Firewall Settings for Scalefusion

Prev Next


Scalefusion is a cloud-hosted solution with servers across the continents. This means devices enrolled and managed by Scalefusion need to have continuous access to Scalefusion's servers so that they can be managed in real-time. The devices also need to have a connection with Google Push services, Apple Push services and Windows Push services, along with other components that are required for the management of devices. Also, to access Scalefusion's Dashboard, the PC/Laptop needs to have access to certain IPs and URLs.

However, an organization might be restricting internet access on their corporate-managed devices and/or PCs/Laptops by using a firewall or a proxy. In such cases, it becomes important to allow the URLs, IPs and ports required for Scalefusion to work smoothly in your organization.

This guide outlines the Firewall settings that need to be done for Scalefusion and OneIdP.

Scalefusion Instances

To comply with data residency regulations, Scalefusion operates multiple regional instances:

Ensure firewall rules are applied according to the instance your organization uses.

General Firewall Requirements (All Regions)

URL/Domain/FQDN

Ports

Protocol

Direction

Description

*.mobilock.in

80, 443

HTTP/S

Outbound

Main domain for API and dashboard access.

*.scalefusion.com

80, 443

HTTP/S

Outbound

Core Scalefusion services.

Google FCM/GCM

5228-5230, 443

TCP

Outbound

Google GCM/FCM push notification connectivity.

*.pushy.me

443, 8883

HTTPS/TCP

Outbound

Pushy messaging domains

*.pushy.io

443, 8883

HTTPS/TCP

Outbound

Pushy messaging domains

s1.xirsys.com, .xirsys.com .xirsys.net

80,443,3478, 5349

HTTP/S/TCP/UDP

Outbound

Used for device discovery and P2P connections for Remote Cast & Control

Pushy Service Endpoints: Pushy's firewall requirement is covered by the wildcard domains .pushy.me and .pushy.io. Individual service endpoints such as api.pushy.me and mqtt.pushy.me do not need to be added as separate firewall entries.

Pushy does not publish a complete list of FQDNs/subdomains for firewall allowlisting. Wildcard allowlisting is the supported approach.

Recommendation: Whitelist wildcard domains to simplify firewall maintenance and include all current and future subdomains.

Why do we require Port 80 for mobilock.in and scalefusion.com?

These URLs are typically used to access Dashboard/Console and when a user/Admin types in the URL without explicit https:// prefix, then the request is made on port 80. We use this call to redirect to https:// URL. However if you don’t want this routing then allowing port 80 can be avoided.

Why does the Xirsys URL require port 80?

Scalefusion uses Xirsys to support Remote Cast & Control sessions that happen over WebRTC. Xirsys services, particularly WebRTC TURN/STUN servers, require specific firewall configurations to ensure connectivity, generally relying on HTTP/HTTPS ports for signalling and specialised ports for TURN traffic.Essential settings include enabling TCP and UDP, allowing outbound traffic on ports 80, 443, 3478, and 5349, and permitting outbound UDP traffic for media transmission, with options to narrow down to specific IP addresses if necessary.

Device Platform Specific Firewall Settings

Android

URL/Domain/FQDN

Ports

Protocol

Direction

Description

Android Enterprise Docs

-

-

Outbound

Android Enterprise Firewall Exceptions

Samsung Knox

-

-

Outbound

Samsung Knox Firewall Exceptions

activation.lenovo.com

443

HTTPS

Outbound

Lenovo device activation URL.

os-base.googleapis.com

443

HTTPS

Outbound

OS device enrollment.

  • Google GCM/FCM IPs: Allow all IPs from Google's ASN 15169 (Google ASN IP list) due to frequent IP changes.

  • Push notifications: For devices without Google Play Services, ensure the required Pushy domains are whitelisted.

iOS and macOS

Windows

URL/Domain

Port

Protocol

Direction

Description

enterpriseregistration.windows.net

443

HTTPS

Outbound

Windows “Access to School or Work” services

manage.microsoft.com

443

HTTPS

Outbound

Windows notification services

wns.windows.com

443

HTTPS

Outbound

Windows notification services

device.login.microsoftonline.com

443

HTTPS

Outbound

Device login services

portal.manage.microsoft.com

443

HTTPS

Outbound

Device management portal

enrollment.manage.microsoft.com

443

HTTPS

Outbound

Enrollment endpoints

geoip.iris.microsoft.com

443

HTTPS

Outbound

IP-based device location

wip.microsoft.com

443

HTTPS

Outbound

Windows Information Protection service

*.service.signalr.net

443

HTTPS

Outbound

SignalR for Windows push notifications

login.microsoftonline.com

443

HTTPS

Outbound

Microsoft login services

  • Windows Update Delivery Optimization:
    See Microsoft’s documentation for URLs and ports required for update optimization and delivery:

    • Ports: 7680 (TCP), 3544 (UDP), 443 (HTTPS)

    • Domains: *.prod.do.dsp.mp.microsoft.com, *.dl.delivery.mp.microsoft.com, *.windowsupdate.com, etc.

Certificate Validation Endpoints (All Regions)

Domain

Port

Protocol

Direction

Description

crl.globalsign.com

443

HTTPS

Outbound

Certificate revocation checks

ocsp.globalsign.com

443

HTTPS

Outbound

OCSP verification (primary)

ocsp2.globalsign.com

443

HTTPS

Outbound

OCSP verification (secondary)


Important: Blocking these may cause SSL/TLS trust errors for Scalefusion services.

Why whitelist GlobalSign URLs: These endpoints are required for certificate revocation and certificate-status verification. Blocking them may result in SSL/TLS trust errors or connection failures when clients and applications attempt to validate Scalefusion certificates.

Scalefusion Core and Service Endpoints

Common Service Endpoints (Global)

URL/Domain

Ports

Protocol

Direction

Description

api.scalefusion.com

443

HTTPS

Outbound

Core Scalefusion API

enroll.scalefusion.com

443

HTTPS

Outbound

Device enrollment and provisioning

vpro.scalefusion.com

80, 443

HTTP/S

Outbound

VPro provisioning service

vpro-wss.scalefusion.com

80, 443

HTTP/S, WSS

Outbound

VPro WebSocket service

eva.scalefusion.com, api-eva.scalefusion.com

443

HTTPS

Outbound

EVA Assistant services

accounts.scalefusion.com

80, 443

HTTP/S

Outbound

Scalefusion authentication

eva.mobilock.in

80, 443

HTTP/S

Outbound

Legacy EVA assistant (MobiLock)

signal.scalefusion.com

80,443

HTTP/S, UDP

Outbound

Remote Cast/Control signaling

iot-connector.scalefusion.com

443

HTTPS

Outbound

IoT device connector

mqtt.scalefusion.com

8883

MQTT/TLS

Outbound

IoT communication

sftermprox.scalefusion.com, sftermws.scalefusion.com

sftermui.scalefusion.com

(and its regional variants sftermui-in, sftermui-mea, sftermui.endpointlockdown.com)

80, 443

HTTP/S, WSS,TCP, UDP

Outbound

Remote Terminal access

swg-api.scalefusion.com

443

HTTPS

Outbound

Secure Web Gateway (Veltar/WCF) services

Use corresponding regional prefixes for India (*-in), MEA (*-mea), and US (endpointlockdown.com) instances.

Common Service Endpoints (Global)

URL/Domain

Ports

Protocol

Direction

Description

api.scalefusion.com

443

HTTPS

Outbound

Core Scalefusion API

api-android.scalefusion.com

443

HTTPS

Outbound

Android device management API

api-apple.scalefusion.com

443

HTTPS

Outbound

Apple (iOS/macOS) device management API

api-windows.scalefusion.com

443

HTTPS

Outbound

Windows device management API

api-nix.scalefusion.com

443

HTTPS

Outbound

Linux (Nix) device management API

api-fd.scalefusion.com

443

HTTPS

Outbound

File distribution API

api-prosurf.scalefusion.com

443

HTTPS

Outbound

ProSurf browser management API

api-rc.scalefusion.com

443

HTTPS

Outbound

Remote Cast/Control API

enroll.scalefusion.com

443

HTTPS

Outbound

Device enrollment and provisioning

eva.scalefusion.com, api-eva.scalefusion.com

443

HTTPS

Outbound

EVA Assistant services

accounts.scalefusion.com

443

HTTPS

Outbound

Scalefusion authentication

eva.mobilock.in

443

HTTPS

Outbound

Legacy EVA assistant (MobiLock)

vpro.scalefusion.com, vpro-wss.scalefusion.com

443

HTTPS, WSS

Outbound

vPro management & WebSocket communications

signal.scalefusion.com

80, 443

HTTP/S, UDP

Outbound

Remote Cast/Control signaling

signal.mobilock.in

80, 443

HTTP/S, UDP

Outbound

Legacy Remote Cast/Control signaling (MobiLock)

iot-connector.scalefusion.com

443

HTTPS

Outbound

IoT device connector

mqtt.scalefusion.com

8883

MQTT/TLS

Outbound

IoT communication

sftermprox.scalefusion.com, sftermui.scalefusion.com, sftermws.scalefusion.com

80, 443

HTTP/S, WSS

Outbound

Remote Terminal access

swg-api.scalefusion.com

443

HTTPS

Outbound

Secure Web Gateway (Veltar/WCF) services

scalefusion.com, www.scalefusion.com

80, 443

HTTP/S

Outbound

Main marketing website

mobilock.in, www.mobilock.in

80, 443

HTTP/S

Outbound

Legacy MobiLock domain/website

app.scalefusion.com

80, 443

HTTP/S

Outbound

Web dashboard for device and policy manage

Common Service Endpoints (India)

URL/Domain

Ports

Protocol

Direction

Description

api-in.scalefusion.com

443

HTTPS

Outbound

Core Scalefusion API

api-android-in.scalefusion.com

443

HTTPS

Outbound

Android device management API

api-apple-in.scalefusion.com

443

HTTPS

Outbound

Apple device management API

api-windows-in.scalefusion.com

443

HTTPS

Outbound

Windows device management API

api-nix-in.scalefusion.com

443

HTTPS

Outbound

Linux device management API

api-fd-in.scalefusion.com

443

HTTPS

Outbound

File distribution API

api-prosurf-in.scalefusion.com

443

HTTPS

Outbound

ProSurf browser management API

api-rc-in.scalefusion.com

443

HTTPS

Outbound

Remote Cast/Control API

enroll-in.scalefusion.com

443

HTTPS

Outbound

Device enrollment and provisioning

eva-in.scalefusion.com, api-eva-in.scalefusion.com

443

HTTPS

Outbound

EVA Assistant services

rc-in.scalefusion.com

443

HTTPS

Outbound

Remote Cast/Control signaling

iot-connector-in.scalefusion.com

443

HTTPS

Outbound

IoT device connector

mqtt-in.scalefusion.com

8883

MQTT/TLS

Outbound

IoT communication

sftermprox-in.scalefusion.com, sftermui-in.scalefusion.com, sftermws-in.scalefusion.com

80, 443

HTTP/S, WSS

Common Service Endpoints (MEA)

URL/Domain

Ports

Protocol

Direction

Description

api-mea.scalefusion.com

443

HTTPS

Outbound

Core Scalefusion API

api-android-mea.scalefusion.com

443

HTTPS

Outbound

Android device management API

api-apple-mea.scalefusion.com

443

HTTPS

Outbound

Apple device management API

api-windows-mea.scalefusion.com

443

HTTPS

Outbound

Windows device management API

api-nix-mea.scalefusion.com

443

HTTPS

Outbound

Linux device management API

api-fd-mea.scalefusion.com

443

HTTPS

Outbound

File distribution API

api-prosurf-mea.scalefusion.com

443

HTTPS

Outbound

ProSurf browser management API

api-rc-mea.scalefusion.com

443

HTTPS

Outbound

Remote Cast/Control API

enroll-mea.scalefusion.com

443

HTTPS

Outbound

Device enrollment and provisioning

api-eva-mea.scalefusion.com

443

HTTPS

Outbound

EVA Assistant services

rc-mea.scalefusion.com

443

HTTPS

Outbound

Remote Cast/Control signaling

iot-connector-mea.scalefusion.com

443

HTTPS

Outbound

IoT device connector

mqtt-mea.scalefusion.com

8883

MQTT/TLS

Outbound

IoT communication

sftermprox-mea.scalefusion.com, sftermui-mea.scalefusion.com, sftermws-mea.scalefusion.com

80, 443

HTTP/S, WSS

Outbound

Remote Terminal access

swg-api-mea.scalefusion.com

443

HTTPS

Outbound

Secure Web Gateway (Veltar/WCF) services

Common Service Endpoints (US)

URL/Domain

Ports

Protocol

Direction

Description

endpointlockdown.com

80, 443

HTTP/S

Outbound

Main domain for Endpoint Lockdown (Core API + dashboard)

swg-api.endpointlockdown.com

443

HTTPS

Outbound

Secure Web Gateway (Veltar/WCF) services

eva.endpointlockdown.com

443

HTTPS

Outbound

EVA Assistant services

iot-connector.endpointlockdown.com

443

HTTPS

Outbound

IoT device connector

mqtt.endpointlockdown.com

8883

MQTT/TLS

Outbound

IoT communication

sftermprox.endpointlockdown.com, sftermui.endpointlockdown.com, sftermws.endpointlockdown.com

80, 443

HTTP/S, WSS

Outbound

Remote Terminal access

Web & Dashboard

URL/Domain

Ports

Protocol

Direction

Description

app.scalefusion.com

80, 443

HTTP/S

Outbound

Web dashboard for device and policy management

scalefusion.com

80, 443

HTTP/S

Outbound

Main marketing website

www.scalefusion.com

80, 443

HTTP/S

Outbound

Main marketing website

mobilock.in

80, 443

HTTP/S

Outbound

Legacy MobiLock domain

www.mobilock.in

80, 443

HTTP/S

Outbound

Legacy MobiLock website

Developer API

Instance

Base URL

Description

Global

https://api.scalefusion.com/

Scalefusion API - Global

India

https://api-in.scalefusion.com/

Scalefusion API - India

US

https://endpointlockdown.com/

Scalefusion API - USA

MEA

https://api-mea.scalefusion.com/

Scalefusion API - UAE

OneIdP Firewall Settings

Instance

URL/Domain

Port

Protocol

Direction

Description

Global

app.oneidp.com, accounts.oneidp.com, launchlocal.oneidp.com

443

HTTPS

Outbound

Core authentication & SSO services

US

us.oneidp.com, us-accounts.oneidp.com, us-launchlocal.oneidp.com

443

HTTPS

Outbound

US regional OneIdP services

India

in.oneidp.com, in-accounts.oneidp.com, in-launchlocal.oneidp.com

443

HTTPS

Outbound

India regional OneIdP services

MEA

mea.oneidp.com, mea-accounts.oneidp.com, mea-launchlocal.oneidp.com

443

HTTPS

Outbound

MEA regional OneIdP services

Remote Cast V2 Firewall Settings (by Region)

Remote Cast V2 Network Overview

Remote Cast V2 uses WebRTC for real-time media streaming. Traffic is split across three endpoints depending on the connection type:

  • rc-<region>.scalefusion.com — Signaling for session setup and control.

  • turn-<region>.scalefusion.com — TURN relay used when direct media connectivity is unavailable.

  • rtc-<region>.scalefusion.com — Direct WebRTC media endpoint for audio/video streams.

A typical session uses the signaling and direct media endpoints. The TURN relay is used as a fallback when direct media connectivity is blocked or unavailable.

Use the region-specific hostnames listed in the table below. Do not construct the hostname by substituting the region name manually.

Instance

Destination

Protocol

Port(s)

Required

Purpose

Global

rc.scalefusion.com

TCP

443

Yes

Signaling (WebSocket over HTTPS)

rtc.scalefusion.com

UDP

50000–60000

Yes

WebRTC media — primary path

rtc.scalefusion.com

TCP

7881

Yes

WebRTC media — TCP fallback when UDP is blocked

turn.scalefusion.com

UDP

3478

Recommended

TURN relay — standard UDP port

turn.scalefusion.com

UDP

443

Recommended

TURN relay — firewall-friendly UDP path

turn.scalefusion.com

TCP

5349

Recommended

TURN relay over TLS — for strict networks

rtc.scalefusion.com

UDP

10000–20000

Recommended

TURN relay media — direct from media nodes

Bharat (India)

rc-in.scalefusion.com

TCP

443

Yes

Signaling (WebSocket over HTTPS)

rtc-in.scalefusion.com

UDP

50000–60000

Yes

WebRTC media — primary path

rtc-in.scalefusion.com

TCP

7881

Yes

WebRTC media — TCP fallback when UDP is blocked

turn-in.scalefusion.com

UDP

3478

Recommended

TURN relay — standard UDP port

turn-in.scalefusion.com

UDP

443

Recommended

TURN relay — firewall-friendly UDP path

turn-in.scalefusion.com

TCP

5349

Recommended

TURN relay over TLS — for strict networks

rtc-in.scalefusion.com

UDP

10000–20000

Recommended

TURN relay media — direct from media nodes

US (EPL)

rc-epl.scalefusion.com

TCP

443

Yes

Signaling (WebSocket over HTTPS)

rtc-epl.scalefusion.com

UDP

50000–60000

Yes

WebRTC media — primary path

rtc-epl.scalefusion.com

TCP

7881

Yes

WebRTC media — TCP fallback when UDP is blocked

turn-epl.scalefusion.com

UDP

3478

Recommended

TURN relay — standard UDP port

turn-epl.scalefusion.com

UDP

443

Recommended

TURN relay — firewall-friendly UDP path

turn-epl.scalefusion.com

TCP

5349

Recommended

TURN relay over TLS — for strict networks

rtc-epl.scalefusion.com

UDP

10000–20000

Recommended

TURN relay media — direct from media nodes

MiddleEast (MEA)

rc-mea.scalefusion.com

TCP

443

Yes

Signaling (WebSocket over HTTPS)

rtc-mea.scalefusion.com

UDP

50000–60000

Yes

WebRTC media — primary path

rtc-mea.scalefusion.com

TCP

7881

Yes

WebRTC media — TCP fallback when UDP is blocked

turn-mea.scalefusion.com

UDP

3478

Recommended

TURN relay — standard UDP port

turn-mea.scalefusion.com

UDP

443

Recommended

TURN relay — firewall-friendly UDP path

turn-mea.scalefusion.com

TCP

5349

Recommended

TURN relay over TLS — for strict networks

rtc-mea.scalefusion.com

UDP

10000–20000

Recommended

TURN relay media — direct from media nodes

Minimum Rules for Restrictive Networks

If your firewall policy only permits TCP traffic and UDP ports cannot be opened, allow the following minimum rules:

Destination

Protocol

Port

Purpose

rc-<region>.scalefusion.com

TCP

443

Signaling

turn-<region>.scalefusion.com

TCP

5349

TURN relay over TLS

rtc-<region>.scalefusion.com

TCP

7881

WebRTC media over TCP

Running on TCP only can degrade media quality compared to UDP. Users may experience higher latency and reduced video quality. UDP is strongly recommended wherever your network policy permits it.

In closed or restrictive network environments, UDP traffic may be blocked. In such cases, allow the required TCP ports.

Network Connectivity Decision Flow

  1. Can the device reach rtc-<region>.scalefusion.com over UDP 50000–60000?

    • Yes: Use the direct media path.

    • No: Attempt the TURN relay.

  2. Can the device reach turn-<region>.scalefusion.com over UDP 3478 or UDP 443?

    • Yes: Use the TURN relay over UDP.

    • No: Attempt TURN over TLS.

  3. Can the device reach turn-<region>.scalefusion.com over TCP 5349?

    • Yes: Use the TURN relay over TLS.

    • No: Media connectivity may fail. Contact your IT administrator.

Proxy and SSL Inspection

Do not enable SSL inspection on rc-<region>.scalefusion.com if the proxy terminates and re-encrypts TLS traffic, as this can interfere with WebSocket (WSS) connectivity.

UDP media traffic cannot traverse standard HTTP/HTTPS proxies. Ensure UDP traffic to turn-<region>.scalefusion.com and rtc-<region>.scalefusion.com is allowed directly through the firewall.

If your environment uses a PAC file or explicit proxy, ensure WebRTC UDP traffic to the Remote Cast V2 endpoints is sent directly rather than through the HTTP/HTTPS proxy.

IP and Hostname Allowlisting

Remote Cast V2 endpoints may resolve to multiple IP addresses, and the underlying IP addresses may change by region.

Where supported by your firewall, use hostname/FQDN-based rules rather than hard-coded IP addresses.

Remote Cast V2 Quick Reference

For IT administrators configuring endpoint or network firewalls, allow the following outbound traffic for the applicable region:

Protocol

Port

Destination

Purpose

TCP

443

rc-<region>.scalefusion.com

Signaling

UDP

3478

turn-<region>.scalefusion.com

TURN relay

UDP

443

turn-<region>.scalefusion.com

TURN relay — firewall-friendly UDP path

TCP

5349

turn-<region>.scalefusion.com

TURN over TLS

TCP

7881

rtc-<region>.scalefusion.com

WebRTC TCP fallback

UDP

50000–60000

rtc-<region>.scalefusion.com

WebRTC media

UDP

10000–20000

rtc-<region>.scalefusion.com

TURN relay media

Content Delivery and CDN URLs by Region

Region

URL/Domain/FQDN (Scalefusion)

URL/Domain/FQDN (OneIdP)

Port

Protocol

Description

Global (EU)

mobilock.s3-website-eu-west-1.amazonaws.com

https://prod-oneidp.s3.eu-central-1.amazonaws.com

443

HTTPS

Content Management, App Management, Branding

db5xszokwvv76.cloudfront.net

443

HTTPS

CDN Edge server for APK distribution

d1r3rtmcqyf4sz.cloudfront.net

443

HTTPS

CDN Edge server for APK distribution

dc2r9u5dy6q1f.cloudfront.net

443

HTTPS

CDN delivers customer uploaded assets (apps/images/doc) and Scalefusion recommended apps only

US

assets-hp-reap.s3.amazonaws.com

https://epl-prod-oneidp.s3.us-east-1.amazonaws.com

443

HTTPS

Content Management, App Management, Branding

db5xszokwvv76.cloudfront.net

443

HTTPS

CDN Edge server for APK distribution

India

assets-sf-bharat.s3.ap-south-1.amazonaws.com

https://in-prod-oneidp.s3.ap-south-1.amazonaws.com

443

HTTPS

Content Management, App Management, Branding

d2vykazg2augye.cloudfront.net

443

HTTPS

CDN Edge server for APK distribution

MEA

scalefusion-uae-assets.s3.me-central-1.amazonaws.com

https://scalefusion-mea-assets-oneidp.s3.me-central-1.amazonaws.com

443

HTTPS

Content Management, App Management, Branding

d7a4g5ksfhora.cloudfront.net

443

HTTPS

CDN Edge server for APK distribution

Webhook & Integration IPs (Outbound Server Connections)

Region

Instance

IP Address

Purpose

Global (EU)

app.scalefusion.com

165.22.203.134

Outbound server connections for webhooks, ITSM/SIEM integrations, on-premises connector callbacks, and similar server-to-client integrations

India

in.scalefusion.com

3.108.153.5

Outbound server connections for webhooks, ITSM/SIEM integrations, on-premises connector callbacks, and similar server-to-client integrations

MEA

mea.scalefusion.com

51.112.212.140

Outbound server connections for webhooks, ITSM/SIEM integrations, on-premises connector callbacks, and similar server-to-client integrations

US

endpointlockdown.com

157.230.176.102

Outbound server connections for webhooks, ITSM/SIEM integrations, on-premises connector callbacks, and similar server-to-client integrations

Note: These IPs are subject to change without prior notice. Ensure both inbound (client-to-server) and outbound (server-to-client) firewall rules include these IPs for uninterrupted service.

Regional deployments: Ensure the appropriate region-specific Scalefusion endpoints and IP addresses are allowed for deployments in India, MEA, US, and Global regions.

Additional Notes

  • TLS Support: Scalefusion supports TLSv1.2 and TLSv1.3 only; ensure your firewall permits traffic over these protocols.

  • Allow wildcard subdomains (e.g., *.mobilock.in) where applicable for smoother updates.

  • Regular updates to firewall rules may be necessary, especially for Microsoft IP ranges and Google ASN blocks.

  • Smokescreen IPs: IP addresses used for server-to-client communications may change without prior notice. Ensure firewall rules are reviewed periodically.