Region: United Kingdom
Managed endpoints connections
Resource
Action1 management servers (server.uk.action1.com):
13.134.53.159
18.169.9.122
13.135.104.156
18.170.156.138
13.134.53.159
18.169.9.122
13.135.104.156
18.170.156.138
Managed endpoints
(Windows endpoints, LAN only)
(Windows endpoints, LAN only)
Type
Outbound
Inbound
Port & Protocol
443 or 22543, TLS 1.2 or TLS 1.3 over TCP
22551 TCP/UDP, 6771 UDP
Required for
Connection to Action1 Cloud
P2P file sharing
Components
Action1 agents
Action1 agents
Details
Make sure the outbound traffic is excluded from TLS/SSL inspection. Otherwise, the connection through some firewalls and proxy appliances (e.g., Zscaler or Cisco Umbrella) may fail. See TLS Inspection for details.
- The port should be open locally on managed endpoints to allow connections between agents in the local network.
- Make sure the Windows Firewall Policy: Prohibit unicast response to multicast or broadcast requests is set to Not Configured (default setting) or No.
- Make sure the Windows Firewall Policy: Prohibit unicast response to multicast or broadcast requests is set to Not Configured (default setting) or No.
NOTE: The Action1 agents now communicate with Action1 servers primarily over port 443, which is open by default in most enterprise environments. The agent first attempts to connect via port 443, and if that connection fails, it automatically falls back to port 22543.
NOTE: If the inbound communication between agents on the local network is not allowed, the agents will not be exchanging downloaded app pieces locally and will always download in full from the cloud.
Connection to Action1 Remote Desktop facilities
Resource
Action1 Remote Desktop relay servers in the UK:
3.11.185.182
18.133.145.77
13.135.127.51
18.132.80.15
18.169.251.25
3.11.185.182
18.133.145.77
13.135.127.51
18.132.80.15
18.169.251.25
Action1 Remote Desktop Console for the UK:
remote.uk.action1.com
remote.uk.action1.com
Type
Outbound
Outbound
Port & Protocol
22543 TCP, TLS 1.2 over TCP
443 HTTPS
Required for
UK only: Connection to Action1 Remote Desktop relay servers.
UK only: Connection to Action1 Remote Desktop Console.
Components
Action1 agents
Action1 Console (web browser)
Details
These servers are located in the UK to ensure a smooth Remote Desktop experience for the users located in this region.
This server is located in the UK to ensure a smooth Remote Desktop experience for the users located in this region.
NOTE: The Action1 agents communicate with Action1 Remote Desktop relay servers primarily over port 443, which is open by default in most enterprise environments. The agent first attempts to connect via port 443, and if that connection fails, it automatically falls back to port 22543.
NOTE: If you are using a proxy or security appliance that performs TLS/SSL inspection, exclude the outbound traffic from the Action1 agent to the Action1 Desktop Relay server from TLS/SSL inspection. Otherwise, the connection may experience latency. See TLS Inspection for details.
For Windows Update management
Resource
*.windowsupdate.com
*.mp.microsoft.com
emdl.ws.microsoft.com
tsfe.trafficshaping. dsp.mp.microsoft.com
download.windowsupdate.com
dl.delivery.mp.microsoft.com
download.windowsupdate.com
windowsupdate.microsoft.com
*.windowsupdate.microsoft.com
*.update.microsoft.com
update.microsoft.com
download.microsoft.com
ntservicepack.microsoft.com
login.live.com
download.windowsupdate.com
dl.delivery.mp.microsoft.com
download.windowsupdate.com
windowsupdate.microsoft.com
*.windowsupdate.microsoft.com
*.update.microsoft.com
update.microsoft.com
download.microsoft.com
ntservicepack.microsoft.com
login.live.com
Type
Outbound
Outbound
Outbound
Outbound
Port & Protocol
TCP, proprietary by Microsoft
HTTPS/TLS 1.2
HTTP
HTTPS/TLS 1.2
Components
Action1 agents
Action1 agents
Action1 agents
Action1 agents
NOTE: * (asterisk sign) in DNS names means including all child subdomains, with multi-level nesting. For example, *.example.com would include example.com, child.example.com, grand.child.example.com, and all other possible subdomains.
For Windows application deployment and 3rd party patch management
Resource
uk-cdn.action1.com
uk-cdn-action1-com.b-cdn.net
uk-cdn-action1-com.b-cdn.net
a1-backend-packages-521765618517-eu-west-2.s3.amazonaws.com
Type
Outbound
Outbound
Port & Protocol
443 HTTPS
443 HTTPS
Components
Action1 agents
Action1 agents
NOTE: To prevent software package downloads from failing when using a proxy appliance (such as Zscaler and Cisco Umbrella), you may need to exclude the outbound traffic from TLS/SSL inspection. See TLS Inspection for details.
Connection between Action1 Deployer (optional component) and Windows infrastructure
Resource
Action1 management servers (server.uk.action1.com):
13.134.53.159
18.169.9.122
13.135.104.156
18.170.156.138
13.134.53.159
18.169.9.122
13.135.104.156
18.170.156.138
Target endpoints
Domain controllers
Type
Outbound
Outbound
Outbound
Port & Protocol
443 or 22543, TCP
135 RPC TCP
139 SMB TCP
445 SMB TCP
Dynamic port range (randomly allocated TCP ports between 49152 - 65535)
139 SMB TCP
445 SMB TCP
Dynamic port range (randomly allocated TCP ports between 49152 - 65535)
389 LDAP TCP
Components
Action1 Deployer
Action1 Deployer
Action1 Deployer
Details
Make sure the outbound traffic is excluded from TLS/SSL inspection. Otherwise, the connection through some proxy appliances (e.g., Zscaler or Cisco Umbrella) may fail. See TLS Inspection for details.
NOTE: Action1 Deployer communicates with Action1 servers primarily over port 443, which is open by default in most enterprise environments. It first attempts to connect via port 443, and if that connection fails, it automatically falls back to port 22543.
For macOS system updates
Resource
Apple's software distribution & download servers:
swscan.apple.com
mesu.apple.com
swcdn.apple.com
gdmf.apple.com
swscan.apple.com
mesu.apple.com
swcdn.apple.com
gdmf.apple.com
Type
Outbound
Port & Protocol
TCP/HTTP/HTTPS
Components
Action1 agents
NOTE: Action1 agents receive macOS system updates by means of the native Software Update utility that uses the connections listed above.
For macOS applications deployment and patching
Resource
uk-cdn.action1.com
uk-cdn-action1-com.b-cdn.net
uk-cdn-action1-com.b-cdn.net
a1-backend-packages-521765618517-eu-west-2.s3.amazonaws.com
Type
Outbound
Outbound
Port & Protocol
443 HTTPS
443 HTTPS
Components
Action1 agents
Action1 agents
NOTE: To prevent software package downloads from failing when using a proxy appliance (such as Zscaler and Cisco Umbrella), you may need to exclude the outbound traffic from TLS/SSL inspection. See TLS Inspection for details.
For Linux system updates
Resource
Registered Linux repositories for the target distribution, for example: repo-oss for openSUSE, main for Ubuntu, BaseOS for RHEL, etc.
Type
Outbound
Port & Protocol
TCP/HTTP/HTTPS
Components
Action1 agents
NOTE: Linux app packages are installed from the online repository using an Action1 script that utilizes the native package manager. For details, see Deploy Software.