Security: Which ports should I open on my firewall for the Snugr box?
Network security and required ports for Snugr
The Snugr solution is designed following a security by design approach.
It does not require any inbound connection from the Internet to your network.
The Snugr gateway communicates exclusively through outbound connections, which are typically allowed by default on most corporate firewalls.
Ports and protocols used (outbound only)
To ensure proper operation of the Snugr gateway, the following ports must be allowed outbound:
-
HTTP / HTTPS / secure FTP
-
TCP 80, 443, 21, 22
-
Used for secure communication with Snugr servers, software updates, and data synchronization.
-
-
NTP – Time synchronization
-
UDP 123
-
Ensures accurate timestamping of events and data.
-
-
ICMP (outbound ping)
-
Allows network diagnostics and connectivity monitoring.
-
No inbound ports need to be opened, significantly reducing the attack surface and simplifying integration into secure environments.
Network segmentation (VLAN)
For enhanced security, Snugr gateways can be deployed in a dedicated VLAN.
This setup allows you to:
-
fully isolate Snugr devices from the internal IT network,
-
prevent any unwanted communication with other systems,
-
while maintaining optimal operation of the solution.