> For the complete documentation index, see [llms.txt](https://captic-2.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://captic-2.gitbook.io/docs/your-captic-system/tier-3-firewall-rules-without-wildcards.md).

# Tier 3: Firewall rules without wildcards

Allow outbound traffic to exact hostnames only, directly or through an HTTPS proxy.

If your firewall policy doesn't allow wildcard domains, the device can work with a list of exact hostnames instead. Some of these hostnames are specific to your Captic tenant.

{% hint style="info" %}
Contact <support@captic.com> for your tenant-specific hostnames.
{% endhint %}

## Firewall rules

```
123 (UDP)
- ntp.ubuntu.com, or your own NTP server

53 (UDP)
- your DNS server

443 (TCP) to:
- mcr.microsoft.com
- archive.ubuntu.com
- crcaptic0efaa796.westeurope.data.azurecr.io
- global.azure-devices-provisioning.net
- docker.io
- crcaptic0efaa796.azurecr.io
- aka.ms
- raw.githubusercontent.com
- captic-com.teleport.sh
- auth.docker.io
- cdn.auth0.com
- login.docker.com
- hub.docker.com
- registry-1.docker.io
- production.cloudflare.docker.com
- docker-images-prod.r2.cloudflarestorage.com
- ml[tenant-specific].blob.core.windows.net
- st0efaa796[tenant-specific].blob.core.windows.net
- [tenant-specific].ods.opinsights.azure.com
- [tenant-specific].oms.opinsights.azure.com
- [tenant-specific].azure-devices.net

5671 (TCP) to:
- [tenant-specific].azure-devices.net

8883 (TCP) to:
- [tenant-specific].azure-devices.net
```

## Through an HTTPS proxy

Instead of opening the firewall, you can route the device's traffic through an HTTPS forward proxy on your network, for example Squid on a jump host.

* The device can send **all** cloud traffic over port 443, so a standard web proxy is enough. Ports 5671 and 8883 aren't needed.
* **DNS and NTP** run over UDP and can't go through an HTTPS proxy. Provide them locally on the device's network.
* Tell us the proxy address and port, and we'll configure the device for it.

`captic-com.teleport.sh` is used for remote support. If you can't allow it, see [Tier 4](/docs/your-captic-system/tier-4-without-teleport.md).
