> For the complete documentation index, see [llms.txt](https://captic-2.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://captic-2.gitbook.io/docs/your-captic-system/tier-2-firewall-rules-with-wildcards.md).

# Tier 2: Firewall rules with wildcards

Allow outbound traffic to a list of domains, with wildcards.

The device may only reach the domains below. Wildcard domains keep the list short and stable, which makes this the quickest tier to set up.

## Firewall rules

```
123 (UDP)
- ntp.ubuntu.com, or your own NTP server

53 (UDP)
- your DNS server

443 (TCP) to:
- mcr.microsoft.com
- archive.ubuntu.com
- *.data.mcr.microsoft.com
- *.cdn.azcr.io
- global.azure-devices-provisioning.net
- docker.io
- *.azurecr.io
- *.blob.core.windows.net
- *.ods.opinsights.azure.com
- *.oms.opinsights.azure.com
- *.azure-devices.net
- aka.ms
- raw.githubusercontent.com
- captic-com.teleport.sh

5671 (TCP) to:
- *.azure-devices.net

8883 (TCP) to:
- *.azure-devices.net
```

{% hint style="info" %}
**Only port 443?** We can configure the device to send all cloud traffic over port 443, so ports 5671 and 8883 aren't needed. Let us know before delivery.
{% endhint %}

`captic-com.teleport.sh` is used for remote support. See [Remote Access](/docs/overview/good-to-know/security/remote-access.md).

You can check the connection from the device itself in the Product UI under **Details > Networking**.
