Aurora Endpoint Security network prerequisites
The Aurora Endpoint Security desktop agents communicate over secure websockets (WSS). These agents require the use of port 443 (HTTPS) and access to specific domains to communicate with the management console. The required domains change based on your region.
Amazon Web Services (AWS) hosts the management console, which does not have fixed IP addresses. You should:
- Allow HTTPS traffic to *.cylance.com.
- Allow the cylance-optics-files-use1.s3.amazonaws.com host and similar hosts for other regions.
- Not allow *.amazonaws.com because it can open your network to other hosts.
The api2.cylance.com domain is deprecated, but kept open to support older Aurora Protect Desktop agents. The legacy domain directs to the same destination as api.cylance.com for threat analysis and risk scoring.
|
Region |
Domains |
|---|---|
|
North America |
Required for signing in to the Endpoint Defense console:
|
|
Required for Aurora Protect Desktop:
|
|
|
Required for Aurora Focus:
|
|
|
Asia-Pacific Northeast |
Required for signing in to the Endpoint Defense console:
|
|
Required for Aurora Protect Desktop:
|
|
|
Required for Aurora Focus:
|
|
|
Asia-Pacific Southeast |
Required for signing in to the Endpoint Defense console:
|
|
Required for Aurora Protect Desktop:
|
|
|
Required for Aurora Focus:
|
|
|
Europe Central |
Required for signing in to the Endpoint Defense console:
|
|
Required for Aurora Protect Desktop:
|
|
|
Required for Aurora Focus:
|
|
|
South America |
Required for signing in to the Endpoint Defense console:
|
|
Required for Aurora Protect Desktop:
|
|
|
Required for Aurora Focus:
|
|
|
GovCloud |
Required for signing in to the Endpoint Defense console:
|
|
Required for Aurora Protect Desktop:
|
|
|
Required for Aurora Focus:
|