Firewall requirements
The probe needs one thing from the network: to reach the collector over HTTPS.
| Direction | To | Port | Protocol |
|---|---|---|---|
| Outbound from each machine | collector-uk-1.bobcloud.net | 443 | HTTPS (TLS 1.2 or later) |
Nothing is needed inbound. The collector never connects to a machine; the probe always starts the conversation, once an hour. If automatic updates are switched on and a newer probe is offered, the probe downloads it from the same address, over the same port - nothing more to allow.
The Linux probe needs exactly the same: outbound HTTPS to the same address, nothing inbound, and its updates from the same address too.
Proxies
The probe uses the machine's system proxy setting, as Windows gives it to programs running as SYSTEM. If the proxy needs signing in, the machine's own account is used.
The Linux probe connects directly. It runs from a systemd timer, which does not see a proxy set in a login shell's environment, so a Linux machine that can reach the internet only through a proxy cannot report yet.
TLS inspection
The probe checks the collector's certificate against the certificates the machine trusts, as any program does. A proxy that inspects TLS will work only if its own certificate is trusted on the machine. We recommend leaving collector-uk-1.bobcloud.net out of inspection: it carries the probe's reports and, with automatic updates, new versions of the probe. (An update is checked against our signature on the machine, so inspection cannot slip a changed file past it.)
When it is blocked
A blocked probe stops reporting and turns up under Needs action as gone quiet. The diagnostics file (Collect diagnostics) tests each step - the name, the connection, the TLS handshake and whose certificate came back, and an HTTPS request - so it shows which one the firewall or proxy refused.
Next: What to tell your EDR