General Page
The guide also provides proxy configuration recommendations, firewall setup instructions for Windows and macOS, and answers common networking and connectivity questions to help ensure reliable streaming performance.
Firewall Requirements for IBM Video Streaming
To broadcast or view streams through IBM Video Streaming, make sure your firewall allows traffic on the required ports. A firewall may exist on your local computer, router, or corporate network.
Firewall Settings for Viewing Streams
To watch IBM Video Streaming content, configure the following stateful firewall rules:
- Outgoing UDP destination port 53 to your nameserver or any IP for DNS resolution.
- Outgoing TCP destination ports 80 and 443 to any IP for web access.
- Outgoing TCP destination port 1935 to any IP for RTMP streaming.
- Outgoing TCP destination ports 8001-8004 to the IP address ranges listed below for web-based chat.
Firewall Settings for Broadcasting
To broadcast through IBM Video Streaming, configure the following stateful firewall rules. If you are behind a corporate firewall, ask your IT department to configure these settings.
- Outgoing UDP destination port 53 to your nameserver or any IP for DNS resolution.
- Outgoing TCP destination ports 80 and 443 to the IP address ranges listed below for web access.
- Outgoing TCP destination port 1935 to the IP address ranges listed below for RTMP streaming.
Optional Secure Ingest Ports
If secure ingest is enabled for your account, also allow:
- Outgoing TCP destination port 4444 to the IP address ranges listed below.
- Outgoing UDP destination ports 2070-2090 to the IP address ranges listed below.
Note: For RTMPS streams, use the following URL format in your encoder:
rtmps://CID.ingest.video.ibm.com/ustreamVideo/CID
IP Address Ranges
Create firewall filters for the following IP address ranges. To help ensure a smooth streaming experience, whitelist all listed IP address ranges, regardless of which locations are closest to your streaming location.
| IP Address / Range | Location |
|---|---|
| 169.53.37.192/27 | Dallas, TX, USA, North America |
| 169.50.20.32/27 | Frankfurt, Germany, Europe |
| 158.177.22.246/32 | Frankfurt, Germany, Europe |
| 169.50.194.128/27 | London, United Kingdom, Europe |
| 169.57.165.32/27 | Sao Paulo, Brazil, South America |
| 168.1.193.160/27 | Sydney, Australia, Oceania |
| 161.202.236.96/27 | Tokyo, Japan, Asia |
| 169.47.38.32/27 | Washington, D.C., USA, North America |
| 169.63.98.153/32 | Washington, D.C., USA, North America |
| 169.63.101.66/32 | Washington, D.C., USA, North America |
| 169.63.164.185/32 | Washington, D.C., USA, North America |
| 169.63.177.88/32 | Washington, D.C., USA, North America |
| 150.239.225.76/32 | Washington, D.C., USA, North America |
| 52.116.124.41/32 | Washington, D.C., USA, North America |
| 169.63.178.76/32 | Washington, D.C., USA, North America |
| 52.117.122.135/32 | Washington, D.C., USA, North America |
| 150.239.108.159/32 | Washington, D.C., USA, North America |
| 169.59.162.41/32 | Washington, D.C., USA, North America |
| 150.239.220.16/32 | Washington, D.C., USA, North America |
| 169.38.91.128/28 | Chennai, India, Asia |
| 169.55.185.16/28 | Toronto, Canada, North America |
| 169.44.203.0/25 | San Jose, CA, USA, North America |
| 169.44.178.0/24 | San Jose, CA, USA, North America |
| 169.62.88.224/27 | San Jose, CA, USA, North America |
| 169.62.84.80/28 | San Jose, CA, USA, North America |
| 169.44.198.144 | San Jose, CA, USA, North America (Aspera Connect) |
| 169.44.198.128 | San Jose, CA, USA, North America (Aspera Connect) |
| 161.202.195.128/27 | Singapore, Singapore, Asia |
| 150.240.166.168 | Dallas, TX, USA, North America |
| 150.239.171.217 | Dallas, TX, USA, North America |
| 150.240.167.103/32 | Dallas, TX, USA, North America |
| 52.116.203.67/32 | Dallas, TX, USA, North America |
| 169.59.29.201/32 | Dallas, TX, USA, North America |
| 52.116.131.227/32 | Dallas, TX, USA, North America |
| 52.116.202.54/32 | Dallas, TX, USA, North America |
| 52.117.6.163/32 | Dallas, TX, USA, North America |
Additional Firewall Settings for ECDN Servers
ECDN servers are deployed behind customer firewalls and act as local caches for video streaming content. To pull content from IBM Video Streaming, ECDN servers require outbound internet connectivity. No inbound connectivity from the internet is required.
Clock Synchronization
Clock synchronization is required for SSL connections to work.
- Allow outgoing UDP port 123.
- Use a local NTP server, or allow access to
[0-3].ubuntu.pool.ntp.org.
OpenVPN Access for Support
Allow OpenVPN traffic over port 443 to:
terminator.deepcaching.com
This allows IBM Video ECDN operations to remotely access ECDN servers for upgrades or troubleshooting when the VPN connection is enabled in the ECDN Management Portal.
Child-Parent Proxy
Port 3128 is required only when the child-parent proxy feature is enabled.
Starting with ECDN server version 2.4.2, child ECDN servers can use parent ECDN servers as a proxy for HTTPS calls to the internet. This optional feature can be enabled by IBM upon customer request.
Domain Names
Many enterprise customers use a proxy server to manage HTTP and HTTPS traffic. To avoid routing large volumes of video traffic through a proxy, configure proxy bypass rules for the following domain names.
Control Plane Domains
Control plane traffic includes web portal access, support services, and management traffic. This traffic may flow through the proxy or bypass it.
ustream.tv.ustream.tvustreamstatic-a.akamaihd.netustvstaticcdn1-a.akamaihd.netustvstaticcdn2-a.akamaihd.net*.deepcaching.comvideo.ibm.com*.video.ibm.com*.services.video.ibm.com*.ums.services.video.ibm.com*.ums.ustream.tv*.ecdn.video.ibm.comubuntu.pool.ntp.org
Data Plane Domains
Data plane traffic includes large volumes of video data pulled by the video player. This traffic should bypass the proxy.
*.deepcaching.netvod-cdn.ustream.tvustreamssl-a.akamaihd.netuhsakamai-a.akamaihd.net*.midgress.deepcaching.net*.fme.ustream.tv*.ingest.video.ibm.com
Frequently Asked Questions
My company uses a proxy service such as Zscaler. Do I need to bypass all listed IP address destinations?
Yes. To reduce management overhead, IBM strongly recommends allowing all IP addresses listed in this article.
IBM Video Streaming uses the source IP address of the player to route playback requests to the closest configured ECDN server or external CDN provider. Routing playback traffic through a centralized proxy may cause suboptimal performance.
If your organization uses proxy services such as Zscaler, traffic to the listed IP address ranges should bypass the proxy.
Who owns the IP addresses listed in this article?
Unless explicitly stated otherwise, all IP addresses listed in this article are owned and managed by IBM.
How often do these IP addresses change?
The IP addresses listed in this article rarely change. If changes are required, IBM will provide 30 days’ notice so customers can update their firewall settings.
Setting Up Firewall Rules on Microsoft Windows 10
- Open Control Panel.
- Click System and Security.
- Click Windows Defender Firewall.
- In the left pane, click Advanced settings.
- In the left pane, right-click Outbound Rules.
- Select New Rule.
- Select Port.
- Select TCP or UDP.
- Specify the required port.
- Select Allow the connection.
- Select when the rule applies based on your preferences.
- Name the rule.
Setting Up Firewall Rules on macOS
For macOS firewall configuration, refer to Apple’s firewall settings documentation. Replace the port numbers in Apple’s instructions with the ports listed in this article.
Changelog
2025-05-06
Added the following IP ranges:
- 169.63.177.88/32 - Washington, D.C., USA, North America
- 169.63.98.153/32 - Washington, D.C., USA, North America
2025-04-11
Added the following IP ranges:
- 169.63.101.66/32 - Washington, D.C., USA, North America
- 169.63.164.185/32 - Washington, D.C., USA, North America
- 150.239.225.76/32 - Washington, D.C., USA, North America
2020-07-02
Removed the following IP ranges:
- 199.66.236.0/22 - San Jose, CA, USA, North America
- 185.23.108.0/24 - Amsterdam, Netherlands, Europe
2020-06-12
Added the following IP address:
- 169.55.4.192/26 - Dallas, TX, USA, North America
2018-06-26
IRC-based chat was replaced by a web-based chat tool. References to outdated IRC ports were removed. Entries for ports 843, 6667, and 8076 may be deleted.
Was this topic helpful?
Document Information
Modified date:
09 June 2026
UID
ibm17275645