PSS IT · NETWORK REQUIREMENTS

What your firewall team needs to allow.

Everything in PSS dials out. There are no inbound firewall rules, no port forwarding, no VPN, and no routable path into your network. Write rules against FQDNs, not IP addresses — and exclude these destinations from TLS/SSL inspection.

This is the page to forward to a network or firewall owner. Certificates and access control live on the Trust Center. Architecture for operations is on Why PSS.

Trust Center How it connects
Network requirements

Write firewall rules against FQDNs, not IP addresses.

All connections are device-initiated outbound. No inbound rules, port forwarding, NAT translation, VPN, or static public IP is required. Neither device exposes a listening service to the customer network. NinjaOne and IXON operate elastic infrastructure behind rotating addresses; Huntress state that no static IPs or fixed FQDNs exist behind their wildcards.

Industrial PC

PortProtocolDestinationPurpose
443TCP*.rmmservice.comRMM agent, patcher, WebSocket and File Explorer rendezvous
443TCP*.ninjarmm.comRMM application, API, agent tunnel, RTC
443 / 7075TCP*.ninjarmm.netRemote session relay — see note below
443TCPninja-attachments.s3.us-west-2.amazonaws.comAgent payloads
443TCP*.huntress.io, *.huntresscdn.comEDR registration, check-in, telemetry, content
443TCPhuntress-*.s3.amazonaws.com, huntress*.blob.core.windows.netEDR installers, updates, evidence upload
443TCPnotify.bugsnag.com, sessions.bugsnag.comEDR agent fault reporting
443TCPraw.githubusercontent.com/huntresslabs/*EDR remediation tooling

Remote session transport. NinjaOne Remote attempts 443 first and falls back to 7075, and once a client succeeds on 7075 it continues using that port. Both behaviours have been observed in our fleet on the same relay endpoints. Because the selection cannot be predicted per endpoint, both ports should be permitted. Allowing only 443 will work for some endpoints and fail intermittently for others, presenting as “remote sessions sometimes don’t connect” while the agent remains online.

Edge gateway (Performance Data Analytics deployments)

PortProtocolDestinationPurpose
443TCP*.ixon.netREST API, MQTT over TLS, and VPN transport, multiplexed on 443
443TCP*.ixon.cloudPlatform services and allowlist resolution
443TCP*.ayayot.comSecondary service domain — omitting this allows registration but breaks telemetry and VPN

The gateway’s VPN handshake precedes its TLS handshake, so the first packet of a session may be classified as non-SSL traffic on an SSL port. Policies that block non-SSL on 443 require an exception. For IP-based firewalls, IXON publish a maintained list at whitelist.ixon.cloud and allowlist.ayayot.com/ipv4.txt; re-poll monthly at minimum.

Infrastructure

PortProtocolDestinationNotes
53UDP/TCPCustomer resolverNormally satisfied internally
123UDPNTP sourceClock skew beyond ~5 minutes breaks TLS validation. Internal NTP preferred.

TLS inspection

The destinations above must be excluded from TLS/SSL inspection. The RMM and EDR agents pin their certificates; a re-signed certificate causes a hard connection failure even when the destination is permitted by policy. This presents as an agent that installs successfully and never checks in.

Port 80

No PSS control, telemetry, or remote-session traffic uses port 80. The Windows panel still requires outbound TCP 80 unless CRL, the trusted-root CTL, and OS patches are already handled internally. It is required for:

UseDestinationsIf blocked
Certificate revocation (CRL/OCSP)crl.microsoft.com, www.microsoft.com/pkiops/*, ocsp.digicert.com, crl3.digicert.com, crl4.digicert.com, ocsp.sectigo.com, crl.sectigo.com, *.amazontrust.comWindows soft-fails after a timeout. Plain HTTP by RFC 5280 and RFC 6960 design. Responses are CA-signed.
Trusted root certificate listctldl.windowsupdate.comMicrosoft documents TCP 80 as a prerequisite; no HTTPS endpoint exists. Root trust stops updating. Can be redirected to an internal server by policy.
Operating-system patch content*.windowsupdate.com, download.windowsupdate.com, *.delivery.mp.microsoft.com, *.update.microsoft.com, download.microsoft.comMetadata uses 443; payload delivery uses 80 via Delivery Optimization. Update scans succeed and downloads fail. Can be delegated to customer WSUS/Intune.

Endpoint protection signature updates continue to function with port 80 closed.

Not required

Inbound rules of any kind · VPN · static public IP · domain join · any listening service · any routed path between the machine network and corporate network · administrative credentials on customer infrastructure

Common questions

What firewall teams usually ask.

Destinations are in the tables above. Certificates are on the Trust Center.

Must we allow TLS/SSL inspection on PSS destinations?
No — those destinations must be excluded from TLS/SSL inspection. The RMM and EDR agents pin their certificates. A re-signed certificate causes a hard connection failure even when the destination is permitted. This presents as an agent that installs successfully and never checks in. It is the most common cause of a delayed install.
Why both TCP 443 and 7075 for remote sessions?
NinjaOne Remote attempts 443 first and falls back to 7075. Once a client succeeds on 7075 it continues using that port. Both behaviours have been observed in our fleet on the same relay endpoints, so selection cannot be predicted per endpoint. Allowing only 443 works for some panels and fails intermittently for others while the agent still appears online. Permit both outbound TCP 443 and 7075 to *.ninjarmm.net.
Is outbound port 80 required?
Yes — for Windows on the panel, not for PSS agents. No PSS control, telemetry, or remote-session traffic uses port 80. The industrial PC still needs outbound TCP 80 for certificate revocation, the trusted-root CTL (ctldl.windowsupdate.com), and OS patch content, unless those are already covered by your WSUS/Intune infrastructure. Endpoint protection signature updates continue with port 80 closed.
What destinations does the Performance Data Analytics gateway need?
Where Performance Data Analytics is deployed: outbound TCP 443 to *.ixon.net, *.ixon.cloud, and *.ayayot.com. Omitting *.ayayot.com can allow registration but break telemetry and VPN. The gateway’s VPN handshake precedes TLS, so policies that block non-SSL on 443 need an exception. IP lists: whitelist.ixon.cloud and allowlist.ayayot.com/ipv4.txt.
Is anything inbound required?
No. All connections are device-initiated outbound. No inbound rules, port forwarding, NAT translation, VPN, or static public IP. Neither device exposes a listening service to the customer network.
Three PSS packages

Same product. Three focused views.

Why PSS is the operations pitch. Trust Center is certificates and access control. IT is this page — destinations and ports for the firewall team.

Ready for your IT and security team.

Need a certificate file, Statement of Applicability, or an architecture walkthrough? Contact us — we will provide it.

James Aitken · Proximity Smart Support™ Product Manager

jamesa@truelightvision.com  ·  519-268-8563  ·  proximitysmartsupport.com

TrueLight Machine Vision Solutions Inc. · A BOS Innovations company · 2335 Discovery Dr., London, ON

QR code — open Why PSS on your phone Scan Why PSS