WebContent

Softstream Client and Relay Server Network Port Requirements

Overview

This article describes the network ports, protocols, and destinations required for Softdrive components to operate correctly when using the Relay network model.

The required network access applies to both endpoints:

  • The local computer running the Softstream client
  • The remote Softdrive desktop

Firewall and network security rules must allow the required outbound communication on both machines.

Important

These requirements apply specifically to environments using the Softdrive Relay network model.

Some destinations use dynamically managed or cloud-hosted IP addresses. Where indicated below, firewall rules should use the FQDN instead of a fixed IP address.

Applies To

  • Softstream Client
  • Softdrive virtual desktops
  • Softdrive Relay Server deployments
  • Customer firewalls and network security appliances
  • Outbound network and egress filtering configurations

Network Requirements

The following outbound connections must be allowed for Softdrive components to communicate with the Softdrive Signal Server, customer Relay Servers, Softnet, and required AWS services.

ServiceDirectionProtocolSource PortDestinationDestination Port
Signal ServerOutboundTCPEphemeral
(1024–65535)
129.158.196.1839500
Relay – Primary (UDP)OutboundUDP9250–9254Customer Relay Server IP50000–51000
Relay – Primary (TCP)OutboundTCPEphemeral
(1024–65535)
Customer Relay Server IP50000–51000
Softnet APIOutboundTCPEphemeral
(1024–65535)
softnet.softdrive.co443
AWS S3 – AnalyticsOutboundTCPEphemeral
(1024–65535)
softdrive-analytics.s3.ca-central-1.amazonaws.com443
AWS S3 – ProductionOutboundTCPEphemeral
(1024–65535)
softdrive-prod.s3.ca-central-1.amazonaws.com443
AWS S3 – Crash DumpOutboundTCPEphemeral
(1024–65535)
softdrive-crash-dump.s3.ca-central-1.amazonaws.com443

Signal Server

The Softstream client requires outbound TCP communication with the Softdrive Signal Server.

  • Destination: 129.158.196.183
  • Protocol: TCP
  • Destination Port: 9500
  • Source Port: Ephemeral ports 1024–65535

The Signal Server is managed by Softdrive.

Relay Server

Softstream communicates with one or more Relay Servers deployed within the customer environment.

The public Relay Server IP address is provided by Softdrive after deployment.

UDP Communication

  • Protocol: UDP
  • Source Ports: 9250–9254
  • Destination: Customer Relay Server IP
  • Destination Ports: 50000–51000

TCP Communication

  • Protocol: TCP
  • Source Ports: Ephemeral ports 1024–65535
  • Destination: Customer Relay Server IP
  • Destination Ports: 50000–51000
Note

A customer environment may contain more than one Relay Server. Network rules must allow communication with all Relay Server IP addresses provided by Softdrive.

Softnet API

Softstream requires HTTPS connectivity to the Softnet API.

  • Destination: softnet.softdrive.co
  • Protocol: TCP
  • Destination Port: 443
  • Source Port: Ephemeral ports 1024–65535
Firewall Configuration

The Softnet API does not use a static destination IP address. Configure firewall or egress rules using the FQDN softnet.softdrive.co or an appropriate egress proxy.

AWS S3 Services

Softstream requires outbound HTTPS connectivity to several Softdrive-managed AWS S3 services.

Analytics

  • Destination: softdrive-analytics.s3.ca-central-1.amazonaws.com
  • Protocol: TCP
  • Destination Port: 443

Production

  • Destination: softdrive-prod.s3.ca-central-1.amazonaws.com
  • Protocol: TCP
  • Destination Port: 443

Crash Dumps

  • Destination: softdrive-crash-dump.s3.ca-central-1.amazonaws.com
  • Protocol: TCP
  • Destination Port: 443
AWS Destinations

AWS S3 services use AWS-managed IP addresses. Firewall rules should therefore use the listed FQDNs instead of individual destination IP addresses.

Configuration Checklist

When configuring a firewall for Softstream Relay connectivity, verify the following:

  • Outbound TCP port 9500 is permitted to the Softdrive Signal Server.
  • Outbound UDP traffic from ports 9250–9254 is permitted to Relay Server ports 50000–51000.
  • Outbound TCP traffic is permitted to Relay Server ports 50000–51000.
  • Outbound HTTPS traffic on TCP 443 is permitted to softnet.softdrive.co.
  • Outbound HTTPS traffic on TCP 443 is permitted to the required Softdrive AWS S3 FQDNs.
  • All required rules are configured for both the local Softstream endpoint and the remote Softdrive desktop.
  • All Relay Server IP addresses provided by Softdrive are included in the firewall configuration.

Expected Result

After the required network rules are configured, the Softstream client and remote Softdrive desktop should be able to communicate with the Softdrive Signal Server, customer Relay Servers, Softnet API, and required AWS services without being blocked by the firewall or network security policy.

Troubleshooting

If users are unable to establish or maintain a Softstream connection after the firewall rules have been configured:

  1. Verify that the required outbound ports are permitted.
  2. Confirm that the rules have been applied to both the local computer and the remote Softdrive desktop.
  3. Verify that all Relay Server IP addresses supplied by Softdrive are included.
  4. Confirm that FQDN-based filtering allows access to the Softnet and AWS S3 destinations listed in this article.
  5. Review firewall or security appliance logs for blocked connections involving the required destinations or ports.

Contact Softdrive Support

If the required network access has been configured and Softstream connectivity issues continue, contact the Softdrive Support Team.

When opening a support request, provide any available firewall logs, affected Softdrive computer information, and details regarding the Relay Server or network path being used.