
| Infoblox Server IP | sa-east-1-geo.threatdefense.infoblox.com<br>- 52.119.41.60
- 103.80.6.60 | TCP-443<br>UDP-53<br>TCP-53 | San Paulo (Brazil) |
| Infoblox Server IP | me-south-1-geo.threatdefense.infoblox.com<br>- 52.119.41.61
- 103.80.6.61 | TCP-443<br>UDP-53<br>TCP-53 | Bahrain (UAE) |
| Infoblox Server IP | af-south-1-geo.threatdefense.infoblox.com<br>- 52.119.41.62
- 103.80.6.62 | TCP-443<br>UDP-53<br>TCP-53 | Johannesburg (South Africa) |
| Infoblox Server IP | us-east-2-geo.threatdefense.infoblox.com<br>- 52.119.41.63
- 103.80.6.63 | TCP-443<br>UDP-53<br>TCP-53 | Ohio (USA) |
| Infoblox Server IP | ap-south-2-geo.threatdefense.infoblox.com<br>- 52.119.41.64
- 103.80.6.64 | TCP-443<br>UDP-53<br>TCP-53 | Hyderabad (India) |
| Infoblox Server IP | ap-east-1-geo.threatdefense.infoblox.com<br>- 52.119.41.65
- 103.80.6.65 | TCP-443<br>UDP-53<br>TCP-53 | Hong Kong |
| Infoblox Server IP | ope.infobloxtd.com<br>- 52.119.41.120
- 103.80.6.120 | TCP-443 | Only used when The "Local On-Prem Resolution" feature of Infoblox Threat Defense is enabled on the DFP service. API endpoint for query validation. |
| Infoblox Server IP | tide.infoblox.com<br>- 18.204.66.140
- 18.205.9.66
- 18.207.20.176 | TCP-443 |  |
| Client endpoint | doh.threatdefense.infoblox.com<br>- 52.119.41.200
- 103.80.6.200 | TCP-443 | Only used by DoH clients connecting to Infoblox Threat Defense cloud |

# Infoblox Threat Defense - Redirect Pages

If you are configuring Infoblox Threat Defense to redirect users to a block page, user endpoints must be able to reach the web page. When using Infoblox’s redirect server, the following table lists the IP addresses that the user endpoints must be able to reach in order to see the block page.

| **Portal Region** | **Source IP** | **Destination Domain and IP** | **Destination Port** | **Description ** |
| --- | --- | --- | --- | --- |
| US | User endpoint (laptop, PC, phone, etc.) | For IPv4:<br>- 3.215.231.251
- 3.216.243.225
- 35.168.95.233
- 54.173.31.46
- 3.220.140.235<br>For IPv6:<br>- 2600:1f18:1043:dc00:8083:68e:ef0f:46de
- 2600:1f18:1043:dc02:ed26:448b:247:90c9
- 2600:1f18:1043:dc00:a339:63ac:4c02:9531
- 2600:1f18:1043:dc00:5ee5:908d:8892:f214
- 2600:1f18:1043:dc02:be4:9bb:7833:d9d4
- 2600:1f18:68e9:d501:bbbb:f976:1d82:c018
- 2600:1f18:68e9:d501:9099:5155:b416:8188
- 2600:1f18:68e9:d500:9efd:6649:c6e4:99ca
- 2600:1f18:68e9:d500:b400:f5c6:c0b1:da3b
- 2600:1f18:68e9:d501:4856:1588:bf9c:b4ab | TCP 443<br>TCP 80 | An end client or end user must be connected to the redirect server.<br>Access to redirect server that will display a block page.<br>For HTTPS connections, client must have the Infoblox Root CA installed to avoid browser error. |
| EU | User endpoint (laptop, PC, phone, etc.) | - 3.78.45.190
- 52.58.168.16
- 3.76.18.216
- 3.76.130.20
- 3.77.69.136 | TCP 443<br>TCP 80 |

# Infoblox Cloud Discovery - Universal Asset Insights

In the Infoblox Portal, you can enable direct, API-based discovery and management of your cloud services (e.g., AWS, Azure, GCP, Akamai, Cloudflare, etc.). If your cloud services support it, you can restrict API access to known, trusted source IP addresses, reducing the risk of unauthorized access.

To enforce this restriction, you must add the Infoblox-provided IP addresses to your inbound allowlist or firewall rules. Infoblox initiates API requests to your environment from these designated IP addresses. If they are not explicitly allowed, the API communication will be blocked.

The following table describes the specific connectivity requirements for the Cloud Discovery service running on NIOS‑X and NIOS servers.

Note the following when reviewing the table:

- The portal region for all entries in the following table is for **Any Region**, either the US or EU region. Configure allowlist rules for any of the region‑specific portal endpoints:  
**US Region:** csp.infoblox.com     
**EU Region:** csp.eu.infoblox.com
- **Infoblox Server IP** shown in the **Source IP** column refers to the interface on the NIOS‑X or NIOS server that initiates traffic to the Infoblox Portal.

| **Portal Region** | **Source IP** | **Destination IP** | **Destination Port** | **Description** |
| --- | --- | --- | --- | --- |
| US | Infoblox Portal<br>- 3.221.42.234 | Not specified. It will be the public cloud provider you have configured discovery and/or management for. | TCP 443 | Access to a redirect server that will display a block page.<br>For HTTPS connections, client must have the Infoblox Root CA installed to avoid browser error. |
| EU | Infoblox Portal<br>- 3.123.171.35
- 52.58.79.200
- 18.197.79.108 |

# Admin User Firewall Requirements

|  | **Allowed Domains** | **Allowed**  
**Port** | **Description** |
| --- | --- | --- | --- |
| Infoblox admins | **US Region**<br>- csp.infoblox.com
- auth.infoblox.com
- *.oktacdn.com
- infoblox-external.okta.com
- cdnjs.cloudflare.com
- d21fqoalzyz7ml.cloudfront.net<br>**EU Region**<br>- csp.eu.infoblox.com | TCP (TLS) 443 | - For HTTPS traffic to all domains
- For URL filtering to access the Infoblox Portal |

# Port Usage for Infoblox Cloud Services

<span style="color: #000000">The following table lists the ports that must be available on your firewall for Infoblox services to function properly. </span>

> ⚠️ ### Note
> ⚠️ 
> ⚠️ All ports listed below are outbound only, except for transferring logs from NIOS to Data Connector, which requires inbound communication.


| **Services** | **Protocol** | **Destination Port** | **Description** |
| --- | --- | --- | --- |
| All Infoblox services | TCP | 443 | - <span style="color: #000000">For Infoblox Portal access. (unrestricted outbound access to TCP 443)</span>
- <span style="color: #000000">For NIOS-X server platform and application management</span>.
- All listed IP addresses require TCP 443 port be open when being used. |
| DNS Forwarding Proxy | TCP<br>UDP | 53 | DNS Forwarding Proxy uses 52.119.40.100 as the default resolver. However, you can use your own local resolver to resolve the destination domains. |
| DHCP server | UDP | 67 | **Warning**: To avoid security issues, ensure that you restrict access to the DHCP control agent while allowing access to the port. |
| Infoblox DNS | TCP | 443 | <span style="color: #000000">For Universal DDI authoritative DNS cloud services.</span><br>- 54.224.108.101
- 18.235.106.26
- 34.194.149.196 |
| DHCP HA (High Availability) | TCP/UDP | 647<br>746<br>847 | These are incoming ports for the HA (high availability) features.<br>The receiving peer must be capable of receiving traffic on the designated port, while the sending peer should be able to transmit traffic to that port, typically from various random ports. Best security practices usually limit access to the device and its ports from peer High Availability (HA) devices. Additionally, it is advisable to utilize a secure channel, especially if the devices are geographically separated rather than connected to the same switch.<br>**Warning**: To avoid security issues, ensure that you restrict access to the DHCP control agent while allowing access to the port. |
| Data Connector | TCP | 22 | Open this port if you want to send data using SCP (Secure Copy Protocol) from the Infoblox NIOS appliance (if configured) to Data Connector.<br><span style="color: #111111">The NIOS UI provides a mechanism to filter the domains it sends to Data Connector. Since NIOS is sending cache logs, when configuring NIOS for use with Data Connector, make sure to configure Data Connector to exclude internal corporate and authoritative domains (*.<corp>/Authorititative). By excluding corporate and authoritative domains, internal traffic logs will not be added.</span><br><span style="color: #000000">Required for incoming SCP data transfer from NIOS to Data Connector when deployed as a container. When you deploy Data Connector as a container, ensure that there are no SSH processes listening on port 22. You must terminate these SSH processes for Data Connector to collect data from NIOS.</span><br><span style="color: #000000">If you deploy Data Connector as a container, ensure that there are no SSH processes listening on port 22. You must terminate these SSH processes for Data Connector to collect data from NIOS.</span> |
| Data Connector | TCP | 514 | Open this port if you want to send syslog and secure syslog for RPZ from the Infoblox NIOS appliance (if configured) to Data Connector. **Note**: Port 514 is an insecure port.<br><span style="color: #111111">The NIOS UI provides a mechanism to filter the domains it sends to Data Connector. Since NIOS is sending cache logs, when configuring NIOS for use with Data Connector, make sure to configure Data Connector to exclude internal corporate and authoritative domains (*.<corp>/Authoritative). By excluding corporate and authoritative domains, internal traffic logs will not be added.</span><br><span style="color: #000000">Required for Data Connector secure syslog for RPZ hits data. If you deploy Data Connector as a container, ensure that this port is not used by other processes.</span><br><span style="color: #000000">If you deploy Data Connector as a container, ensure that this port is not used by other processes for Data Connector to collect data from NIOS.</span> |
| Data Connector | TCP | 6514 | Open this port if you want to send syslog and secure syslog for RPZ from the Infoblox NIOS appliance (if configured) to Data Connector.   
**Note**: Port 6514 is a secure port.<br><span style="color: #111111">The NIOS UI provides a mechanism to filter the domains it sends to Data Connector. Since NIOS is sending cache logs, when configuring NIOS for use with Data Connector, make sure to configure Data Connector to exclude internal corporate and authoritative domains (*.<corp>/Authoritative). By excluding corporate and authoritative domains, internal traffic logs will not be added.</span><br><span style="color: #000000">Used for transferring syslog data from NIOS to Data container. Port 6514 is a default secure port. If you deploy Data Connector as a container, ensure that this port is not used by other processes.</span><br><span style="color: #000000">If you deploy Data Connector as a container, ensure that this port is not used by other processes for Data Connector to collect data from NIOS.</span> |

# Government Cloud (gov-prod) Connectivity

For NIOS-X servers deployed in the Infoblox Government Cloud (gov-prod) environment, additional ports are required to enable connectivity to the Infoblox Portal and to perform diagnostic commands from the portal.

The following table describes the connectivity requirements for NIOS-X servers in the Infoblox Government Cloud (gov-prod) environment.

| **Source IP** | **Destination Domain and IP** | **Protocol** | **Destination Port** | **Description** |
| --- | --- | --- | --- | --- |
| Customer IP address or subnet | [onprem-teleport-csp.gov-prd-2.box.prd.infoblox-fedcloud.com](http://onprem-teleport-csp.gov-prd-2.box.prd.infoblox-fedcloud.com)<br>- 40.38.145.224 | SSH | 3023 | Allows the Infoblox server's troubleshooting service to connect to the Infoblox Portal. If these ports are not allowed, performing diagnostic commands from the Portal will time out. |
| SSH | 3024 |
| HTTPS | 3026 |
| HTTPS | 3036 |
| HTTPS | 3080 |