To enable communication between the Application Server and the Priva Cloud, specific ports must be open in the firewall. In addition, communication with the Priva Cloud must be permitted, based on the FQDNs or based on the IP addresses.
Port numbers (Compass Application Server - Priva Cloud)
| Port | Details | Protocol |
| 123 | NTP | UTP |
| 443 | HTTPS | TCP |
| 5671 | AMQP | TCP |
| 5672 | AMQP | TCP |
| 8883 | MQTT | TCP |
FQDNs (Compass Application Server - Priva Cloud)
The table below shows the Fully Qualified Domain Names (FQDNs) required for communication between the Compass Application Server and the Priva Cloud. You can choose between using wildcards (addresses starting with *) or releasing the complete FQDNs. The list of complete FQDNs is, however, dynamic; FQDNs may be added or changed in the future. Using wildcards is more maintenance-friendly, because the list of wildcards will change less often than the list of complete FQDNs.
| FQDN | Service |
| *.blob.core.windows.net (HTTPS) | |
| coprdfrontend2sawe.blob.core.windows.net | Gateway services |
| edgegatewayfirmware.blob.core.windows.net | Gateway services |
| prddevicemetadatasa.blob.core.windows.net | Gateway services |
| prdfileuploadersa.blob.core.windows.net | Gateway services |
| prdhdptsgwtelemetrysa.blob.core.windows.net | Cloud History |
| prdprivaauditlogs.blob.core.windows.net | Gateway services |
| *.priva.com (HTTPS) | |
| cr.priva.com | Gateway services |
| cr-data-westeurope.priva.com | Gateway services |
| data-gateway-fileuploader.priva.com | Gateway services |
| edge-remote.priva.com | Gateway services |
| local-auth-provisioning.priva.com | Gateway services |
| *.pool.ntp.org (NTP) | |
| Country dependent, i.e.: 0.uk.pool.ntp.org | NTP server |
| *.oms.opinsights.azure.com (HTTPS) | Gateway services |
| Miscellaneous | |
| aka.ms2 (HTTPS) | Gateway services |
| global.azure-devices-provisioning.net (HTTPS) | Gateway services |
| mcr.microsoft.com (HTTPS) | Gateway services |
| prd-priva-generic-ih.azure-devices.net (HTTPS, MQTT, AMQP) | Gateway services |
| priva.azurecr.io (HTTPS) | Gateway services |
| priva.westeurope.data.azurecr.io (HTTPS) | Gateway services |
| westeurope.data.mcr.microsoft.com (HTTPS) | Gateway services |
IP addresses (gateway - Priva Cloud)
Priva uses the "EuropeWest" and "EuropeNorth" IP address ranges from Microsoft that are required for Priva Digital Services. These series are used dynamically by Microsoft and therefore can not be mentioned specifically. The series that Microsoft uses, can be found on their website: go to
https://www.microsoft.com/en-us/download/details.aspx?id=56519 and download the json file.
This file is updated weekly. New ranges added in the file will not be used in Azure for at least one week. If you are
using the IP address restriction list, download the new json file every week and perform the necessary changes at
your site to correctly identify services running in Azure.