MOCREO Sensor SystemReference
Network Requirements and Firewall Configuration
Ports and destination domains the Hub, the Sensor App, and the Web Portal need; outbound only, no inbound connection is required.
Most customers do not need this information. It applies to networks with firewalls or other security measures, such as corporate or enterprise environments; provide it to your IT staff when needed.
In short: the Hub needs outbound TCP ports 80, 443, and 8883 plus UDP port 123 (NTP). No inbound connection is required. The Hub MAC address is shown in the App during setup as soon as the Hub is connected to the phone.
Services Required by the Hub (Outbound)
| Protocol | Port | Destination Domain | Function |
|---|---|---|---|
| TCP | 8883 | a1zjlbcv9qbzin-ats.iot.us-west-2.amazonaws.com | MQTT remote notification |
| TCP | 443 | mocreo.com | MOCREO device/client API |
| TCP | 443 | sync.sync-sign.com | Device health report |
| TCP | 443 | update.sync-sign.com | OTA update server |
| TCP | 443 | file.sync-sign.com | Image assets resource server |
| TCP | 80 | pub.sync-sign.com | Time server (failsafe to NTP) |
Basic Network Services (Outbound)
| Protocol | Port | Destination Domain | Function |
|---|---|---|---|
| UDP | 123 | pool.ntp.org, 0.asia.pool.ntp.org, europe.pool.ntp.org, time.google.com, 0.north-america.pool.ntp.org | NTP time synchronisation |
Services Required by the Sensor App and Web Portal (Outbound)
| Protocol | Port | Destination Domain | Function |
|---|---|---|---|
| TCP | 443 | portal.mocreo.com | Web Portal webpages |
| TCP | 443 | a1zjlbcv9qbzin-ats.iot.us-west-2.amazonaws.com | MQTT remote notification (WSS) |
| TCP | 443 | mocreo.com | MOCREO device/client API |
Inbound to the Hub (Optional)
Only needed to reach the Hub's built-in web server from your local network. It is usually not necessary to open this port to the public network.
| Protocol | Port | Destination IP | Function |
|---|---|---|---|
| TCP | 80 | 192.168.x.x (the local IP the Hub obtained) | Hub Web Portal |