Getting Started

Endpoints

Patch Management

Vulnerability Management

Software Deployment & IT Assets

Automation & Remote Desktop

Real-Time Reports & Alerts

Account Access & Management

SSO Authentication

Security Concerns

Integrations

Need Help?

Action1 5 Documentation 5 Region: UK

Region: UK

Managed endpoints connections

Resource

Action1 servers (server.eu.action1.com):
  • 18.159.245.29
  • 18.195.232.183
  • 3.69.247.61
  • 52.29.164.59
Managed endpoints
(Windows endpoints, LAN only)

Type

Outbound
Inbound

Port & Protocol

443 or 22543,
TLS 1.2 or TLS 1.3 over TCP
22551 TCP/UDP,
6771 UDP

Required for

Connection to Action1 Cloud
P2P file sharing

Components

Action1 agents
Action1 agents

Details

Make sure the outbound traffic is excluded from TLS/SSL inspection. Otherwise, the connection through some firewalls and proxy appliances (e.g., Zscaler or Cisco Umbrella) may fail. See TLS Inspection for details.
- The port should be open locally on managed endpoints to allow connections between agents in the local network.
- Make sure the Windows Firewall Policy: Prohibit unicast response to multicast or broadcast requests is set to Not Configured (default setting) or No.

NOTE: The Action1 agents now communicate with Action1 servers primarily over port 443, which is open by default in most enterprise environments. The agent first attempts to connect via port 443, and if that connection fails, it automatically falls back to port 22543.

NOTE: If the inbound communication between agents on the local network is not allowed, the agents will not be exchanging downloaded app pieces locally and will always download in full from the cloud.

Connection to Action1 Remote Desktop facilities

Resource

Action1 Remote Desktop relay servers in the UK:
  • 13.134.53.159
  • 18.169.9.122
  • 13.135.104.156
  • 18.170.156.138
Action1 Remote Desktop Console for Europe:
  • remote.uk.action1.com

Type

Outbound
Outbound

Port & Protocol

22543 TCP,
TLS 1.2 over TCP
443 HTTPS

Required for

UK only: Connection to Action1 Remote Desktop relay servers.
UK only: Connection to Action1 Remote Desktop Console.

Components

Action1 agents
Action1 Console (web browser)

Details

These servers are located in the UK to ensure a smooth Remote Desktop experience for the users located in this region.
This server is located in the UK to ensure a smooth Remote Desktop experience for the users located in this region.

NOTE: The Action1 agents communicate with Action1 Remote Desktop relay servers primarily over port 443, which is open by default in most enterprise environments. The agent first attempts to connect via port 443, and if that connection fails, it automatically falls back to port 22543.

NOTE: If you are using a proxy or security appliance that performs TLS/SSL inspection, exclude the outbound traffic from the Action1 agent to the Action1 Desktop Relay server from TLS/SSL inspection. Otherwise, the connection may experience latency. See TLS Inspection for details.

For Windows Update management

Resource

*.windowsupdate.com
*.mp.microsoft.com
emdl.ws.microsoft.com
  • tsfe.trafficshaping.dsp.mp.microsoft.com
  • download.windowsupdate.com
  • dl.delivery.mp.microsoft.com
  • download.windowsupdate.com
  • windowsupdate.microsoft.com
  • *.windowsupdate.microsoft.com
  • *.update.microsoft.com
  • update.microsoft.com
  • download.microsoft.com
  • ntservicepack.microsoft.com
  • login.live.com

Type

Outbound
Outbound
Outbound
Outbound

Port & Protocol

TCP, proprietary by Microsoft
HTTPS/TLS 1.2
HTTP
HTTPS/TLS 1.2

Components

Action1 agents
Action1 agents
Action1 agents
Action1 agents

NOTE: * (asterisk sign) in DNS names means including all child subdomains, with multi-level nesting. For example,  *.example.com would include example.com, child.example.com, grand.child.example.com, and all other possible subdomains.

For Windows application deployment and 3rd party patch management

Resource

  • uk-cdn.action1.com
  • uk-cdn-action1-com.b-cdn.net
a1-backend-packages-521765618517-eu-west-2.s3.amazonaws.com

Type

Outbound
Outbound

Port & Protocol

443 HTTPS
443 HTTPS

Components

Action1 agents
Action1 agents

NOTE: To prevent software package downloads from failing when using a proxy appliance (such as Zscaler and Cisco Umbrella), you may need to exclude the outbound traffic from TLS/SSL inspection. See TLS Inspection for details.

Connection between Action1 Deployer (optional component) and Windows infrastructure

Resource

Action1 servers (server.eu.action1.com):
  • 13.134.53.159
  • 18.169.9.122
  • 13.135.104.156
  • 18.170.156.138
Target endpoints
Domain controllers

Type

Outbound
Outbound
Outbound

Port & Protocol

443 or 22543, TCP
135 RPC TCP
139 SMB TCP
445 SMB TCP
Dynamic port range (randomly allocated TCP ports between 49152 - 65535)
389 LDAP TCP

Components

Action1 Deployer
Action1 Deployer
Action1 Deployer

Details

Make sure the outbound traffic is excluded from TLS/SSL inspection. Otherwise, the connection through some firewalls and proxy appliances (e.g., Zscaler or Cisco Umbrella) may fail. See TLS Inspection for details.

NOTE: Action1 Deployer communicates with Action1 servers primarily over port 443, which is open by default in most enterprise environments. It first attempts to connect via port 443, and if that connection fails, it automatically falls back to port 22543.

For macOS system updates

Resource

Apple's software distribution & download servers:
  • swscan.apple.com
  • mesu.apple.com
  • swcdn.apple.com
  • gdmf.apple.com

Type

Outbound

Port & Protocol

TCP/HTTP/HTTPS

Components

Action1 agents

NOTE: Action1 agents receive macOS system updates by means of the native Software Update utility that uses the connections listed above.

For macOS applications deployment and patching

Resource

  • uk-cdn.action1.com
  • uk-cdn-action1-com.b-cdn.net
a1-backend-packages-521765618517-eu-west-2.s3.amazonaws.com

Type

Outbound
Outbound

Port & Protocol

443 HTTPS
443 HTTPS

Components

Action1 agents
Action1 agents

NOTE: To prevent software package downloads from failing when using a proxy appliance (such as Zscaler and Cisco Umbrella), you may need to exclude the outbound traffic from TLS/SSL inspection. See TLS Inspection for details.

For Linux system updates

Resource

Registered Linux repositories for the target distribution, for example: repo-oss for openSUSE, main for Ubuntu, BaseOS for RHEL, etc.

Type

Outbound

Port & Protocol

TCP/HTTP/HTTPS

Components

Action1 agents

NOTE: Linux app packages are installed from the online repository using an Action1 script that utilizes the native package manager. For details, see Deploy Software.