Overview
This article describes the network ports, protocols, and destinations required for Softdrive components to operate correctly when using the Relay network model.
The required network access applies to both endpoints:
- The local computer running the Softstream client
- The remote Softdrive desktop
Firewall and network security rules must allow the required outbound communication on both machines.
These requirements apply specifically to environments using the Softdrive Relay network model.
Some destinations use dynamically managed or cloud-hosted IP addresses. Where indicated below, firewall rules should use the FQDN instead of a fixed IP address.
Applies To
- Softstream Client
- Softdrive virtual desktops
- Softdrive Relay Server deployments
- Customer firewalls and network security appliances
- Outbound network and egress filtering configurations
Network Requirements
The following outbound connections must be allowed for Softdrive components to communicate with the Softdrive Signal Server, customer Relay Servers, Softnet, and required AWS services.
| Service | Direction | Protocol | Source Port | Destination | Destination Port |
|---|---|---|---|---|---|
| Signal Server | Outbound | TCP | Ephemeral (1024–65535) | 129.158.196.183 | 9500 |
| Relay – Primary (UDP) | Outbound | UDP | 9250–9254 | Customer Relay Server IP | 50000–51000 |
| Relay – Primary (TCP) | Outbound | TCP | Ephemeral (1024–65535) | Customer Relay Server IP | 50000–51000 |
| Softnet API | Outbound | TCP | Ephemeral (1024–65535) | softnet.softdrive.co | 443 |
| AWS S3 – Analytics | Outbound | TCP | Ephemeral (1024–65535) | softdrive-analytics.s3.ca-central-1.amazonaws.com | 443 |
| AWS S3 – Production | Outbound | TCP | Ephemeral (1024–65535) | softdrive-prod.s3.ca-central-1.amazonaws.com | 443 |
| AWS S3 – Crash Dump | Outbound | TCP | Ephemeral (1024–65535) | softdrive-crash-dump.s3.ca-central-1.amazonaws.com | 443 |
Signal Server
The Softstream client requires outbound TCP communication with the Softdrive Signal Server.
- Destination:
129.158.196.183 - Protocol: TCP
- Destination Port: 9500
- Source Port: Ephemeral ports 1024–65535
The Signal Server is managed by Softdrive.
Relay Server
Softstream communicates with one or more Relay Servers deployed within the customer environment.
The public Relay Server IP address is provided by Softdrive after deployment.
UDP Communication
- Protocol: UDP
- Source Ports: 9250–9254
- Destination: Customer Relay Server IP
- Destination Ports: 50000–51000
TCP Communication
- Protocol: TCP
- Source Ports: Ephemeral ports 1024–65535
- Destination: Customer Relay Server IP
- Destination Ports: 50000–51000
A customer environment may contain more than one Relay Server. Network rules must allow communication with all Relay Server IP addresses provided by Softdrive.
Softnet API
Softstream requires HTTPS connectivity to the Softnet API.
- Destination:
softnet.softdrive.co - Protocol: TCP
- Destination Port: 443
- Source Port: Ephemeral ports 1024–65535
The Softnet API does not use a static destination IP address. Configure firewall or egress rules using the FQDN softnet.softdrive.co or an appropriate egress proxy.
AWS S3 Services
Softstream requires outbound HTTPS connectivity to several Softdrive-managed AWS S3 services.
Analytics
- Destination:
softdrive-analytics.s3.ca-central-1.amazonaws.com - Protocol: TCP
- Destination Port: 443
Production
- Destination:
softdrive-prod.s3.ca-central-1.amazonaws.com - Protocol: TCP
- Destination Port: 443
Crash Dumps
- Destination:
softdrive-crash-dump.s3.ca-central-1.amazonaws.com - Protocol: TCP
- Destination Port: 443
AWS S3 services use AWS-managed IP addresses. Firewall rules should therefore use the listed FQDNs instead of individual destination IP addresses.
Configuration Checklist
When configuring a firewall for Softstream Relay connectivity, verify the following:
- Outbound TCP port 9500 is permitted to the Softdrive Signal Server.
- Outbound UDP traffic from ports 9250–9254 is permitted to Relay Server ports 50000–51000.
- Outbound TCP traffic is permitted to Relay Server ports 50000–51000.
- Outbound HTTPS traffic on TCP 443 is permitted to
softnet.softdrive.co. - Outbound HTTPS traffic on TCP 443 is permitted to the required Softdrive AWS S3 FQDNs.
- All required rules are configured for both the local Softstream endpoint and the remote Softdrive desktop.
- All Relay Server IP addresses provided by Softdrive are included in the firewall configuration.
Expected Result
After the required network rules are configured, the Softstream client and remote Softdrive desktop should be able to communicate with the Softdrive Signal Server, customer Relay Servers, Softnet API, and required AWS services without being blocked by the firewall or network security policy.
Troubleshooting
If users are unable to establish or maintain a Softstream connection after the firewall rules have been configured:
- Verify that the required outbound ports are permitted.
- Confirm that the rules have been applied to both the local computer and the remote Softdrive desktop.
- Verify that all Relay Server IP addresses supplied by Softdrive are included.
- Confirm that FQDN-based filtering allows access to the Softnet and AWS S3 destinations listed in this article.
- Review firewall or security appliance logs for blocked connections involving the required destinations or ports.
Contact Softdrive Support
If the required network access has been configured and Softstream connectivity issues continue, contact the Softdrive Support Team.
When opening a support request, provide any available firewall logs, affected Softdrive computer information, and details regarding the Relay Server or network path being used.