Rackspace PDR NIDS networking requirements

Although there are implementation differences across platforms, the network requirements are generally consistant. Differences are indicated in italics with where and why the network access control list (ACL) might differ.

Ingress requirements to the Threat Manager™ appliances

Cloud platforms only

SourceDestinationProtocolPortDescription
Agent(s) CIDRApplianceTCP443Agent updates
Agent(s) CIDRApplianceTCP7777Agent data transport (between agent and appliance on local network)
208.71.209.32/27ApplianceTCP22Optional and temporary Required for troubleshooting during provisioning only
204.110.218.96/27ApplianceTCP22Optional and temporary Required for troubleshooting during provisioning only
204.110.219.96/27ApplianceTCP22Optional and temporary Required for troubleshooting during provisioning only
185.54.124.0/24ApplianceTCP22Optional EU Alert Logic® Datacenter as directed by your PDR team and temporary Required for troubleshooting during provisioning only

Egress requirements from the Threat Manager appliances

Standard US Alert Logic datacenter

SourceDestinationProtocolPortDescription
ApplianceAgent (CIDRs)ALLALLActive Scanning
Appliance8.8.4.4TCP/UDP53DNS
Appliance8.8.8.8TCP/UDP53DNS
Appliance0.0.0.0/0TCP80Appliance updates
Appliance204.110.218.96/27TCP443Updates
Appliance204.110.219.96/27TCP443Updates
Appliance208.71.209.32/27TCP443Updates
Appliance208.71.209.32/27TCP4138Event transport
Appliance204.110.218.96/27TCP4138Event transport
Appliance204.110.219.96/27TCP4138Event transport
Appliance204.110.219.96/27UDP123NTP, time sync
Appliance208.71.209.32/27UDP123NTP, time sync

Egress requirements from the Threat Manager appliances standard EU Alert Logic datacenter

Only implemented when instructed by your PDR team

SourceDestinationProtocolPortDescription
ApplianceAgent (CIDRs)ALLALLActive Scanning
Appliance185.54.124.0/24TCP443Updates
Appliance185.54.124.0/24TCP4138Event transport
Appliance8.8.8.8TCP/UDP53DNS
Appliance8.8.4.4TCP/UDP53DNS
Appliance0.0.0.0/0TCP80Appliance updates
Appliance185.54.124.0/24UDP123NTP, time sync