Endpoint Security Required Domains and URLs

WatchGuard and Panda Endpoint Security products require access to multiple Internet-hosted resources. To install and operate Endpoint Security products when you have a firewall, proxy server, or other network restrictions, such as SSL/TLS inspection, you must have access to the URLs and ports listed below.

Recommended URLs and Ports

To allow connections to Endpoint Security products and modules through your firewall, we recommend that you add exceptions for the URLs and ports in this section.

If you cannot use these domains, go to the appropriate section for a comprehensive list of specific URLs and their permutations:

Feature or Function Host Names Ports
Communications Agent

*.watchguard.com

*.pandasecurity.com

*.rc.pandasecurity.com

*.pandasoftware.com

aether100proservicebus.servicebus.windows.net

aether100pronotification.table.core.windows.net

aether100prostorage.blob.core.windows.net

TCP 443

TCP 80

Remote Access *.rc.pandasecurity.com

TCP 443

TCP 8080

URL Filtering

rp.cloud.threatseeker.com

wg.cloud.threatseeker.com

TCP 443

Patch Management

*.ivanti.com

content.ivanti.com

application.ivanti.com

license.shavlik.com

Go to this Ivanti Knowledge Base Article (external link) to review a list of URLs required to download catalog content and patches.

TCP 443

Advanced Visualization

*.pandasecurity.devo.com

TCP 443

Root Certificate Verification

*.globalsign.net

*.globalsign.com

*.digicert.com

*.sectigo.com

TCP 443

TCP 80

IP Addresses Required for IPv6

In addition, allow connections to these IP address ranges for IPv6:

2620:149:a44::/48

2403:300:a42::/48

2403:300:a51::/48

2a01:b740:a42::/48

Domain Name Rules and Exceptions

In addition, we recommend you configure proxies with domain name rules to allow Endpoint Security connections to required domains. Default domain name rules were added in Fireware v12.5.5/v12.6.2.

To allow connections to Endpoint Security products and modules through a Firebox, the default WebBlocker and blocked sites exceptions lists were updated in Fireware v12.5.5/v12.6.2. to include the above URLs.

Exceptions for iOS Devices

The Endpoint Security app installed on Apple mobile device uses the Apple Push Notification service to communicate with the software. If the device is connected to the network by 2G, 3G, or 4G, there are no specific network requirements.

iOS devices that are connected to the network by Wi-Fi, access point (AP) or other method, must be able to connect to specific servers through these ports:

TCP 5223 to communicate with the Apple Push Notification service

TCP 443 or 2197 to send notifications

The Apple Push Notification service uses load balancing. The Apple device will not always connect to the same IP address. We recommend that you configure your firewall to allow connections to the entire 17.0.0.0/8 range assigned to Apple. If this is not possible, at a minimum, allow connections to these IP ranges for IPv4:

17.249.0.0/16

17.252.0.0/16

17.57.144.0/22

17.188.128.0/18

17.188.20.0/23

Panda and Cytomic Endpoint Security Products

This section includes a comprehensive list of specific URLs for Panda and Cytomic products. For more information, go to Local Ports and URL Access (external link).

You do not have to allow a specific URL if you already allow the domain.

Management Agent
Communication between the Server and Management UI through the Gateway Description
https://endpointgw.aether.pandasecurity.com Aether web service URL
https://endpointpgw.aether.pandasecurity.com Aether priority web service URL (only for integrations)
https://accesscontrolgw.aether.pandasecurity.com Packages repository (legacy system compatibility URL for CPU, RAM, and hardware monitoring)
https://storage.accesscontrolmngr.pandasecurity.com Packages repository (legacy system compatibility URL for CPU, RAM, and hardware monitoring)
https://gateway.aether.pandasecurity.com Gateway
   
Communication between the Server and Management UI Description
https://endpointws.aether.pandasecurity.com Aether web service URL
https://endpointpws.aether.pandasecurity.com Aether priority web service URL (only for integrations)
wss://commandhubws.aether.pandasecurity.com Real-time notification service
https://storage.accesscontrol.pandasecurity.com Packages repository (legacy system compatibility URL for CPU, RAM, and hardware monitoring)
https://aether100proservicebus.servicebus.windows.net CPU, RAM, and hardware monitoring URL
https://aether100pronotification.table.core.windows.net Notification service if real-time notification service is not available
   
Updates and Upgrades Description
https://aether100prostorage.blob.core.windows.net Special signature files repository
http://corporate.updates.pandasecurity.com Packages and signature repository
http://corporate.updates.pandasecurity.com/aether/nano Packages and signature repository
https://repository.pandasecurity.com Packages and signature repository
http://acs.pandasoftware.com Third-party vendor uninstallers
https://cpp-repository.pandasecurity.com/ Packages and signature repository
   
Endpoint Security  
Communication with Collective Intelligence Servers — Endpoint Protection and Endpoint Protection Platform Description
https://cpg-kw.pandasecurity.com/kdws/files Knowledge files
https://cpg-kw.pandasecurity.com/kdws/sigs Knowledge signature files
https://cpg-fulg.pandasecurity.com/frws File upload Minerva log messages
https://cpg-fudlp.pandasecurity.com/frws File upload Minerva DLP
https://cpg-fusm.pandasecurity.com/frws/info File upload samples query
https://cpg-fusm.pandasecurity.com/frws File upload samples
https://cpg-fulg.pandasecurity.com/frws File upload Minerva statistics
https://cpg-fuelg.pandesecurity.com/frws File upload Minerva extended statistics (Windows)
https://cpg-fuo.pandasecurity.com/frws File upload contextual
https://cpg-fuo.pandasecurity.com/frws File upload statistics
https://cpg-nap.pandasecurity.com/nap/buffer File upload network attack information
https://iext.pandasecurity.com/ProyIEXT/ServletIExt Malware information
http://proinfo.pandasecurity.com/connectiontest.html Connection test
https://wg.cloud.threatseeker.com/urlinfo URL filtering
https://cpg-fusmb.pandasecurity.com/frws File upload big samples (Windows)
https://cpg-fusmb.pandasecurity.com/bigfiles File upload big samples query (Windows)
https://cpg-fusm.pandasecurity.com/frws/info Deep learning query
https://cpg-fuo.pandasecurity.com/frws Deep learning upload
https://cppl-fuelg.pandasecurity.com/frws File upload Minerva Extended statistics (Linux/Mac)
https://cppl-fusmb.pandasecurity.com/frws File upload big samples (Linux/Mac)
https://cppl-fusmb.pandasecurity.com/bigfiles File upload load big samples query (Linux/Mac)
https://dmp.devicesmc.pandasecurity.com Anti-theft (Android)
 
Communication with Collective Intelligence Servers — Adaptive Defense, Adaptive Defense 360, Adaptive Defense 360A Description
https://cpp-kw.pandasecurity.com/kdws/files Knowledge files
https://cpp-kw.pandasecurity.com/kdws/sigs Knowledge signature files
https://cpp-fulg.pandasecurity.com/frws File upload Minerva log messages
https://cpp-fudlp.pandasecurity.com/frws File upload Minerva DLP
https://cpp-fusm.pandasecurity.com/frws/info File upload samples query
https://cpp-fusm.pandasecurity.com/frws File upload samples
https://cpp-fulg.pandasecurity.com/frws File upload Minerva statistics
https://cpp-fuelg.pandasecurity.com/frws File upload Minerva extended statistics (Windows)
https://cpp-fuo.pandasecurity.com/frws File upload contextual
https://cpp-fuo.pandasecurity.com/frws File upload statistics
https://cpp-nap.pandasecurity.com/nap/buffer File upload network attack information
https://iext.pandasecurity.com/ProyIEXT/ServletIExt Malware information
http://proinfo.pandasecurity.com/connectiontest.html Connection test
https://wg.cloud.threatseeker.com/urlinfo URL filtering
https://cpp-fusmb.pandasecurity.com/frws File upload big samples (Windows)
https://cpp-fusmb.pandasecurity.com/bigfiles File upload big samples query (Windows)
https://cpp-fusm.pandasecurity.com/frws/info Deep learning query
https://cpp-fuo.pandasecurity.com/frws Deep learning upload
https://cppi-fuelg.pandasecurity.com/frws File upload Minerva extended statistics (Linux/Mac)
https://cppi-fusmb.pandasecurity.com/frws File upload big samples (Linux/Mac)
https://cppi-fusmb.pandasecurity.com/bigfiles File upload big samples query (Linux/Mac)
https://dmp.devicesmc.pandasecurity.com Anti-theft (Android)
   
Communication with Collective Intelligence Servers — VIP Description
https://cppe-kw.pandasecurity.com/kdws/files Knowledge files
https://cppe-kw.pandasecurity.com/kdws/sigs Knowledge signature files
https://cppe-fulg.pandasecurity.com/frws File upload Minerva log messages
https://cpp-fudlp.pandasecurity.com/frws File upload Minerva DLP
https://cppe-fusm.pandasecurity.com/frws/info File upload samples query
https://cppe-fusm.pandasecurity.com/frws File upload samples
https://cppe-fulg.pandasecurity.com/frws File upload Minerva statistics
https://cppe-fulg.pandasecurity.com/frws File upload Minerva extended statistics (Windows)
https://cppe-fuo.pandasecurity.com/frws File upload contextual
https://cppe-fuo.pandasecurity.com/frws File upload statistics
https://cpp-nap.pandasecurity.com/nap/buffer File upload network attack information
https://iext.pandasecurity.com/ProyIEXT/ServletIExt Malware information
http://proinfo.pandasecurity.com/connectiontest.html Connection test
https://wg.cloud.threatseeker.com/urlinfo URL filtering
https://cppe-fusmb.pandasecurity.com/frws File upload big samples (Windows)
https://cppe-fusmb.pandasecurity.com/bigfiles File upload big samples (Windows)
https://cppe-fusm.pandasecurity.com/frws/info Deep learning query
https://cppe-fuo.pandasecurity.com/frws Deep learning upload
https://cppi-fuelg.pandasecurity.com/frws File upload Minerva extended statistics (Linux/Mac)
https://cppi-fusmb.pandasecurity.com/frws File upload big samples (Linux/Mac)
https://cppi-fusmb.pandasecurity.com/bigfiles File upload big samples query (Linux/Mac)
https://dmp.devicesmc.pandasecurity.com Anti-theft (Android)
   
Communication with Collective Intelligence Servers — Protection Versions 8.00.18.xx Description
https://rp.cloud.threatseeker.com/urlinfo/ URL filtering
   
Patch Management Description
https://content.ivanti.com Knowledge delivery catalog
https://application.ivanti.com Knowledge delivery catalog
   
Remote Control Access (AEPDR) Description
dir.rc.pandasecurity.com (through port 443) DNS directory
eu01.rc.pandasecurity.com (through ports 8080 and 443) DNS directory
eu02.rc.pandasecurity.com (through ports 8080 and 443) Remote control node
eu03.rc.pandasecurity.com (through ports 8080 and 443) Remote control node
eu04.rc.pandasecurity.com (through ports 8080 and 443) Remote control node
eu05.rc.pandasecurity.com (through ports 8080 and 443) Remote control node
eu06.rc.pandasecurity.com (through ports 8080 and 443) Remote control node
ams01.rc.pandasecurity.com (through ports 8080 and 443) Remote control node
ams02.rc.pandasecurity.com (through ports 8080 and 443) Remote control node
   
PSInfo Description
https://pcopsupport.pandasecurity.com Web service
   
Advanced Visualization Tool — Management UI Description
https://pandasecurity.devo.com Devo console access
   
Root Certificates — Windows Operating Systems Description
http://crl.globalsign.net SSL and codesign certificate provider
http://ocsp.globalsign.com/ SSL and codesign certificate provider
http://ocsp2.globalsign.com SSL and co-design certificate provider
http://cacerts.digicert.com SSL and co-design certificate provider
http://crl.sectigo.com SSL and codesign certificate provider
http://ocsp.sectigo.com SSL and codesign certificate provider

WatchGuard Endpoint Security Products by Data Region

From 26 November 2024, WatchGuard Endpoint Security products require exceptions for new permutations of the collective intelligence server URLs. If you do not have a general exception for *.pandasecurity.com, then you must add the preface wes- to the specific URLs for the collective intelligence servers. For example, you must update the exclusion https://cpg-kw-pandasecurity.com to https://wes-cpg-kw-pandasecurity.com. Go to the appropriate region below for a complete list of the required URLs for WatchGuard Endpoint Security products.

This section includes a comprehensive list of specific URLs for each cloud data region.

You do not have to allow a specific URL if you already allow the domain.

Related Topics

Endpoint Security Network Requirements

WatchGuard Endpoint Security Release Notes (external link)