Azure outbound network access destinations
If you have limited outbound internet access (for example, due to using a firewall or proxy), review this content to learn which specific outbound destinations must be available in order to register a Cloudera environment.
Cloudera recommends hostname-based policies, as some of the destination services do not have static IP addresses. IP address details in CIDR notation have been provided where static IPs are in-use.
The following tables include general destinations as well as Azure-specific destinations.
| Descriptiona/Usage | Cloudera service | Destination | Protocol and Authentication | IP Protocol/Port | Comments |
|---|---|---|---|---|---|
|
Control Plane API |
All services |
US-based Control Plane:
EU-based Control Plane:
AP-based Control Plane:
|
HTTPS with Cloudera-generated access key |
TCP/443 |
Cloudera Control Plane REST API. |
|
Cloudera CCMv2 Persistent Control Plane connection |
All services |
US-based Control Plane:
EU-based Control Plane:
AP-based Control Plane:
|
HTTPS with mutual authentication |
TCP/443 |
Multiple long-lived/persistent connections |
|
Cloudera Databus Telemetry, billing and metering data |
All services |
US-based Control Plane:
EU-based Control Plane:
AP-based Control Plane:
|
HTTPS with Cloudera-generated access key for dbus HTTPS for S3 |
TCP/443 |
Regular interval for telemetry, billing, metering services, and used for Cloudera Observability if enabled. Larger payloads are sent to a Cloudera managed S3 bucket. |
|
Cloudera Observability Metrics System metrics collection |
All services |
US-based Control Plane:
EU-based Control Plane:
AP-based Control Plane:
|
HTTPS |
TCP/443 |
New as of March 2024. |
|
Cloudera Manager parcels Software distribution |
All services |
archive.cloudera.com |
HTTPS |
TCP/443 |
Cloudera's public software repository. CDN backed service; IP range not predictable. |
|
RPMs Cloudera RPMs for workload agents |
All services |
cloudera-service-delivery-cache.s3.amazonaws.com |
HTTPS |
TCP/443 |
RPM packages for some workload componentss. |
| Description/Usage | Cloudera service | Destination | Protocol and Authentication | IP Protocol/Port | Comments |
|---|---|---|---|---|---|
|
General Azure guidelines |
All services |
See Safelist the Azure portal URLs on your firewall or proxy server for Azure egress best practices. |
|||
|
All services |
<STORAGE_ACCOUNT_NAME>.dfs.core.windows.net |
HTTPS Azure authentication |
TCP/443 |
Azure Storage VPC endpoint is required (Microsoft.Storage).Replace
|
|
|
All services |
*.postgres.database.azure.com |
JDBC / Postgres binary protocol |
TCP/5432 |
Azure SQL VPC endpoint is required (Microsoft.Sql). |
|
|
ARM to manage User Assigned Managed Identities |
All services |
management.azure.com |
HTTPS Azure authentication |
TCP/443 |
This can be allowed by using the AzureResourceManager Azure service tag. Additionally IP addresses to whitelist are available to download. |
|
All services |
*.agentsvc.azure-automation.net *.ods.opinsights.azure.com *.oms.opinsights.azure.com *.blob.core.windows.net |
HTTPS Azure authentication |
TCP/443 |
Optional, but may cause issues with Azure approved images if blocked. |
|
