# Hosted server required firewall rules

**URL:** <https://hub.mender.io/t/hosted-server-required-firewall-rules/6719>\
**Category:** General Discussions\
**Tags:** hosted-mender, firewall, ports\
**Created:** [April 9, 2024, 9:57am UTC](https://hub.mender.io/t/hosted-server-required-firewall-rules/6719 "2024-04-09T09:57:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michal](https://avatars.discourse-cdn.com/v4/letter/m/34f0e0/32.png) [@Michal](https://hub.mender.io/u/Michal)\
**Post date:** [April 9, 2024, 9:57am UTC](https://hub.mender.io/t/hosted-server-required-firewall-rules/6719/1 "2024-04-09T09:57:26Z")

</div>

Hello,  
We have some devices, that are placed behind strict firewall in customrs network and are connecting to [hosted.mender.io](http://hosted.mender.io) server.  
We have directed the customer to unblock 443 port and [hosted.mender.io](http://hosted.mender.io) url.  
Devices are reporting status and inventory correctly, but I can not get the update through (it stucks in downloading state).  
I don’t have remote access to devices, so can not test it using wget :-/

Is there any list of required ports/urls for hosted Mender to work correctly?

Thanks in advance,  
Michal Špánik

---

<div class="post-metadata">

**Author:** ![robgio](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/robgio/32/1760_2.png) [@robgio](https://hub.mender.io/u/robgio)\
**Post date:** [April 9, 2024, 10:08am UTC](https://hub.mender.io/t/hosted-server-required-firewall-rules/6719/2 "2024-04-09T10:08:32Z")

</div>

Hi @Michal , yes: you can check this requirements page: [Requirements | Mender documentation](https://docs.mender.io/overview/requirements)

---

<div class="post-metadata">

**Author:** ![Michal](https://avatars.discourse-cdn.com/v4/letter/m/34f0e0/32.png) [@Michal](https://hub.mender.io/u/Michal)\
**Post date:** [April 9, 2024, 10:26am UTC](https://hub.mender.io/t/hosted-server-required-firewall-rules/6719/3 "2024-04-09T10:26:31Z")

</div>

Hi @robgio thanks, I missed that page. So all 5 urls are required for successful deployment?  
I can see, that last went into effect in December, is it subject to change dynamically in future, so we need to watch it out, or was it one time change?

Thank you very much.

---

<div class="post-metadata">

**Author:** ![robgio](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/robgio/32/1760_2.png) [@robgio](https://hub.mender.io/u/robgio)\
**Post date:** [April 9, 2024, 11:07am UTC](https://hub.mender.io/t/hosted-server-required-firewall-rules/6719/4 "2024-04-09T11:07:18Z")

</div>

Hi @Michal , it depends on your plan; if you’re not using an Enterprise plan, for sure your artifacts are hosted on Cloudflare, so you just need `https://c271964d41749feb10da762816c952ee.r2.cloudflarestorage.com` for Artifacts storage access, and `*.hosted.mender.io` for UI and API: you can ignore `*s3.amazonaws.com`.

There is no plan to change these URLs, for sure not dynamically: it was a one time change.
