Port requirements for Genetec Cloudlink appliances
To enable communication between Genetec Cloudlink appliances and Security Center SaaS, you must open specific network ports.
US datacenters
The following network ports must be open for systems hosted in US datacenters.
| Outbound port | Endpoint domain | Required by | Port usage |
|---|---|---|---|
| UDP 123 | Network Time Protocol (NTP) servers are selected from the following sources
(highest priority to lowest priority):
|
Edge OS | Connection to an NTP server. |
| ICMP ping | 8.8.8.8 | Edge OS | Diagnostics to indicate if the appliance can reach a global, public endpoint. |
| UDP 53 | DNS servers are selected from the following sources (highest to lowest
priority).
|
Edge OS | Connection to a DNS server. |
| TCP 443 | Recommended: *.genetec.cloud *.genetec.com Current service endpoints: eastus2.firmwarerepository.edge.genetec.cloud login.genetec.com Current service static IPs: 208.88.71.3 208.88.71.4 |
Edge OS | Connection between Genetec Cloudlink and Security Center SaaS. |
| TCP 443 |
|
Edge OS | Endpoints required for connecting to and managing Genetec Cloudlink appliances. |
| TCP 443 | Recommended: *.genetec.cloud Current service endpoints: eastus2.video.genetec.cloud eastus2.tds.genetec.cloud Current service static IPs: 208.88.71.3 208.88.71.4 20.157.76.128/28 |
Video | Connection for live video streaming, video recording, and video playback. |
| TCP 554 | Recommended: *.genetec.cloud Current service endpoint: rtsp.eastus2.video.genetec.cloud Current service static IPs: 20.157.76.128/28 |
Video | Connection for RTSP streaming. |
| TCP 443 |
|
Video | Endpoints for video recording and video playback that support load balancing and resiliency. |
| TCP 1935 | Recommended: *.gsc-cloud.com Current service endpoint: {GenetecReference}.gsc-cloud.com Note: You
can obtain your Genetec reference from your Genetec channel partner. The reference
format is SCC followed by 12 digits, for example:
SCC‑232136‑654353. |
Video | Interactive Connectivity Establishment (ICE) TCP in Web Real-Time Communication (WebRTC) for live streaming. |
| UDP 3478 TCP 3478 UDP 443 TCP 443 UDP 80 TCP 80 UDP 20000-60000 |
turn.video.geneteccloud.com stun.relay.metered.ca global.relay.metered.ca |
Video | Traversal Using Relays around NAT (TURN) server and Session Traversal Utilities for NAT (STUN) servers for live WebRTC video streaming. |
| TCP 2624 | Recommended: *.gsc-cloud.com Current service endpoint: {GenetecReference}.gsc-cloud.com Note: You
can obtain your Genetec reference from your Genetec channel partner. The reference
format is SCC followed by 12 digits, for example:
SCC‑232136‑654353. |
Intrusion | Connection for intrusion. |
| TCP 443 |
|
Access control | Connection between Genetec Cloudlink and Security Center SaaS. |
| TCP 443 |
|
Access control | Connection to Synergis. |
Canadian datacenters
The following network ports must be open for systems hosted in Canadian datacenters.
| Outbound port | Endpoint domain | Required by | Port usage |
|---|---|---|---|
| UDP 123 | Network Time Protocol (NTP) servers are selected from the following sources
(highest priority to lowest priority):
|
Edge OS | Connection to an NTP server. |
| ICMP ping | 8.8.8.8 | Edge OS | Diagnostics to indicate if the appliance can reach a global, public endpoint. |
| UDP 53 | DNS servers are selected from the following sources (highest to lowest
priority).
|
Edge OS | Connection to a DNS server. |
| TCP 443 | Recommended: *.genetec.cloud *.genetec.com Current service endpoints: centralca.firmwarerepository.edge.genetec.cloud login.genetec.com Current service static IPs: 208.88.71.3 208.88.71.4 |
Edge OS | Connection between Genetec Cloudlink and Security Center SaaS. |
| TCP 443 |
|
Edge OS | Endpoints required for connecting to and managing Genetec Cloudlink appliances. |
| TCP 443 | Recommended: *.genetec.cloud Current service endpoints: centralca.video.genetec.cloud cancentral.tds.genetec.cloud Current service static IPs: 208.88.71.3 208.88.71.4 20.157.121.64/28 |
Video | Connection for live video streaming, video recording, and video playback. |
| TCP 554 | Recommended: *.genetec.cloud Current service endpoint: rtsp.centralca.video.genetec.cloud Current service static IPs: 20.157.121.64/28 |
Video | Connection for RTSP streaming. |
| TCP 443 |
|
Video | Endpoints for video recording and video playback that support load balancing and resiliency. |
| TCP 1935 | Recommended: *.gsc-cloud.com Current service endpoint: {GenetecReference}.gsc-cloud.com Note: You
can obtain your Genetec reference from your Genetec channel partner. The reference
format is SCC followed by 12 digits, for example:
SCC‑232136‑654353. |
Video | Interactive Connectivity Establishment (ICE) TCP in Web Real-Time Communication (WebRTC) for live streaming. |
| UDP 3478 TCP 3478 UDP 443 TCP 443 UDP 80 TCP 80 UDP 20000-60000 |
turn.video.geneteccloud.com stun.relay.metered.ca global.relay.metered.ca |
Video | Traversal Using Relays around NAT (TURN) server and Session Traversal Utilities for NAT (STUN) servers for live WebRTC video streaming. |
| TCP 2624 | Recommended: *.gsc-cloud.com Current service endpoint: {GenetecReference}.gsc-cloud.com Note: You
can obtain your Genetec reference from your Genetec channel partner. The reference
format is SCC followed by 12 digits, for example:
SCC‑232136‑654353. |
Intrusion | Connection for intrusion. |
| TCP 443 |
|
Access control | Connection between Genetec Cloudlink and Security Center SaaS. |
| TCP 443 |
|
Access control | Connection to Synergis. |
Australian datacenters
The following network ports must be open for systems hosted in Australian datacenters.
| Outbound port | Endpoint domain | Required by | Port usage |
|---|---|---|---|
| UDP 123 | Network Time Protocol (NTP) servers are selected from the following sources
(highest priority to lowest priority):
|
Edge OS | Connection to an NTP server. |
| ICMP ping | 8.8.8.8 | Edge OS | Diagnostics to indicate if the appliance can reach a global, public endpoint. |
| UDP 53 | DNS servers are selected from the following sources (highest to lowest
priority).
|
Edge OS | Connection to a DNS server. |
| TCP 443 | Recommended: *.genetec.cloud *.genetec.com Current service endpoints: eastau.firmwarerepository.edge.genetec.cloud login.genetec.com Current service static IPs: 208.88.71.3 208.88.71.4 |
Edge OS | Connection between Genetec Cloudlink and Security Center SaaS. |
| TCP 443 |
|
Edge OS | Endpoints required for connecting to and managing Genetec Cloudlink appliances. |
| TCP 443 | Recommended: *.genetec.cloud Current service endpoints: eastau.video.genetec.cloud australiaeast.tds.genetec.cloud Current service static IPs: 208.88.71.3 208.88.71.4 20.47.123.48/28 |
Video | Connection for live video streaming, video recording, and video playback. |
| TCP 554 | Recommended: *.genetec.cloud Current service endpoint: rtsp.eastau.video.genetec.cloud Current service static IPs: 20.47.123.48/28 |
Video | Connection for RTSP streaming. |
| TCP 443 |
|
Video | Endpoints for video recording and video playback that support load balancing and resiliency. |
| TCP 1935 | Recommended: *.gsc-cloud.com Current service endpoint: {GenetecReference}.gsc-cloud.com Note: You
can obtain your Genetec reference from your Genetec channel partner. The reference
format is SCC followed by 12 digits, for example:
SCC‑232136‑654353. |
Video | Interactive Connectivity Establishment (ICE) TCP in Web Real-Time Communication (WebRTC) for live streaming. |
| UDP 3478 TCP 3478 UDP 443 TCP 443 UDP 80 TCP 80 UDP 20000-60000 |
turn.video.geneteccloud.com stun.relay.metered.ca global.relay.metered.ca |
Video | Traversal Using Relays around NAT (TURN) server and Session Traversal Utilities for NAT (STUN) servers for live WebRTC video streaming. |
| TCP 2624 | Recommended: *.gsc-cloud.com Current service endpoint: {GenetecReference}.gsc-cloud.com Note: You
can obtain your Genetec reference from your Genetec channel partner. The reference
format is SCC followed by 12 digits, for example:
SCC‑232136‑654353. |
Intrusion | Connection for intrusion. |
| TCP 443 |
|
Access control | Connection between Genetec Cloudlink and Security Center SaaS. |
| TCP 443 |
|
Access control | Connection to Synergis. |
European datacenters
The following network ports must be open for systems hosted in European datacenters.
| Outbound port | Endpoint domain | Required by | Port usage |
|---|---|---|---|
| UDP 123 | Network Time Protocol (NTP) servers are selected from the following sources
(highest priority to lowest priority):
|
Edge OS | Connection to an NTP server. |
| ICMP ping | 8.8.8.8 | Edge OS | Diagnostics to indicate if the appliance can reach a global, public endpoint. |
| UDP 53 | DNS servers are selected from the following sources (highest to lowest
priority).
|
Edge OS | Connection to a DNS server. |
| TCP 443 | Recommended: *.genetec.cloud *.genetec.com Current service endpoints: westeu.firmwarerepository.edge.genetec.cloud login.genetec.com Current service static IPs: 208.88.71.3 208.88.71.4 |
Edge OS | Connection between Genetec Cloudlink and Security Center SaaS. |
| TCP 443 |
|
Edge OS | Endpoints required for connecting to and managing Genetec Cloudlink appliances. |
| TCP 443 | Recommended: *.genetec.cloud Current service endpoints: westeu.video.genetec.cloud westeurope.tds.genetec.cloud Current service static IPs: 208.88.71.3 208.88.71.4 20.157.123.144/28 |
Video | Connection for live video streaming, video recording, and video playback. |
| TCP 554 | Recommended: *.genetec.cloud Current service endpoint: rtsp.westeu.video.genetec.cloud Current service static IPs: 20.157.123.144/28 |
Video | Connection for RTSP streaming. |
| TCP 443 |
|
Video | Endpoints for video recording and video playback that support load balancing and resiliency. |
| TCP 1935 | Recommended: *.gsc-cloud.com Current service endpoint: {GenetecReference}.gsc-cloud.com Note: You
can obtain your Genetec reference from your Genetec channel partner. The reference
format is SCC followed by 12 digits, for example:
SCC‑232136‑654353. |
Video | Interactive Connectivity Establishment (ICE) TCP in Web Real-Time Communication (WebRTC) for live streaming. |
| UDP 3478 TCP 3478 UDP 443 TCP 443 UDP 80 TCP 80 UDP 20000-60000 |
turn.video.geneteccloud.com stun.relay.metered.ca global.relay.metered.ca |
Video | Traversal Using Relays around NAT (TURN) server and Session Traversal Utilities for NAT (STUN) servers for live WebRTC video streaming. |
| TCP 2624 | Recommended: *.gsc-cloud.com Current service endpoint: {GenetecReference}.gsc-cloud.com Note: You
can obtain your Genetec reference from your Genetec channel partner. The reference
format is SCC followed by 12 digits, for example:
SCC‑232136‑654353. |
Intrusion | Connection for intrusion. |
| TCP 443 |
|
Access control | Connection between Genetec Cloudlink and Security Center SaaS. |
| TCP 443 |
|
Access control | Connection to Synergis. |
UK datacenters
The following network ports must be open for systems hosted in UK datacenters.
| Outbound port | Endpoint domain | Required by | Port usage |
|---|---|---|---|
| UDP 123 | Network Time Protocol (NTP) servers are selected from the following sources
(highest priority to lowest priority):
|
Edge OS | Connection to an NTP server. |
| ICMP ping | 8.8.8.8 | Edge OS | Diagnostics to indicate if the appliance can reach a global, public endpoint. |
| UDP 53 | DNS servers are selected from the following sources (highest to lowest
priority).
|
Edge OS | Connection to a DNS server. |
| TCP 443 | Recommended: *.genetec.cloud *.genetec.com Current service endpoints: southuk.firmwarerepository.edge.genetec.cloud login.genetec.com Current service static IPs: 208.88.71.3 208.88.71.4 |
Edge OS | Connection between Genetec Cloudlink and Security Center SaaS. |
| TCP 443 |
|
Edge OS | Endpoints required for connecting to and managing Genetec Cloudlink appliances. |
| TCP 443 | Recommended: *.genetec.cloud Current service endpoints: southuk.video.genetec.cloud southuk.tds.genetec.cloud Current service static IPs: 208.88.71.3 208.88.71.4 20.47.68.192/28 |
Video | Connection for live video streaming, video recording, and video playback. |
| TCP 554 | Recommended: *.genetec.cloud Current service endpoint: rtsp.southuk.video.genetec.cloud Current service static IPs: 20.47.68.192/28 |
Video | Connection for RTSP streaming. |
| TCP 443 |
|
Video | Endpoints for video recording and video playback that support load balancing and resiliency. |
| TCP 1935 | Recommended: *.gsc-cloud.com Current service endpoint: {GenetecReference}.gsc-cloud.com Note: You
can obtain your Genetec reference from your Genetec channel partner. The reference
format is SCC followed by 12 digits, for example:
SCC‑232136‑654353. |
Video | Interactive Connectivity Establishment (ICE) TCP in Web Real-Time Communication (WebRTC) for live streaming. |
| UDP 3478 TCP 3478 UDP 443 TCP 443 UDP 80 TCP 80 UDP 20000-60000 |
turn.video.geneteccloud.com stun.relay.metered.ca global.relay.metered.ca |
Video | Traversal Using Relays around NAT (TURN) server and Session Traversal Utilities for NAT (STUN) servers for live WebRTC video streaming. |
| TCP 2624 | Recommended: *.gsc-cloud.com Current service endpoint: {GenetecReference}.gsc-cloud.com Note: You
can obtain your Genetec reference from your Genetec channel partner. The reference
format is SCC followed by 12 digits, for example:
SCC‑232136‑654353. |
Intrusion | Connection for intrusion. |
| TCP 443 | google.com Recommended: *.geneteccloud.com |
Access control | Connection between Genetec Cloudlink and Security Center SaaS. |
| TCP 443 |
|
Access control | Connection to Synergis. |
Network communication with cameras
For video, the following ports must be open for local cameras. Opening these ports ensures that the Cloudlink appliance can connect to the cameras, manage them, and stream video.
| Inbound port | Outbound port | Port usage |
|---|---|---|
| TCP 443 TCP 80 |
Camera connections HTTPS on port 443 is preferred. Cloudlink appliances only fall back to HTTP on port 80 if secure communication isn’t available. |
|
| TCP 554 | RTSP for video requests. | |
| UDP 3702 | Camera discovery requests on 239.255.255.250 (multicast). | |
| UDP 10000 to 10599 | Real-Time Transport Protocol (RTP) and Real-time Transport Control Protocol (RTCP) communication from cameras to the Cloudlink appliance. | |
| UDP 5353 | UDP 5353 | Camera discovery. |
| UDP 20000 | Camera discovery responses. |
Communication with intrusion panels
Open the following ports on Cloudlink appliances to enable communication between intrusion panels and the Intrusion app (Genetec Intrusion Bridge). The ports let the Cloudlink to connect to panels and exchange events and commands.
| Inbound port | Outbound port | Port usage |
|---|---|---|
| TCP 2624 | Connecting the Intrusion app (Genetec™ Intrusion Bridge) on the Cloudlink appliance to the Genetec™ Intrusion Protocol extension in Security Center SaaS. | |
| TCP 7700 | Connecting to Bosch intrusion panels. | |
| TCP 10002-10005 | The default port for connecting and transmitting events between Honeywell
Galaxy panels and the Intrusion app (Genetec Intrusion Bridge) on the
Cloudlink. Note: These ports automatically open when you add
an intrusion panel to a Cloudlink appliance. |
|
| TCP 10005 | The default port for sending and receiving commands between Honeywell Galaxy
panels and the Intrusion app (Genetec Intrusion Bridge) on the Cloudlink. Note: This
port is not configurable. |