Ports & Endpoints
This guide documents network endpoints and ports used by Breeze Agent and related services.
Breeze Agent
- Outbound HTTPS:
TCP 443from Breeze hosts to the Breeze service. - Hostname:
breeze-server.cloudaware.com. - No inbound access is required for Breeze Agent itself.
TunHub (Agent-Assisted Tunnels)
When Breeze hosts act as TunHub connectors for private networks:
- Outbound HTTPS:
TCP 443togw.tunhub.cloudaware.comandapi.tunhub.cloudaware.com. - TunHub (ports): outbound
TCP 20000–21999togw.tunhub.cloudaware.comwhen dedicated ports are used.
Cloud Provider Metadata
For cloud integrations, ensure instance metadata endpoints are reachable by the agent, for example: 169.254.169.254 on AWS, Azure, and many Linux cloud images.
Logs & Log Management
If you use Cloudaware Log Management (Conflux) or external SIEM/SOAR tools connected through Log Management, additional endpoints may be required for log forwarding.
Allowlisting
For a consolidated, up‑to‑date list of Breeze and TunHub hostnames, IPs, and ports to allowlist, see Service Endpoints & Public IPs or the Breeze Agent 1.x Requirements guide.