Scalefusion is a cloud-hosted solution with servers across the continents. This means devices enrolled and managed by Scalefusion need to have continuous access to Scalefusion's servers so that they can be managed in real-time. The devices also need to have a connection with Google Push services, Apple Push services and Windows Push services, along with other components that are required for the management of devices. Also, to access Scalefusion's Dashboard, the PC/Laptop needs to have access to certain IPs and URLs.
However, an organization might be restricting internet access on their corporate-managed devices and/or PCs/Laptops by using a firewall or a proxy. In such cases, it becomes important to allow the URLs, IPs and ports required for Scalefusion to work smoothly in your organization.
This guide outlines the Firewall settings that need to be done for Scalefusion and OneIdP.
Scalefusion Instances
To comply with data residency regulations, Scalefusion operates multiple regional instances:
Instance Name | URL | Location |
|---|---|---|
Global (EU) | EU | |
US | USA | |
India | India | |
MEA | UAE |
Ensure firewall rules are applied according to the instance your organization uses.
General Firewall Requirements (All Regions)
URL/Domain/FQDN | Ports | Protocol | Direction | Description |
|---|---|---|---|---|
80, 443 | HTTP/S | Outbound | Main domain for API and dashboard access. | |
80, 443 | HTTP/S | Outbound | Core Scalefusion services. | |
Google FCM/GCM | 5228-5230, 443 | TCP | Outbound | Google GCM/FCM push notification connectivity. |
*.pushy.me | 443, 8883 | HTTPS/TCP | Outbound | Pushy messaging domains |
*.pushy.io | 443, 8883 | HTTPS/TCP | Outbound | Pushy messaging domains |
s1.xirsys.com, .xirsys.com .xirsys.net | 80,443,3478, 5349 | HTTP/S/TCP/UDP | Outbound | Used for device discovery and P2P connections for Remote Cast & Control |
Pushy Service Endpoints: Pushy's firewall requirement is covered by the wildcard domains .pushy.me and .pushy.io. Individual service endpoints such as api.pushy.me and mqtt.pushy.me do not need to be added as separate firewall entries.
Pushy does not publish a complete list of FQDNs/subdomains for firewall allowlisting. Wildcard allowlisting is the supported approach.
Recommendation: Whitelist wildcard domains to simplify firewall maintenance and include all current and future subdomains.
Why do we require Port 80 for mobilock.in and scalefusion.com?
These URLs are typically used to access Dashboard/Console and when a user/Admin types in the URL without explicit https:// prefix, then the request is made on port 80. We use this call to redirect to https:// URL. However if you don’t want this routing then allowing port 80 can be avoided.
Why does the Xirsys URL require port 80?
Scalefusion uses Xirsys to support Remote Cast & Control sessions that happen over WebRTC. Xirsys services, particularly WebRTC TURN/STUN servers, require specific firewall configurations to ensure connectivity, generally relying on HTTP/HTTPS ports for signalling and specialised ports for TURN traffic.Essential settings include enabling TCP and UDP, allowing outbound traffic on ports 80, 443, 3478, and 5349, and permitting outbound UDP traffic for media transmission, with options to narrow down to specific IP addresses if necessary.
Device Platform Specific Firewall Settings
Android
URL/Domain/FQDN | Ports | Protocol | Direction | Description |
|---|---|---|---|---|
Android Enterprise Docs | - | - | Outbound | |
Samsung Knox | - | - | Outbound | |
443 | HTTPS | Outbound | Lenovo device activation URL. | |
443 | HTTPS | Outbound | OS device enrollment. |
Google GCM/FCM IPs: Allow all IPs from Google's ASN 15169 (Google ASN IP list) due to frequent IP changes.
Push notifications: For devices without Google Play Services, ensure the required Pushy domains are whitelisted.
iOS and macOS
Follow Apple’s official firewall guidelines for Push Notifications:
Apple Push Notifications Firewall ConfigurationFollow Apple’s official guidelines for Apple Device Management
Host and Ports required for Apple Device Management
TCP and UDP ports used by Apple Software Products
Windows
URL/Domain | Port | Protocol | Direction | Description | |
|---|---|---|---|---|---|
| 443 | HTTPS | Outbound | Windows “Access to School or Work” services | |
| 443 | HTTPS | Outbound | Windows notification services | |
| 443 | HTTPS | Outbound | Windows notification services | |
| 443 | HTTPS | Outbound | Device login services | |
| 443 | HTTPS | Outbound | Device management portal | |
| 443 | HTTPS | Outbound | Enrollment endpoints | |
| 443 | HTTPS | Outbound | IP-based device location | |
| 443 | HTTPS | Outbound | Windows Information Protection service | |
*.service.signalr.net | 443 | HTTPS | Outbound | SignalR for Windows push notifications | |
login.microsoftonline.com | 443 | HTTPS | Outbound | Microsoft login services |
Windows Update Delivery Optimization:
See Microsoft’s documentation for URLs and ports required for update optimization and delivery:Ports: 7680 (TCP), 3544 (UDP), 443 (HTTPS)
Domains:
*.prod.do.dsp.mp.microsoft.com,*.dl.delivery.mp.microsoft.com,*.windowsupdate.com, etc.
Certificate Validation Endpoints (All Regions)
Domain | Port | Protocol | Direction | Description |
|---|---|---|---|---|
| 443 | HTTPS | Outbound | Certificate revocation checks |
| 443 | HTTPS | Outbound | OCSP verification (primary) |
| 443 | HTTPS | Outbound | OCSP verification (secondary) |
Important: Blocking these may cause SSL/TLS trust errors for Scalefusion services.
Why whitelist GlobalSign URLs: These endpoints are required for certificate revocation and certificate-status verification. Blocking them may result in SSL/TLS trust errors or connection failures when clients and applications attempt to validate Scalefusion certificates.
Scalefusion Core and Service Endpoints
Common Service Endpoints (Global)
URL/Domain | Ports | Protocol | Direction | Description |
|---|---|---|---|---|
| 443 | HTTPS | Outbound | Core Scalefusion API |
| 443 | HTTPS | Outbound | Device enrollment and provisioning |
vpro.scalefusion.com | 80, 443 | HTTP/S | Outbound | VPro provisioning service |
vpro-wss.scalefusion.com | 80, 443 | HTTP/S, WSS | Outbound | VPro WebSocket service |
| 443 | HTTPS | Outbound | EVA Assistant services |
80, 443 | HTTP/S | Outbound | Scalefusion authentication | |
80, 443 | HTTP/S | Outbound | Legacy EVA assistant (MobiLock) | |
| 80,443 | HTTP/S, UDP | Outbound | Remote Cast/Control signaling |
| 443 | HTTPS | Outbound | IoT device connector |
| 8883 | MQTT/TLS | Outbound | IoT communication |
sftermui.scalefusion.com (and its regional variants | 80, 443 | HTTP/S, WSS,TCP, UDP | Outbound | Remote Terminal access |
| 443 | HTTPS | Outbound | Secure Web Gateway (Veltar/WCF) services |
Use corresponding regional prefixes for India (
*-in), MEA (*-mea), and US (endpointlockdown.com) instances.
Common Service Endpoints (Global)
URL/Domain | Ports | Protocol | Direction | Description |
|---|---|---|---|---|
| 443 | HTTPS | Outbound | Core Scalefusion API |
| 443 | HTTPS | Outbound | Android device management API |
| 443 | HTTPS | Outbound | Apple (iOS/macOS) device management API |
| 443 | HTTPS | Outbound | Windows device management API |
| 443 | HTTPS | Outbound | Linux (Nix) device management API |
| 443 | HTTPS | Outbound | File distribution API |
| 443 | HTTPS | Outbound | ProSurf browser management API |
| 443 | HTTPS | Outbound | Remote Cast/Control API |
| 443 | HTTPS | Outbound | Device enrollment and provisioning |
| 443 | HTTPS | Outbound | EVA Assistant services |
| 443 | HTTPS | Outbound | Scalefusion authentication |
| 443 | HTTPS | Outbound | Legacy EVA assistant (MobiLock) |
| 443 | HTTPS, WSS | Outbound | vPro management & WebSocket communications |
| 80, 443 | HTTP/S, UDP | Outbound | Remote Cast/Control signaling |
| 80, 443 | HTTP/S, UDP | Outbound | Legacy Remote Cast/Control signaling (MobiLock) |
| 443 | HTTPS | Outbound | IoT device connector |
| 8883 | MQTT/TLS | Outbound | IoT communication |
| 80, 443 | HTTP/S, WSS | Outbound | Remote Terminal access |
| 443 | HTTPS | Outbound | Secure Web Gateway (Veltar/WCF) services |
| 80, 443 | HTTP/S | Outbound | Main marketing website |
| 80, 443 | HTTP/S | Outbound | Legacy MobiLock domain/website |
| 80, 443 | HTTP/S | Outbound | Web dashboard for device and policy manage |
Common Service Endpoints (India)
URL/Domain | Ports | Protocol | Direction | Description |
|---|---|---|---|---|
| 443 | HTTPS | Outbound | Core Scalefusion API |
| 443 | HTTPS | Outbound | Android device management API |
| 443 | HTTPS | Outbound | Apple device management API |
| 443 | HTTPS | Outbound | Windows device management API |
| 443 | HTTPS | Outbound | Linux device management API |
| 443 | HTTPS | Outbound | File distribution API |
| 443 | HTTPS | Outbound | ProSurf browser management API |
| 443 | HTTPS | Outbound | Remote Cast/Control API |
| 443 | HTTPS | Outbound | Device enrollment and provisioning |
| 443 | HTTPS | Outbound | EVA Assistant services |
| 443 | HTTPS | Outbound | Remote Cast/Control signaling |
| 443 | HTTPS | Outbound | IoT device connector |
| 8883 | MQTT/TLS | Outbound | IoT communication |
| 80, 443 | HTTP/S, WSS |
Common Service Endpoints (MEA)
URL/Domain | Ports | Protocol | Direction | Description |
|---|---|---|---|---|
| 443 | HTTPS | Outbound | Core Scalefusion API |
| 443 | HTTPS | Outbound | Android device management API |
| 443 | HTTPS | Outbound | Apple device management API |
| 443 | HTTPS | Outbound | Windows device management API |
| 443 | HTTPS | Outbound | Linux device management API |
| 443 | HTTPS | Outbound | File distribution API |
| 443 | HTTPS | Outbound | ProSurf browser management API |
| 443 | HTTPS | Outbound | Remote Cast/Control API |
| 443 | HTTPS | Outbound | Device enrollment and provisioning |
| 443 | HTTPS | Outbound | EVA Assistant services |
| 443 | HTTPS | Outbound | Remote Cast/Control signaling |
| 443 | HTTPS | Outbound | IoT device connector |
| 8883 | MQTT/TLS | Outbound | IoT communication |
| 80, 443 | HTTP/S, WSS | Outbound | Remote Terminal access |
| 443 | HTTPS | Outbound | Secure Web Gateway (Veltar/WCF) services |
Common Service Endpoints (US)
URL/Domain | Ports | Protocol | Direction | Description |
|---|---|---|---|---|
| 80, 443 | HTTP/S | Outbound | Main domain for Endpoint Lockdown (Core API + dashboard) |
| 443 | HTTPS | Outbound | Secure Web Gateway (Veltar/WCF) services |
| 443 | HTTPS | Outbound | EVA Assistant services |
| 443 | HTTPS | Outbound | IoT device connector |
| 8883 | MQTT/TLS | Outbound | IoT communication |
| 80, 443 | HTTP/S, WSS | Outbound | Remote Terminal access |
Web & Dashboard
URL/Domain | Ports | Protocol | Direction | Description |
|---|---|---|---|---|
80, 443 | HTTP/S | Outbound | Web dashboard for device and policy management | |
80, 443 | HTTP/S | Outbound | Main marketing website | |
80, 443 | HTTP/S | Outbound | Main marketing website | |
80, 443 | HTTP/S | Outbound | Legacy MobiLock domain | |
80, 443 | HTTP/S | Outbound | Legacy MobiLock website |
Developer API
Instance | Base URL | Description |
|---|---|---|
Global | Scalefusion API - Global | |
India | Scalefusion API - India | |
US | Scalefusion API - USA | |
MEA | Scalefusion API - UAE |
OneIdP Firewall Settings
Instance | URL/Domain | Port | Protocol | Direction | Description |
|---|---|---|---|---|---|
Global |
| 443 | HTTPS | Outbound | Core authentication & SSO services |
US |
| 443 | HTTPS | Outbound | US regional OneIdP services |
India |
| 443 | HTTPS | Outbound | India regional OneIdP services |
MEA |
| 443 | HTTPS | Outbound | MEA regional OneIdP services |
Remote Cast V2 Firewall Settings (by Region)
Remote Cast V2 Network Overview
Remote Cast V2 uses WebRTC for real-time media streaming. Traffic is split across three endpoints depending on the connection type:
rc-<region>.scalefusion.com— Signaling for session setup and control.turn-<region>.scalefusion.com— TURN relay used when direct media connectivity is unavailable.rtc-<region>.scalefusion.com— Direct WebRTC media endpoint for audio/video streams.
A typical session uses the signaling and direct media endpoints. The TURN relay is used as a fallback when direct media connectivity is blocked or unavailable.
Use the region-specific hostnames listed in the table below. Do not construct the hostname by substituting the region name manually.
Instance | Destination | Protocol | Port(s) | Required | Purpose |
|---|---|---|---|---|---|
Global | TCP | 443 | Yes | Signaling (WebSocket over HTTPS) | |
UDP | 50000–60000 | Yes | WebRTC media — primary path | ||
TCP | 7881 | Yes | WebRTC media — TCP fallback when UDP is blocked | ||
UDP | 3478 | Recommended | TURN relay — standard UDP port | ||
UDP | 443 | Recommended | TURN relay — firewall-friendly UDP path | ||
TCP | 5349 | Recommended | TURN relay over TLS — for strict networks | ||
UDP | 10000–20000 | Recommended | TURN relay media — direct from media nodes | ||
Bharat (India) | TCP | 443 | Yes | Signaling (WebSocket over HTTPS) | |
UDP | 50000–60000 | Yes | WebRTC media — primary path | ||
TCP | 7881 | Yes | WebRTC media — TCP fallback when UDP is blocked | ||
UDP | 3478 | Recommended | TURN relay — standard UDP port | ||
UDP | 443 | Recommended | TURN relay — firewall-friendly UDP path | ||
TCP | 5349 | Recommended | TURN relay over TLS — for strict networks | ||
UDP | 10000–20000 | Recommended | TURN relay media — direct from media nodes | ||
US (EPL) | TCP | 443 | Yes | Signaling (WebSocket over HTTPS) | |
UDP | 50000–60000 | Yes | WebRTC media — primary path | ||
TCP | 7881 | Yes | WebRTC media — TCP fallback when UDP is blocked | ||
UDP | 3478 | Recommended | TURN relay — standard UDP port | ||
UDP | 443 | Recommended | TURN relay — firewall-friendly UDP path | ||
TCP | 5349 | Recommended | TURN relay over TLS — for strict networks | ||
UDP | 10000–20000 | Recommended | TURN relay media — direct from media nodes | ||
MiddleEast (MEA) | TCP | 443 | Yes | Signaling (WebSocket over HTTPS) | |
UDP | 50000–60000 | Yes | WebRTC media — primary path | ||
TCP | 7881 | Yes | WebRTC media — TCP fallback when UDP is blocked | ||
UDP | 3478 | Recommended | TURN relay — standard UDP port | ||
UDP | 443 | Recommended | TURN relay — firewall-friendly UDP path | ||
TCP | 5349 | Recommended | TURN relay over TLS — for strict networks | ||
UDP | 10000–20000 | Recommended | TURN relay media — direct from media nodes |
Minimum Rules for Restrictive Networks
If your firewall policy only permits TCP traffic and UDP ports cannot be opened, allow the following minimum rules:
Destination | Protocol | Port | Purpose |
|---|---|---|---|
| TCP | 443 | Signaling |
| TCP | 5349 | TURN relay over TLS |
| TCP | 7881 | WebRTC media over TCP |
Running on TCP only can degrade media quality compared to UDP. Users may experience higher latency and reduced video quality. UDP is strongly recommended wherever your network policy permits it.
In closed or restrictive network environments, UDP traffic may be blocked. In such cases, allow the required TCP ports.
Network Connectivity Decision Flow
Can the device reach
rtc-<region>.scalefusion.comover UDP 50000–60000?Yes: Use the direct media path.
No: Attempt the TURN relay.
Can the device reach
turn-<region>.scalefusion.comover UDP 3478 or UDP 443?Yes: Use the TURN relay over UDP.
No: Attempt TURN over TLS.
Can the device reach
turn-<region>.scalefusion.comover TCP 5349?Yes: Use the TURN relay over TLS.
No: Media connectivity may fail. Contact your IT administrator.
Proxy and SSL Inspection
Do not enable SSL inspection on rc-<region>.scalefusion.com if the proxy terminates and re-encrypts TLS traffic, as this can interfere with WebSocket (WSS) connectivity.
UDP media traffic cannot traverse standard HTTP/HTTPS proxies. Ensure UDP traffic to turn-<region>.scalefusion.com and rtc-<region>.scalefusion.com is allowed directly through the firewall.
If your environment uses a PAC file or explicit proxy, ensure WebRTC UDP traffic to the Remote Cast V2 endpoints is sent directly rather than through the HTTP/HTTPS proxy.
IP and Hostname Allowlisting
Remote Cast V2 endpoints may resolve to multiple IP addresses, and the underlying IP addresses may change by region.
Where supported by your firewall, use hostname/FQDN-based rules rather than hard-coded IP addresses.
Remote Cast V2 Quick Reference
For IT administrators configuring endpoint or network firewalls, allow the following outbound traffic for the applicable region:
Protocol | Port | Destination | Purpose |
|---|---|---|---|
TCP | 443 |
| Signaling |
UDP | 3478 |
| TURN relay |
UDP | 443 |
| TURN relay — firewall-friendly UDP path |
TCP | 5349 |
| TURN over TLS |
TCP | 7881 |
| WebRTC TCP fallback |
UDP | 50000–60000 |
| WebRTC media |
UDP | 10000–20000 |
| TURN relay media |
Content Delivery and CDN URLs by Region
Region | URL/Domain/FQDN (Scalefusion) | URL/Domain/FQDN (OneIdP) | Port | Protocol | Description |
|---|---|---|---|---|---|
Global (EU) | 443 | HTTPS | Content Management, App Management, Branding | ||
443 | HTTPS | CDN Edge server for APK distribution | |||
443 | HTTPS | CDN Edge server for APK distribution | |||
443 | HTTPS | CDN delivers customer uploaded assets (apps/images/doc) and Scalefusion recommended apps only | |||
US | 443 | HTTPS | Content Management, App Management, Branding | ||
443 | HTTPS | CDN Edge server for APK distribution | |||
India | 443 | HTTPS | Content Management, App Management, Branding | ||
443 | HTTPS | CDN Edge server for APK distribution | |||
MEA | https://scalefusion-mea-assets-oneidp.s3.me-central-1.amazonaws.com | 443 | HTTPS | Content Management, App Management, Branding | |
443 | HTTPS | CDN Edge server for APK distribution |
Webhook & Integration IPs (Outbound Server Connections)
Region | Instance | IP Address | Purpose |
|---|---|---|---|
Global (EU) |
|
| Outbound server connections for webhooks, ITSM/SIEM integrations, on-premises connector callbacks, and similar server-to-client integrations |
India |
|
| Outbound server connections for webhooks, ITSM/SIEM integrations, on-premises connector callbacks, and similar server-to-client integrations |
MEA |
|
| Outbound server connections for webhooks, ITSM/SIEM integrations, on-premises connector callbacks, and similar server-to-client integrations |
US |
|
| Outbound server connections for webhooks, ITSM/SIEM integrations, on-premises connector callbacks, and similar server-to-client integrations |
Note: These IPs are subject to change without prior notice. Ensure both inbound (client-to-server) and outbound (server-to-client) firewall rules include these IPs for uninterrupted service.
Regional deployments: Ensure the appropriate region-specific Scalefusion endpoints and IP addresses are allowed for deployments in India, MEA, US, and Global regions.
Additional Notes
TLS Support: Scalefusion supports TLSv1.2 and TLSv1.3 only; ensure your firewall permits traffic over these protocols.
Allow wildcard subdomains (e.g., *.mobilock.in) where applicable for smoother updates.
Regular updates to firewall rules may be necessary, especially for Microsoft IP ranges and Google ASN blocks.
Smokescreen IPs: IP addresses used for server-to-client communications may change without prior notice. Ensure firewall rules are reviewed periodically.