IBM Support

Opening Firewall/Proxy Ports (General)

General Page

This article explains the firewall and network configuration requirements for IBM Video Streaming and IBM Enterprise Video Streaming. It outlines the ports, IP address ranges, domain whitelisting requirements, and ECDN-specific settings needed for both viewing and broadcasting streams.
The guide also provides proxy configuration recommendations, firewall setup instructions for Windows and macOS, and answers common networking and connectivity questions to help ensure reliable streaming performance.

Firewall Requirements for IBM Video Streaming

To broadcast or view streams through IBM Video Streaming, make sure your firewall allows traffic on the required ports. A firewall may exist on your local computer, router, or corporate network.

Firewall Settings for Viewing Streams

To watch IBM Video Streaming content, configure the following stateful firewall rules:

  • Outgoing UDP destination port 53 to your nameserver or any IP for DNS resolution.
  • Outgoing TCP destination ports 80 and 443 to any IP for web access.
  • Outgoing TCP destination port 1935 to any IP for RTMP streaming.
  • Outgoing TCP destination ports 8001-8004 to the IP address ranges listed below for web-based chat.

Firewall Settings for Broadcasting

To broadcast through IBM Video Streaming, configure the following stateful firewall rules. If you are behind a corporate firewall, ask your IT department to configure these settings.

  • Outgoing UDP destination port 53 to your nameserver or any IP for DNS resolution.
  • Outgoing TCP destination ports 80 and 443 to the IP address ranges listed below for web access.
  • Outgoing TCP destination port 1935 to the IP address ranges listed below for RTMP streaming.

Optional Secure Ingest Ports

If secure ingest is enabled for your account, also allow:

  • Outgoing TCP destination port 4444 to the IP address ranges listed below.
  • Outgoing UDP destination ports 2070-2090 to the IP address ranges listed below.

Note: For RTMPS streams, use the following URL format in your encoder:

rtmps://CID.ingest.video.ibm.com/ustreamVideo/CID

IP Address Ranges

Create firewall filters for the following IP address ranges. To help ensure a smooth streaming experience, whitelist all listed IP address ranges, regardless of which locations are closest to your streaming location.

IP Address / RangeLocation
169.53.37.192/27Dallas, TX, USA, North America
169.50.20.32/27Frankfurt, Germany, Europe
158.177.22.246/32Frankfurt, Germany, Europe
169.50.194.128/27London, United Kingdom, Europe
169.57.165.32/27Sao Paulo, Brazil, South America
168.1.193.160/27Sydney, Australia, Oceania
161.202.236.96/27Tokyo, Japan, Asia
169.47.38.32/27Washington, D.C., USA, North America
169.63.98.153/32Washington, D.C., USA, North America
169.63.101.66/32Washington, D.C., USA, North America
169.63.164.185/32Washington, D.C., USA, North America
169.63.177.88/32Washington, D.C., USA, North America
150.239.225.76/32Washington, D.C., USA, North America
52.116.124.41/32Washington, D.C., USA, North America
169.63.178.76/32Washington, D.C., USA, North America
52.117.122.135/32Washington, D.C., USA, North America
150.239.108.159/32Washington, D.C., USA, North America
169.59.162.41/32Washington, D.C., USA, North America
150.239.220.16/32Washington, D.C., USA, North America
169.38.91.128/28Chennai, India, Asia
169.55.185.16/28Toronto, Canada, North America
169.44.203.0/25San Jose, CA, USA, North America
169.44.178.0/24San Jose, CA, USA, North America
169.62.88.224/27San Jose, CA, USA, North America
169.62.84.80/28San Jose, CA, USA, North America
169.44.198.144San Jose, CA, USA, North America (Aspera Connect)
169.44.198.128San Jose, CA, USA, North America (Aspera Connect)
161.202.195.128/27Singapore, Singapore, Asia
150.240.166.168Dallas, TX, USA, North America
150.239.171.217Dallas, TX, USA, North America
150.240.167.103/32Dallas, TX, USA, North America
52.116.203.67/32Dallas, TX, USA, North America
169.59.29.201/32Dallas, TX, USA, North America
52.116.131.227/32Dallas, TX, USA, North America
52.116.202.54/32Dallas, TX, USA, North America
52.117.6.163/32Dallas, TX, USA, North America

 

Additional Firewall Settings for ECDN Servers

ECDN servers are deployed behind customer firewalls and act as local caches for video streaming content. To pull content from IBM Video Streaming, ECDN servers require outbound internet connectivity. No inbound connectivity from the internet is required.

Clock Synchronization

Clock synchronization is required for SSL connections to work.

  • Allow outgoing UDP port 123.
  • Use a local NTP server, or allow access to [0-3].ubuntu.pool.ntp.org.

OpenVPN Access for Support

Allow OpenVPN traffic over port 443 to:

terminator.deepcaching.com

This allows IBM Video ECDN operations to remotely access ECDN servers for upgrades or troubleshooting when the VPN connection is enabled in the ECDN Management Portal.

Child-Parent Proxy

Port 3128 is required only when the child-parent proxy feature is enabled.

Starting with ECDN server version 2.4.2, child ECDN servers can use parent ECDN servers as a proxy for HTTPS calls to the internet. This optional feature can be enabled by IBM upon customer request.

Domain Names

Many enterprise customers use a proxy server to manage HTTP and HTTPS traffic. To avoid routing large volumes of video traffic through a proxy, configure proxy bypass rules for the following domain names.

Control Plane Domains

Control plane traffic includes web portal access, support services, and management traffic. This traffic may flow through the proxy or bypass it.

  • ustream.tv
  • .ustream.tv
  • ustreamstatic-a.akamaihd.net
  • ustvstaticcdn1-a.akamaihd.net
  • ustvstaticcdn2-a.akamaihd.net
  • *.deepcaching.com
  • video.ibm.com
  • *.video.ibm.com
  • *.services.video.ibm.com
  • *.ums.services.video.ibm.com
  • *.ums.ustream.tv
  • *.ecdn.video.ibm.com
  • ubuntu.pool.ntp.org

Data Plane Domains

Data plane traffic includes large volumes of video data pulled by the video player. This traffic should bypass the proxy.

  • *.deepcaching.net
  • vod-cdn.ustream.tv
  • ustreamssl-a.akamaihd.net
  • uhsakamai-a.akamaihd.net
  • *.midgress.deepcaching.net
  • *.fme.ustream.tv
  • *.ingest.video.ibm.com

 

Frequently Asked Questions

My company uses a proxy service such as Zscaler. Do I need to bypass all listed IP address destinations?

Yes. To reduce management overhead, IBM strongly recommends allowing all IP addresses listed in this article.

IBM Video Streaming uses the source IP address of the player to route playback requests to the closest configured ECDN server or external CDN provider. Routing playback traffic through a centralized proxy may cause suboptimal performance.

If your organization uses proxy services such as Zscaler, traffic to the listed IP address ranges should bypass the proxy.

Who owns the IP addresses listed in this article?

Unless explicitly stated otherwise, all IP addresses listed in this article are owned and managed by IBM.

How often do these IP addresses change?

The IP addresses listed in this article rarely change. If changes are required, IBM will provide 30 days’ notice so customers can update their firewall settings.

Setting Up Firewall Rules on Microsoft Windows 10

  1. Open Control Panel.
  2. Click System and Security.
  3. Click Windows Defender Firewall.
  4. In the left pane, click Advanced settings.
  5. In the left pane, right-click Outbound Rules.
  6. Select New Rule.
  7. Select Port.
  8. Select TCP or UDP.
  9. Specify the required port.
  10. Select Allow the connection.
  11. Select when the rule applies based on your preferences.
  12. Name the rule.

Setting Up Firewall Rules on macOS

For macOS firewall configuration, refer to Apple’s firewall settings documentation. Replace the port numbers in Apple’s instructions with the ports listed in this article.

Changelog

2025-05-06

Added the following IP ranges:

  • 169.63.177.88/32 - Washington, D.C., USA, North America
  • 169.63.98.153/32 - Washington, D.C., USA, North America

2025-04-11

Added the following IP ranges:

  • 169.63.101.66/32 - Washington, D.C., USA, North America
  • 169.63.164.185/32 - Washington, D.C., USA, North America
  • 150.239.225.76/32 - Washington, D.C., USA, North America

2020-07-02

Removed the following IP ranges:

  • 199.66.236.0/22 - San Jose, CA, USA, North America
  • 185.23.108.0/24 - Amsterdam, Netherlands, Europe

2020-06-12

Added the following IP address:

  • 169.55.4.192/26 - Dallas, TX, USA, North America

2018-06-26

IRC-based chat was replaced by a web-based chat tool. References to outdated IRC ports were removed. Entries for ports 843, 6667, and 8076 may be deleted.

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSLQ0V","label":"IBM Video Streaming"},"ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":""}]

Document Information

Modified date:
09 June 2026

UID

ibm17275645