Fortanix Armor requires network connectivity to access external repositories and services and to support communication with the Kubernetes cluster during deployment. Ensure that the following network destinations are whitelisted to allow the required connections. For detailed traffic flow, refer to the Fortanix Armor Architecture Diagram (on-premises).
PROTOCOL | INBOUND / OUTBOUND | PORT NUMBER | PURPOSE |
|---|---|---|---|
TCP | Inbound | 443 | HTTPS - Used for static content |
TCP | Inbound | 443 | HTTPS - Used for Web UI and API access |
TCP | Outbound | 443 | Internet - Azure Attestation service |
TCP | Outbound | 443 | Azure’s Provisioning Certificate Caching Service (PCCS) endpoint ( |
TCP | Outbound | 443 | Fortanix PCCS endpoint ( |
TCP | Outbound | 443 | Intel Trust Authority ( |
TCP | Outbound | 443 | Fortanix OCI registry ( |
TCP | Outbound | 443 | Azure Blob Storage ( |
TCP | Outbound (Optional) | 514 | External Syslog server for audit logging, if configured |