For the complete documentation index, see llms.txt. This page is also available as Markdown.

Egress Firewall Requirements for VergeOS

Outbound firewall allow-list for VergeOS systems — ports and destinations required to reach the Update Server and Marketplace.

If your VergeOS system operates behind a restrictive egress firewall or proxy, you must allow outbound access to the Update Server. Access to the Marketplace is optional, but required if you want to use Verge.io-provided recipes. This article describes what to allow and how to find the exact destinations for your environment.

Outbound Access

Service
Required
Protocol
Port
Source IP

Update Server

Yes

TCP

443

Management/UI IP

Marketplace

No

TCP

443

Management/UI IP

All outbound traffic originates from your system's management (UI) IP address — not from individual node IPs.

Finding the Destination FQDNs

VergeOS may serve different regions from different hostnames. Locate the exact destinations directly in your UI:

Update Server URL

  1. Navigate to System > Updates.

  2. The URL field on the dashboard shows the update server address (e.g., https://updates.vergeos.com).

Marketplace URL

  1. From the top menu, navigate to Repositories > List.

  2. Locate the Marketplace entry and note its URL (e.g., https://marketplace.vergeos.com).

Allow outbound TCP 443 from your management IP to each of these hostnames.

Additional Resources


Document Information

  • Last Updated: 2026-06-03

  • VergeOS Version: 26.1

Last updated

Was this helpful?