Skip to main content

Open Only What the Proxy Needs

A proxy port open to 0.0.0.0/0 is an open relay waiting to be found. An outbound path left closed is an activation that fails at 02:00 on cutover night. Both failures come from the same gap: firewall rules agreed informally and never written down with a scope. This page is the single reference for those rules. Agree them with the network owner before installation.

Restrict the inbound listeners

Each rule has a named source scope. None should be opened to 0.0.0.0/0. The management interface is the highest-value target on the host — it changes policy for every user behind the proxy. Restrict it to administrator workstations, not to the client network.

Allow the outbound paths

Outbound DNS goes to the root servers A.ROOT-SERVERS.NET through M.ROOT-SERVERS.NET, or to the upstream resolvers your network team designates. SafeSquid cannot categorize or resolve destinations without it.

Endpoints that block activation

Activation fails without these. Confirm them before the cutover window, not during it.

Endpoints that block updates, not activation

The instance activates without these, then quietly stops receiving current data. Treat them as required for a production deployment even though activation succeeds.

Additional categorization endpoints

Missing: the sources in this repository disagree on this set — one lists encurl.itonlinesecure.in, another omits it, and neither is dated against the current build. The hosts below are the entries both sources share. Confirm the authoritative list through the approved release or support channel before allowlisting, and do not treat this table as complete. Treat this page as a deployment checklist, not a firewall exception template. Confirm current endpoint requirements through the approved release or support channel before production allowlisting.

Verify reachability before installing

Expected result: the host resolves and reaches the Self-Service Portal path needed for key and activation workflows.

Capture firewall evidence

Store these artifacts with the deployment record:
  • The firewall change record, with owner, source CIDRs, destination services, test window, and rollback.
  • Confirmation that 8443 is scoped to administrator networks only.
  • Reachability output for the activation endpoints.
  • The date of the last review of the outbound allowlist, and its owner.

Troubleshoot firewall failures

Next steps

  • Deployment Checklist - confirm the resolver, time source, and the rest of the readiness list.
  • Activate Your License - apply the key once the activation endpoints are reachable.
  • Sizing - size the node these rules will carry traffic for.