🔥 Firewall Configuration Reference
Proper firewall configuration is essential for GCXONE to communicate with your devices. This reference provides the exact IPs, ports, and domains required for a secure and functional installation.
Critical Requirement
Without whitelisting the primary gateway IPs, the GCXONE platform will be unable to receive alarms or heartbeat signals from your hardware.
🌐 Mandatory IP Addresses
These addresses must be whitelisted for Outbound traffic from your device network.
Primary Gateways
| Service | IP Address | Purpose |
|---|---|---|
| GCXONE Gateway (Primary) | 18.185.17.113 | Main platform communication |
| GCXONE Gateway (Backup) | 3.124.50.242 | Failover and redundancy |
| Messaging Services | 3.127.50.212 | Secure event delivery |
Video Streaming Servers
| Service | IP Address | Usage |
|---|---|---|
| Streaming Node 1 | 3.126.237.150 | Primary WebRTC node |
| Streaming Node 2 | 3.75.73.51 | Fallback streaming |
| Streaming Node 3 | 18.156.39.63 | Regional overflow |
🔌 Required Ports & Protocols
Ensure these ports are open for the specified protocols.
| Port Range | Protocol | Service | Usage |
|---|---|---|---|
| 80 | HTTP | Web Redirects | Initial connection handshake |
| 443 | HTTPS/WSS | Core API | Secure dashboard & WebSockets |
| 554 | RTSP | Video Stream | Fallback for legacy viewers |
| 5671 / 5672 | AMQPS | Messaging | Secure event delivery (TLS) |
| 10001 - 10500 | UDP/TCP | WebRTC | Dynamic ports for video streaming |
| 123 | UDP | NTP | Time synchronization |
WebRTC Port Range: The 10001-10500 range is required for peer-to-peer video negotiation, ensuring the lowest possible latency during live monitoring.
📱 Manufacturer-Specific Receivers
If you are using these specific brands, whitelist their dedicated alarm receivers:
| Brand | IP Address | Role |
|---|---|---|
| Hikvision | 35.156.60.98 | Alarm Receiver |
| Dahua | 52.59.60.20 | Alarm Receiver |
| Hanwha | 18.184.110.24 | Alarm Receiver |
🛠️ Connectivity Diagnostics
Use these commands from a workstation on the same network as your devices to verify access:
ping 18.185.17.113
# Check API access
telnet 18.185.17.113 443
# Check streaming node
telnet 3.126.237.150 10001