Network Whitelisting & Infrastructure
Technical requirements for configuring firewalls and understanding our cloud infrastructure.
Overview
impressBox operates on a modern, cloud-based architecture designed for security and scalability. Our player software utilizes outbound-only communication, meaning the player initiates all connections to our servers.
This design eliminates the need for IT administrators to open inbound ports on local firewalls, significantly reducing the security attack surface of your internal network. To ensure seamless operation, your network firewall must allow outbound traffic to the specific endpoints listed below.
Where impressBox Is Hosted
Cloud Infrastructure Locations
We utilize a distributed infrastructure to ensure high availability and low latency. Our primary servers are located in:
- Google Cloud Platform: Warsaw, Poland
- DigitalOcean: Frankfurt, Germany
- Delska Data Centers: Riga, Latvia & Vilnius, Lithuania
About Delska
Delska is one of Northern Europe’s most sustainable and secure data center operators. Their facilities in Riga and Vilnius are TIER III certified, ISO 27001 compliant, and run on 100% green energy, aligning with our commitment to environmental responsibility and data security.
Required Outbound Network Access
Please configure your network firewall to allow outbound TCP traffic to the following destinations.
| Host / IP Address | Port(s) | Purpose |
|---|---|---|
| 46.101.167.174 | 443, 22 | Main control server & SSH tunneling |
| 34.118.86.208 | 443 | Content delivery & API endpoints |
| 34.116.152.54 | 443 | Real-time WebSocket connections |
| 185.160.141.242 - 245 | 443 | Media storage & CDN origin |
| 159.89.214.108 | 443 | Backup API services |
Specific to BalenaOS Hardware The following endpoints are required ONLY for external hardware using BalenaOS-powered computers. | ||
| 144.126.247.118 | 443 | Balena IoT framework connectivity |
| 144.126.247.118 | 3128 | Secure tunneling for device upgrades |
| 159.89.213.64 | 22 | Secure tunneling for device upgrades |
How to Use This Information
Provide the table above to your Network Administrator or IT Security team. They should add these IP addresses to the allowlist (whitelist) of your firewall or proxy server.
Firewalls
Ensure outbound rules allow TCP connections on the specified ports to the destination IPs.
Proxies
If using a transparent or authenticated proxy, ensure these destinations are bypassed or authenticated correctly.
Important Notes
- Restricted Networks: If you are on a highly restricted guest network or corporate VLAN, devices may fail to register or download content until these rules are applied.
- Software Updates: Blocking access to these IPs may prevent player software from receiving critical security patches and feature updates.
- SSL Inspection: If your network performs SSL inspection (Man-in-the-Middle), you may need to exclude impressBox traffic or install your root CA on the player devices (if supported by the hardware platform).
Support & Contact
If you have specific compliance requirements or need assistance with network configuration, please contact our technical support team.
UAB "Dėžutė"
Code: 303477853
Vilnius, Lithuania