Allow Access to Mondoo Service Endpoints
Firewall allowlist entries for installation, updates, and the Mondoo API.
If your environment blocks outbound traffic by default, allow the Mondoo service endpoints below so clients can install, update, and report scan results. All Mondoo client traffic is outbound HTTPS on port 443; Mondoo never requires inbound access to your environment.
Allow by hostname (recommended)
Mondoo services run behind load balancers, so IP addresses can change over time. Where your firewall supports hostname (FQDN) rules, allow these hostnames instead of pinning IP addresses:
| Hostname | Purpose |
|---|---|
us.api.mondoo.com | Mondoo Platform API for the US region: registration, policies, scan results |
eu.api.mondoo.com | Mondoo Platform API for the EU region: registration, policies, scan results |
ingest.us.mondoo.com | Scan result uploads for the US region |
ingest.eu.mondoo.com | Scan result uploads for the EU region |
releases.mondoo.com | Mondoo client releases and updates |
install.mondoo.com | The install service; needed only during setup |
Allow both the API hostname and the ingest hostname for the region your organization runs in. cnspec uploads scan results to the ingest host, not the API host, so a firewall that allows only the API lets scans run but blocks their results from reaching Mondoo. To confirm that a client can reach both, run cnspec status: it reports whether the API and the ingest endpoint are reachable.
Allow by IP address
If your firewall supports only IP-based rules, use the addresses below. Because these addresses can change, prefer hostname rules where possible.
releases.mondoo.com (Mondoo client releases) and install.mondoo.com (the install service) both resolve to 34.110.159.213. Over IPv6, install.mondoo.com resolves to 2600:1901:0:d78e:: and releases.mondoo.com to 2600:1901:0:d78e::1:
34.110.159.213
2600:1901:0:d78e::
2600:1901:0:d78e::1For the Mondoo API and scan result uploads, use the IP address for the region your organization runs in. Today each region's ingest host resolves to the same address as its API host:
34.160.242.34 # US region (us.api.mondoo.com, ingest.us.mondoo.com)
34.102.168.217 # EU region (eu.api.mondoo.com, ingest.eu.mondoo.com)