Browse documentation
AvailableAdministration

Administration Network Requirements

Plan the local and public HTTPS paths administrators use.

Applies to
Current OZVO services
Product area
Administration
Audience
Owners and Administrators
Last reviewed
September 17, 2026
Status
Available

Guidance

  • Local access uses the commissioned Edge hostname over HTTPS.
  • Remote access uses portal.ozvosecurity.com and access.ozvosecurity.com on outbound TCP/443.
  • No inbound Internet port-forward is required.

Required connectivity

UseDirectionProtocol / portDestination
Local dashboardClient to OZVO Edge on the local networkHTTPS / TCP 443Commissioned local hostname
Remote portalBrowser outboundHTTPS / TCP 443portal.ozvosecurity.com
Remote relayOZVO Edge outboundWSS over TLS / TCP 443access.ozvosecurity.com
Windows AgentWindows endpoint outboundHTTPS / TCP 443Commissioned, pinned OZVO enrollment and Agent hostnames
Identity providerBrowser outboundHTTPS / TCP 443Your configured organization identity-provider domains

Firewall principle

Remote access uses outbound TCP/443. No inbound Internet port forwarding is required. OZVO does not expose SSH to the Internet and the remote service is not an arbitrary TCP tunnel.

DNS and TLS

  • Allow normal DNS resolution for the commissioned local hostname and approved public OZVO hostnames.
  • Preserve TLS inspection behavior only when it is compatible with the commissioned trust and pinning design.
  • Do not replace DNS names with IP addresses or bypass certificate warnings.
  • If an allowlist is required, use the exact destinations provided for your commissioned site.
Still need help?Contact Support with the site, device, time, and exact error—never credentials or recovery secrets.Contact Support