Allowing Outbound Traffic to RapidIdentity Cloud
RapidIdentity Cloud IP addresses may change during planned maintenance windows, or at the discretion of the cloud service provider. If you allow traffic from ports 443 and 80, you do not need to explicitly allow certain domains. The following services run on each port:
- Port 443
Port 443 serves the RapidIdentity portal used by students, parents, teachers, and administrators.
- Port 80
- Port 80 redirects unencrypted portal traffic to port 443 and listens for encrypted web services protocol connections.
If you have stricter security rules, you must add RapidIdentity domains and update your allowlist when those domains change. The following domains must be added, as well as any associated subdomains:
rapididentity.com
identitymanagement.net
us000-rapididentity.com
us001-rapididentity.com
us002-rapididentity.com
us003-rapididentity.com
us004-rapididentity.com
us005-rapididentity.com
us006-rapididentity.com
eu001-rapididentity.com
You must also add any custom domains with dedicated endpoint IPs on ports 80 and 443.
Allowing Traffic from RapidIdentity Cloud
Most traffic from RapidIdentity Cloud is tunneled over one or more encrypted identity bridges. To enable SFTP file transfers and RapidIdentity Connect jobs that make API calls to other cloud services, you must still enable domains associated with the NAT gateways, including the following:
3.210.0.81
3.214.194.8
3.230.75.110
3.232.202.13
3.233.193.134
13.48.53.173
16.16.39.79
18.213.77.211
18.215.109.69
34.235.78.167
34.228.33.86
52.205.96.173
52.4.132.24
54.90.158.12
54.144.14.93
72.44.53.174
98.88.219.50
98.89.233.164
184.73.31.52