Configuring the firewall for Test Cloud Dedicated
For general network configuration and firewall information, refer to Configuring the firewall
Test Cloud Dedicated Portal
Allow these domains used by Test Cloud Dedicated Portal:
If you use Azure buckets, they must not be located in the tenant's region or in the failover region.
Domains
| Scenario | Domains |
|---|---|
| Sign in with basic authentication | https://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.comhttps://platform-cdn.uipath.com |
| Sign in with Azure Active Directory (Azure AD) | https://aadcdn.msftauth.nethttps://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.comhttps://login.microsoftonline.com |
| Sign in with UiPath Assistant (basic email) | *-signalr.service.signalr.net For events related to signing in with basic authentication: https://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.comhttps://platform-cdn.uipath.com |
| Sign in with UiPath Studio (basic email) | https://api.nuget.org*-signalr.service.signalr.nethttps://gallery.uipath.comhttps://pkgs.dev.azure.com For events related to signing in with basic authentication: https://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.comhttps://platform-cdn.uipath.com |
| Static assets: Fonts, Styling and CDN hosted scripts | Fonts: https://use.typekit.nethttps://fonts.gstatic.comhttps://platform-cdn.uipath.com Images: https://s.gravatar.comhttps://secure.gravatar.comhttps://*.wp.comhttps://*.googleusercontent.comhttps://i.ytimg.comhttps://platform-cdn.uipath.com CSS: https://fonts.googleapis.com/csshttps://use.typekit.nethttps://p.typekit.nethttps://platform-cdn.uipath.com Scripts: https://primer.typekit.nethttps://use.typekit.nethttps://platform-cdn.uipath.com |
Outbound Robot connections
During the workflow execution, the Robot connects to different services to download required automation packages, check licenses, verify certificates, and more.
The following table lists the outbound connections that must be allowed:
| Hostname | Purpose |
|---|---|
https://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.com | For Test Cloud Dedicated Orchestrator. |
download.uipath.com | To download Studio or Robot MSI installers during automatic updates. |
pkgs.dev.azure.comuipathpackages.myget.org | The Robot downloads the required activity packages. |
*.vo.msecnd.net | Azure CDN, used by Myget for distributing files |
activate.uipath.com | Licensing Server. If we block this service then UiPath® is not able to check the license status and verify the data in the license folder. |
jptk0*.proinity.net | The Robot validates the root certification authority of the code signing certificate. Please notice that this happens only if the root certification authority is not already in the Windows Certificate Store. |
*.nuget.org | The Robot downloads the required activity dependencies. |
a23-*-*-*.deploy.static.akamaitechnologies.com | The Robot checks whether or not the code signing certificate has been revoked. |
x1.i.lencr.org | To verify whether the Let's Encrypt certificate authority has revoked the code signing certificate. |
*.service.signalr.net | The Robot connects to Orchestrator's SignalR channels. |
*.ingest.sentry.io | The UiPath® Assistant sends the application errors to Sentry in order to track and solve the most usual problems. |
dev.azure.compkgs.dev.azure.com*.blob.core.windows.net | To enable UiPath Robots to store and retrieve data using Azure storage services. |
gallery.uipath.commarketplace.uipath.com*.pkgs.visualstudio.com Note:gallery.uipath.com/api/v2 redirects to uipath.pkgs.visualstudio.com. | These are the URLs for the Marketplace NuGet feed |
dc.applicationinsights.azure.comdc.applicationinsights.microsoft.comdc.services.visualstudio.com*.in.applicationinsights.azure.com | The Robot uses these endpoints to send telemetry data. |
asstoffalp.z6.web.core.windows.net | Used to load components for the UiPath® Assistant for Excel add-in. |
*.trafficmanager.net | Proxy service used by the Live Streaming feature to connect between the robot and browser. |
Outbound IPs for notifications
You can configure Notification service systems to use SMTP servers from your own on-premises or cloud networks. If you want to provide additional security to your Notification service system, you can protect it with a firewall, and only allow Notification Service's outbound static IP ranges through it. Reach out to the UiPath support team for the list of outbound IP ranges that you need to allow behind your firewall.
Action Center
Domains
The following table lists the domains used by Action Center that we recommend allowing, based on the functionality you plan to use:
| Scenario | Domains to Allow |
|---|---|
| Authentication | https://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.comhttps://lh3.googleusercontent.com/ |
| Navigate to Action Center page | https://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.comhttps://uipath-acc-prod.azureedge.net/https://www.youtube.com/https://platform-cdn.uipath.com/https://fonts.gstatic.com/*.googleapis.com |
| View/Assign/Un-assign/Delete an Action | https://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.comhttps://api.smartling.com/https://uipath-acc-prod.azureedge.net/*.cloudfront.nethttps://platform-cdn.uipath.com/https://fonts.gstatic.com/*.googleapis.com |
| Storage bucket (File upload/download) | *.blob.core.windows.net |
Automation Ops
Automation Ops
The following table lists the domains used by Automation Ops:
| Scenario | Domains to Allow |
|---|---|
| Navigate to the Automation Ops page | https://stdadmstgcdn.azureedge.nethttps://app.vssps.visualstudio.comhttps://stdadmstgcdn.blob.core.windows.nethttps://nexus.ensighten.comhttps://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.comhttps://platform-cdn.uipath.comhttps://use.typekit.nethttps://p.typekit.nethttps://content.usage.uipath.comhttps://dc.services.visualstudio.comhttps://data.usage.uipath.com*-signalr.service.signalr.nethttps://s.gravatar.comhttps://i2.wp.comhttps://github.comhttps://github.githubassets.comhttps://avatars.githubusercontent.comhttps://collector.github.comhttps://api.github.com |
Data Service
The following table lists the domains used by Data Service:
| Scenario | Domains to Allow |
|---|---|
| All Data Service operations |
https://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.com
|
| Fetching static frontend content |
*.cloudapp.azure.com
|
| Sending notifications to notification hub |
*.service.signalr.net
|
| Collection of telemetry |
*.visualstudio.com
|
Insights
Domains
The following table lists the domains used by Insights:
| Scenario | Domains to Allow |
|---|---|
| Navigate to the Insights page | https://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.comhttps://uipath-insights-statics.azureedge.net/ |
Outbound IP ranges
Due to a limitation on Microsoft side for Log Export, you cannot set up inbound IP restriction when your Azure blob storage account and the Insights infrastructure is under the same region in Azure. For more information on this limitation, check the Restrictions for IP network rules page from the Microsoft Azure Blob Storage documentation.
Orchestrator
Domains
Robots send traffic to these Test Cloud Dedicated Orchestrator domains. We recommend that you allow these domains to ensure proper functioning of your automations, as described in the following table:
| Module or Functionality | Domains to Allow |
|---|---|
| UiPath Orchestrator | https://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.comhttps://orch-cdn.uipath.com |
| Automation Cloud Dedicated Robots - VM | https://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.comhttps://download.uipath.com |
| Storage | *.blob.core.windows.net If using Amazon s3 buckets: *.s3.amazonaws.com |
| Package and library feeds (library, tenant processes, and others) | https://pkgs.dev.azure.com |
| Azure SignalR | *.service.signalr.net |
| Studio and Robot auto-update functionality | https://download.uipath.com |
Test Manager
Domains
The following table lists the domains used by Test Manager that we recommend allowing, based on the functionality you plan to use:
| Module or functionality | Domains to allow |
|---|---|
| UiPath Test Manager | https://<customURL>.dedicated.uipath.comhttps://sandbox.stg.dedicated.uipath.com |
| Azure SignalR | *.service.signalr.net |