Skip to main content

Service Endpoints & Public IPs

This document covers outbound firewall and proxy rules for Cloudaware services.

Breeze

Outbound connectivity from Breeze Agents to the Cloudaware Breeze service is required for normal operation.

Breeze Connection Details

  • Hostname: breeze-server.cloudaware.com
  • Protocol/Port: HTTPS (TCP 443)
  • Public IP Address: 34.8.229.223

Breeze Allowlisting Guidance

  • Allowlist outbound HTTPS (TCP 443) from all Breeze Agent hosts to breeze-server.cloudaware.com.
  • If your security model relies on static IPs, allowlist 34.8.229.223 as the Breeze service public IP address.

TunHub

TunHub Connection Details

  • Hostname: gw.tunhub.cloudaware.com, api.tunhub.cloudaware.com
  • Protocol/Ports: HTTPS (TCP 443, 20000–21999)
  • Public IP Addresses: 136.114.23.96, 35.208.52.229

TunHub Allowlisting Guidance

Allowlist outbound HTTPS from all TunHub components to:

  • gw.tunhub.clodaware.com, IP 136.114.23.96, ports: 443, 20000-21999
  • api.tunhub.cloudaware.com, IP 35.208.52.229, port 443

Operational Notes

  • Prefer hostname-based allowlisting whenever possible. Hostname rules require fewer updates if Cloudaware rotates or expands IP ranges.
  • If you rely on static IP allowlists, use centralized or automated firewall policy management to simplify and standardize allowlist updates.
  • Review this page periodically as part of your baseline security review. Cloudaware may introduce additional endpoints, services, or IP addresses over time.