Endpoint Summary
Prefer DNS names for outbound firewall rules when your firewall supports them. IP addresses behind service names can change as platform infrastructure evolves.
Control Plane Trusted Networks
Control plane policies define which source networks can reach management services such as WinBox, SSH, HTTP, HTTPS, Telnet, FTP, API, and API-SSL. The default control-plane policy includes:154.66.115.25510.0.0.0/8172.16.0.0/12192.168.0.0/16
Management Tunnel Addressing
The management VPN uses addresses from100.64.0.0/10. Do not reuse this range for site LANs if it would create routing ambiguity with the SDX management tunnel.
Practical Firewall Rules
At minimum, managed routers need:- Outbound TCP
8443toapi.altostrat.iofor the management VPN. - Outbound HTTPS to
v1.api.altostrat.iofor portal and integration calls to the public SDX API. - Outbound SFTP to
sftp.sdx.altostrat.iowhen configuration backups are enabled.
When You Need IP-Based Allowlists
If your environment cannot use DNS-based rules, keep IP allowlists under change control and confirm the current list with Altostrat before enforcing them. Avoid copying old regional IP lists between environments without validation.Related Pages
Management VPN
Understand how the outbound tunnel is created and recovered.
Control plane policies
Configure router management services and trusted networks.