Egress Firewall Requirements for VergeOS
Outbound firewall allow-list for VergeOS systems — ports and destinations required to reach the Update Server and Marketplace.
If your VergeOS system operates behind a restrictive egress firewall or proxy, you must allow outbound access to the Update Server. Access to the Marketplace is optional, but required if you want to use Verge.io-provided recipes. This article describes what to allow and how to find the exact destinations for your environment.
Systems that cannot allow any outbound internet access require a special air-gap license. See Requesting an Air-Gap License.
Outbound Access
Update Server
Yes
TCP
443
Management/UI IP
Marketplace
No
TCP
443
Management/UI IP
All outbound traffic originates from your system's management (UI) IP address — not from individual node IPs.
Finding the Destination FQDNs
VergeOS may serve different regions from different hostnames. Locate the exact destinations directly in your UI:
Update Server URL
Navigate to System > Updates.
The URL field on the dashboard shows the update server address (e.g.,
https://updates.vergeos.com).
Marketplace URL
From the top menu, navigate to Repositories > List.
Locate the Marketplace entry and note its URL (e.g.,
https://marketplace.vergeos.com).
Allow outbound TCP 443 from your management IP to each of these hostnames.
Additional Resources
Last updated
Was this helpful?