# Ports and endpoints to allow

**URL:** <https://hub.mender.io/t/ports-and-endpoints-to-allow/4412>\
**Category:** General Discussions\
**Created:** [December 18, 2021, 12:23pm UTC](https://hub.mender.io/t/ports-and-endpoints-to-allow/4412 "2021-12-18T12:23:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mkonnov](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mkonnov/32/764_2.png) [@mkonnov](https://hub.mender.io/u/mkonnov)\
**Post date:** [December 18, 2021, 12:23pm UTC](https://hub.mender.io/t/ports-and-endpoints-to-allow/4412/1 "2021-12-18T12:23:41Z")

</div>

Hi everyone !

We have some devices running in a networks where policies denies all access to the NAT and we need to provide the list of particular endpoints and ports that we’ll need to access.

We have allowed `TCP 443 s3.amazonaws.com` since it’s pretty clear from logs that the images are pulling from S3, but still we see the following error (creds are xxx’ed):

```auto
Can not fetch update image: Get "https://s3.amazonaws.com/hosted-mender-artifacts/xxxxxxxxxxxxxxxx/09f73bb9-93da-4e5e-8847-xxxxxxxxxxxxx?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=XXXXXXXXXXXXXXXX%2F20211210%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20211210T000850Z&X-Amz-Expires=86400&X-Amz-SignedHeaders=host&response-content-type=application%2Fvnd.mender-artifact&X-Amz-Signature=xxxxxxxxxxxxxxxxxxxxxxxxxx": read tcp 10.10.11.113:46872->52.216.237.77:443: read: connection reset by peer

```

Could someone provide us a list of necessary endpoints and ports to open for the update to succeed ?

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [December 20, 2021, 9:40am UTC](https://hub.mender.io/t/ports-and-endpoints-to-allow/4412/2 "2021-12-20T09:40:50Z")

</div>

[https://docs.mender.io/overview/security#no-open-ports-on-the-device](https://docs.mender.io/overview/security#no-open-ports-on-the-device)

So you should be good.

For hosted, the only endpoints you will see used are `hosted.mender.io`, and `s3`

---

<div class="post-metadata">

**Author:** ![mkonnov](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mkonnov/32/764_2.png) [@mkonnov](https://hub.mender.io/u/mkonnov)\
**Post date:** [December 20, 2021, 10:46am UTC](https://hub.mender.io/t/ports-and-endpoints-to-allow/4412/3 "2021-12-20T10:46:18Z")

</div>

@oleorhagen sorry, I forgot to specify.  
The ports are going to be open at the firewall, not the device.  
This way, `TCP 443 s3.amazonaws.com` and `TCP 443 hosted.mender.io` are correct ?

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [December 20, 2021, 10:57am UTC](https://hub.mender.io/t/ports-and-endpoints-to-allow/4412/4 "2021-12-20T10:57:32Z")

</div>

That is correct 🙂
