AvailableSystem Requirements
Network Requirements
Local and outbound connectivity needed by Edge, Agent, portal, and identity services.
- Applies to
- Current OZVO services
- Product area
- System Requirements
- Audience
- Owners and Administrators
- Last reviewed
- September 17, 2026
- Status
- Available
Guidance
- Local dashboard uses HTTPS/TCP 443 to the commissioned Edge hostname.
- Remote relay uses outbound WSS/TCP 443 to access.ozvosecurity.com.
- No inbound Internet port-forward is required.
Required connectivity
| Use | Direction | Protocol / port | Destination |
|---|---|---|---|
| Local dashboard | Client to OZVO Edge on the local network | HTTPS / TCP 443 | Commissioned local hostname |
| Remote portal | Browser outbound | HTTPS / TCP 443 | portal.ozvosecurity.com |
| Remote relay | OZVO Edge outbound | WSS over TLS / TCP 443 | access.ozvosecurity.com |
| Windows Agent | Windows endpoint outbound | HTTPS / TCP 443 | Commissioned, pinned OZVO enrollment and Agent hostnames |
| Identity provider | Browser outbound | HTTPS / TCP 443 | Your configured organization identity-provider domains |
Firewall principle
Remote access uses outbound TCP/443. No inbound Internet port forwarding is required. OZVO does not expose SSH to the Internet and the remote service is not an arbitrary TCP tunnel.
DNS and TLS
- Allow normal DNS resolution for the commissioned local hostname and approved public OZVO hostnames.
- Preserve TLS inspection behavior only when it is compatible with the commissioned trust and pinning design.
- Do not replace DNS names with IP addresses or bypass certificate warnings.
- If an allowlist is required, use the exact destinations provided for your commissioned site.
Still need help?Contact Support with the site, device, time, and exact error—never credentials or recovery secrets.Contact Support →
