Everything in PSS dials out. There are no inbound firewall rules, no port forwarding, no VPN, and no routable path into your network. Write rules against FQDNs, not IP addresses — and exclude these destinations from TLS/SSL inspection.
This is the page to forward to a network or firewall owner. Certificates and access control live on the Trust Center. Architecture for operations is on Why PSS.
All connections are device-initiated outbound. No inbound rules, port forwarding, NAT translation, VPN, or static public IP is required. Neither device exposes a listening service to the customer network. NinjaOne and IXON operate elastic infrastructure behind rotating addresses; Huntress state that no static IPs or fixed FQDNs exist behind their wildcards.
| Port | Protocol | Destination | Purpose |
|---|---|---|---|
| 443 | TCP | *.rmmservice.com | RMM agent, patcher, WebSocket and File Explorer rendezvous |
| 443 | TCP | *.ninjarmm.com | RMM application, API, agent tunnel, RTC |
| 443 / 7075 | TCP | *.ninjarmm.net | Remote session relay — see note below |
| 443 | TCP | ninja-attachments.s3.us-west-2.amazonaws.com | Agent payloads |
| 443 | TCP | *.huntress.io, *.huntresscdn.com | EDR registration, check-in, telemetry, content |
| 443 | TCP | huntress-*.s3.amazonaws.com, huntress*.blob.core.windows.net | EDR installers, updates, evidence upload |
| 443 | TCP | notify.bugsnag.com, sessions.bugsnag.com | EDR agent fault reporting |
| 443 | TCP | raw.githubusercontent.com/huntresslabs/* | EDR remediation tooling |
Remote session transport. NinjaOne Remote attempts 443 first and falls back to 7075, and once a client succeeds on 7075 it continues using that port. Both behaviours have been observed in our fleet on the same relay endpoints. Because the selection cannot be predicted per endpoint, both ports should be permitted. Allowing only 443 will work for some endpoints and fail intermittently for others, presenting as “remote sessions sometimes don’t connect” while the agent remains online.
| Port | Protocol | Destination | Purpose |
|---|---|---|---|
| 443 | TCP | *.ixon.net | REST API, MQTT over TLS, and VPN transport, multiplexed on 443 |
| 443 | TCP | *.ixon.cloud | Platform services and allowlist resolution |
| 443 | TCP | *.ayayot.com | Secondary service domain — omitting this allows registration but breaks telemetry and VPN |
The gateway’s VPN handshake precedes its TLS handshake, so the first packet of a session may be classified as non-SSL traffic on an SSL port. Policies that block non-SSL on 443 require an exception. For IP-based firewalls, IXON publish a maintained list at whitelist.ixon.cloud and allowlist.ayayot.com/ipv4.txt; re-poll monthly at minimum.
| Port | Protocol | Destination | Notes |
|---|---|---|---|
| 53 | UDP/TCP | Customer resolver | Normally satisfied internally |
| 123 | UDP | NTP source | Clock skew beyond ~5 minutes breaks TLS validation. Internal NTP preferred. |
No PSS control, telemetry, or remote-session traffic uses port 80. The Windows panel still requires outbound TCP 80 unless CRL, the trusted-root CTL, and OS patches are already handled internally. It is required for:
| Use | Destinations | If blocked |
|---|---|---|
| Certificate revocation (CRL/OCSP) | crl.microsoft.com, www.microsoft.com/pkiops/*, ocsp.digicert.com, crl3.digicert.com, crl4.digicert.com, ocsp.sectigo.com, crl.sectigo.com, *.amazontrust.com | Windows soft-fails after a timeout. Plain HTTP by RFC 5280 and RFC 6960 design. Responses are CA-signed. |
| Trusted root certificate list | ctldl.windowsupdate.com | Microsoft documents TCP 80 as a prerequisite; no HTTPS endpoint exists. Root trust stops updating. Can be redirected to an internal server by policy. |
| Operating-system patch content | *.windowsupdate.com, download.windowsupdate.com, *.delivery.mp.microsoft.com, *.update.microsoft.com, download.microsoft.com | Metadata uses 443; payload delivery uses 80 via Delivery Optimization. Update scans succeed and downloads fail. Can be delegated to customer WSUS/Intune. |
Endpoint protection signature updates continue to function with port 80 closed.
Inbound rules of any kind · VPN · static public IP · domain join · any listening service · any routed path between the machine network and corporate network · administrative credentials on customer infrastructure
Destinations are in the tables above. Certificates are on the Trust Center.
*.ninjarmm.net.ctldl.windowsupdate.com), and OS patch content, unless those are already covered by your WSUS/Intune infrastructure. Endpoint protection signature updates continue with port 80 closed.*.ixon.net, *.ixon.cloud, and *.ayayot.com. Omitting *.ayayot.com can allow registration but break telemetry and VPN. The gateway’s VPN handshake precedes TLS, so policies that block non-SSL on 443 need an exception. IP lists: whitelist.ixon.cloud and allowlist.ayayot.com/ipv4.txt.Why PSS is the operations pitch. Trust Center is certificates and access control. IT is this page — destinations and ports for the firewall team.
Need a certificate file, Statement of Applicability, or an architecture walkthrough? Contact us — we will provide it.
jamesa@truelightvision.com · 519-268-8563 · proximitysmartsupport.com
TrueLight Machine Vision Solutions Inc. · A BOS Innovations company · 2335 Discovery Dr., London, ON