Network and Firewall Requirements
Last updated: August 15, 2026
NetSpeek Edge VM Network and Firewall Requirements
Internet Communication (NetSpeek Edge VM ↔ NetSpeek Cloud)
| Port | Protocol | Direction | Connectivity Provided | URLs / Endpoints | Purpose |
|---|---|---|---|---|---|
| 443 | HTTPS (TCP) | Outbound | NetSpeek Cloud API | *.netspeek.ai | Configuration, metadata sync, API requests, monitoring, cloud updates |
| 443 | WSS (TCP) | Outbound | NetSpeek Cloud API | *.netspeek.ai | Real-time action dispatch relay |
Outbound ports to NetSpeek platform must be open for *.netspeek.ai addresses – this is commonly referred to as a “wildcard” rule, meaning that any address ending in netspeek.ai is accessible.
Internet Communication (NetSpeek Edge VM ↔ Internet Services)
| Port(s) | Protocol(s) | Direction | Connectivity Provided | URLs / Endpoints | Purpose |
|---|---|---|---|---|---|
| 443 8443 | HTTPS (TCP) MQTT (TCP) | Outbound | Amazon Greengrass IOT services | *iot.us-east-2.amazonaws.com *iot.us-east-1.amazonaws.com | Orchestrating OTA updates to Edge VM functionality |
| 443 | HTTPS (TCP) | Outbound | Amazon S3 storage services | *.s3.amazonaws.com *.s3.us-east-2.amazonaws.com | File delivery / download of updates to Edge VM functionality |
Outbound ports to AWS services must be open for *. addresses as described in the table above. This is commonly referred to as a “wildcard” rule, meaning that any address in the defined Amazon Web Services namespace is accessible.
LAN / Corporate Network Communications (NetSpeek Edge VM ↔ Intranet)
| Port | Protocol | Direction (from Edge VM’s perspective) | Supported Integrations (Devices Contacted) | Purpose |
|---|---|---|---|---|
| 22 | TCP | Outbound | Biamp Tesira | Secure device control (TTP, Tesira Text Protocol, over SSH) |
| 23 | TCP | Outbound | Biamp Tesira | Device control (TTP, Tesira Test Protocol, over Telnet; less secure, consider SSH in production) |
| 45 | TCP/UDP | In/Out | Sennheiser (SCPv1) | Device management |
| 80 | HTTP (TCP) | Outbound | NEC/Sharp, Sony, Logitech CollabOS, MiddleAtlantic, Cisco RoomOS1 | Device management |
| 443 | HTTPS (TCP) | Outbound | Logitech CollabOS, Cisco RoomOS, Poly VideoOS, Crestron CresNext, NetSpeek Windows Runtime Service2 | Secure device management & command relay |
| 1515 | TCP | Outbound | Samsung | Device management |
| 4000 | HTTPS (TCP) | Outbound | Samsung | Embedded API control |
| 4003 | HTTPS (TCP) | Outbound | Barco ClickShare | Device management |
| 4006 | HTTPS (TCP) | Outbound | Shure | Device management |
| 8001 | HTTP/WS (TCP) | Outbound | Samsung | Real-time display control |
| 8080 | HTTP (TCP) | Inbound | Edge VM’s Browser Interface | Local management |
| 9761 | TCP | Outbound | LG WebOS3 | Device Management (LG RS232 ASCII Command Protocol over IP) |
| 443 8080 | HTTPS (TCP) | Outbound | Sennheiser (SCPv2)4 | Device management |
1 Cisco RoomOS devices need HTTP traffic on TCP port 80 only if tls:false is configured on the endpoints. This port can be omitted if your Cisco devices are configured for HTTPS/TLS traffic on TCP port 443.
2 The NetSpeek Windows Runtime Service will, by default during installation on a Windows OS device, configure a firewall rule (to permit inbound traffic, from the Windows OS’ perspective) to support the NWRS’ default listening port, TCP 443. This listening port, and the associated firewall rule on the Windows OS, can be configured to any arbitrary port as described in the NetSpeek Windows Runtime Service Documents.
3 LG WebOS integration used TCP ports 3000/3001 prior to NetSpeek platform version 1.9 – connectivity to these devices has been migrated to port TCP 9761 as of August 2026, which may necessitate network-side changes in environments where port-specific permissions are necessary.
4 NetSpeek is exploring consolidation of Sennheiser Sound Control Protocol version 2 traffic to a single port. At present, all devices are managed on port TCP 443 except TC Bar device types, which are managed on port TCP 8080.
NetSpeek Platform Connectivity Requirements
Administration of the NetSpeek platform requires, in addition to allowing the Edge VM the connectivity described above, allowing the personal devices of administrators to access the URLs below via web browser.
As with the Edge VM, it is often simpler to permit *.netspeek.ai generic connectivity for platform administration rather than permitting the below URLs individually/specifically.
Platform Administration – Beta Environment and Tenants: https://portal.beta.netspeek.ai/
Platform Administration – Production Environment and Tenants: https://portal.netspeek.ai/