Views:
The following firewall exceptions apply to networks with:

TrendAI Vision One™ Authentication

Service
Region
Exceptions
TrendAI Vision One™
  • All
signin.v1.trendmicro.com
tm.login.trendmicro.com
iamservice.trendmicro.com
Other custom IDP services
Google reCAPTCHA:
www.gstatic.com
fonts.gstatic.com
Plus one of the following:
www.google.com (recommended)
www.recaptcha.net

Endpoint Security Exceptions

Service / Agent
Region
Exceptions
Endpoint Sensor features
  • All
assessment-ap5.mgcp.trendmicro.com
release-us1.mgcp.trendmicro.com
api-ap5.xbc.trendmicro.com
tgw-ap5.mgcp.trendmicro.com
support-connector-api.manage.trendmicro.com
supportconnectorpacks.manage.trendmicro.com
rpcollectedthings.manage.trendmicro.com
cloudendpoint-ap5.mgcp.trendmicro.com
er-ws-as1.xdr.trendmicro.com
era-as1.xdr.trendmicro.com
endpointpolicy-cdn-ap5.xbc.trendmicro.com
files.trendmicro.com
xlogr-as1.xdr.trendmicro.com
api.in.xdr.trendmicro.com
api-cert.in.xdr.trendmicro.com
upload.in.xdr.trendmicro.com
wsc-ap5.xbc.trendmicro.com
files.trendmicro.com
ipv6-iaus.trendmicro.com
ipv6-iaus.activeupdate.trendmicro.com
iaus.activeupdate.trendmicro.com
iaus.trendmicro.com
Browser extension
Important
Important
Apply these exceptions if you enable the feature using Endpoint Sensor or the Web Reputation module in Standard Endpoint Protection.
  • All
clients2.google.com/service/update2/crx
edge.microsoft.com/extensionwebstorebase/v1/crx
Sandbox Analysis
  • All
sandbox-threatconnect.trendmicro.com
Standard Endpoint Protection features
Important
Important
If you enable endpoint sensor detection and response, you must also add the Endpoint Sensor features exceptions.
  • All
<Apex One console_DNS>.manage.trendmicro.com
licenseupdate.trendmicro.com
asm01-nabu-prod.aot.trendmicro.com
api-nabu.aot.trendmicro.com
osce14-p.activeupdate.trendmicro.com
tmsm35-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
osce14.icrc.trendmicro.com
osce14-0-en.url.trendmicro.com
osce140-en.fbs25.trendmicro.com
osce14-en.gfrbridge.trendmicro.com
osce14-en-census.trendmicro.com
osce14bak-en-census.trendmicro.com
osce140-en-f.trx.trendmicro.com
oscecmp140-en-f.trx.trendmicro.com
osce140-en-b.trx.trendmicro.com
mcs.trendmicro.com
www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/
files.trendmicro.com
aurd-test2.activeupdate.trendmicro.com
support-connector-api.manage.trendmicro.com
support-connector-service.manage.trendmicro.com
supportconnectorpacks.manage.trendmicro.com
rpcollectedthings.blob.core.windows.net
macOS Agents:
tmsm35.icrc.trendmicro.com/ss
tmsm3-5-cs.url.trendmicro.com
tmsm3-5-de.url.trendmicro.com
tmsm3-5-en.url.trendmicro.com
tmsm3-5-es.url.trendmicro.com
tmsm3-5-fr.url.trendmicro.com
tmsm3-5-it.url.trendmicro.com
tmsm3-5-pl.url.trendmicro.com
tmsm3-5-tc.url.trendmicro.com
tmsm35-cs.gfrbridge.trendmicro.com
tmsm35-de.gfrbridge.trendmicro.com
tmsm35-en.gfrbridge.trendmicro.com
tmsm35-es.gfrbridge.trendmicro.com
tmsm35-fr.gfrbridge.trendmicro.com
tmsm35-it.gfrbridge.trendmicro.com
tmsm35-pl.gfrbridge.trendmicro.com
tmsm35-tc.gfrbridge.trendmicro.com
tmsm350-cs.fbs25.trendmicro.com
tmsm350-de.fbs25.trendmicro.com
tmsm350-en.fbs25.trendmicro.com
tmsm350-es.fbs25.trendmicro.com
tmsm350-fr.fbs25.trendmicro.com
tmsm350-it.fbs25.trendmicro.com
tmsm350-pl.fbs25.trendmicro.com
tmsm350-tc.fbs25.trendmicro.com
Server & Workload Protection Agents
Important
Important
If you enable endpoint sensor detection and response, you must also add the Endpoint Sensor features exceptions.
  • All regions
workload.in-1.cloudone.trendmicro.com
agents.workload.in-1.cloudone.trendmicro.com
<agents-001 through agents-010>.workload.in-1.cloudone.trendmicro.com
agent-comm.workload.in-1.cloudone.trendmicro.com
dsmim.workload.in-1.cloudone.trendmicro.com
relay.workload.in-1.cloudone.trendmicro.com
xdr-resp-ioc.workload.in-1.cloudone.trendmicro.com
files.trendmicro.com
iaus.activeupdate.trendmicro.com
iaus.trendmicro.com
ipv6-iaus.trendmicro.com
ipv6-iaus.activeupdate.trendmicro.com
dsaas1100-en-census.trendmicro.com
ds200-en.fbs25.trendmicro.com
ds200-jp.fbs25.trendmicro.com
dsaas.icrc.trendmicro.com
dsaas-en-f.trx.trendmicro.com
dsaas-en-b.trx.trendmicro.com
deepsecaas11-en.gfrbridge.trendmicro.com
dsaas.url.trendmicro.com
gateway.workload.in-1.cloudone.trendmicro.com
gateway-control.workload.in-1.cloudone.trendmicro.com
relay.deepsecurity.trendmicro.com
Firewall EIP Block:
workload.in-1.cloudone.trendmicro.com (3.108.13.32/27, 18.96.226.0/27)
agents.workload.in-1.cloudone.trendmicro.com (3.108.13.32/27, 18.96.226.0/27)
relay.workload.in-1.cloudone.trendmicro.com (3.108.13.32/27, 18.96.226.0/27)
dsmim.workload.in-1.cloudone.trendmicro.com (3.108.13.32/27, 18.96.226.0/27)
<agents-001 through agents-010>.workload.in-1.cloudone.trendmicro.com (3.108.13.32/27, 18.96.226.0/27)
Zero Trust Secure Access Exceptions
Important
Important
You must also specify the exceptions for the Endpoint Sensor Agents. These exceptions are found at Endpoint Sensor Agents.
Service
Region
Exceptions
Access Module
  • All
prod.ztsaagent.trendmicro.com
upload.in.xdr.trendmicro.com
event-in.ztsaagent.trendmicro.com
Authentication
  • All
agent-in-rel.ztna.trendmicro.com
signin.v1.trendmicro.com
tm.login.trendmicro.com
iamservice.trendmicro.com
Other custom IDP services
Google reCAPTCHA:
www.gstatic.com
fonts.gstatic.com
Plus one of the following:
www.google.com (recommended)
www.recaptcha.net
Internet Access Service
  • All
auth.ztsa-iag.trendmicro.com
pac.in.ztsa-iag.trendmicro.com
auth.in.ztsa-iag.trendmicro.com
Internet Access Cloud Gateway
  • All
proxy.ztsa-iag.trendmicro.com
proxy.in.ztsa-iag.trendmicro.com
d9vbqsel5dvrs.cloudfront.net
Internet Access On-Premises Gateway with Smart Protection Network: Off
  • All
xlogr-an1.xdr.trendmicro.com
api.ap-south-1.in.ddcloud.trendmicro.com
iwsh30-en.url.trendmicro.com
api-ap-southeast-1.crs.trendmicro.com
iwsh300-en.census.trendmicro.com
iwsaas30-en-f.trx.trendmicro.com
iwsh30-p.activeupdate.trendmicro.com
d9vbqsel5dvrs.cloudfront.net
Internet Access On-Premises Gateway with Smart Protection Network: On
  • All
xlogr-an1.xdr.trendmicro.com
api.ap-south-1.in.ddcloud.trendmicro.com
ctapi.trendmicro.com
iwsh30-p.activeupdate.trendmicro.com
d9vbqsel5dvrs.cloudfront.net
Private Access Connector
  • All
agent-in-rel.ztna.trendmicro.com
saseztnaprodinsagen2.blob.core.windows.net
saseztnaprodinsa.blob.core.windows.net
sase-ztna-prod-in-iothub-cntevt.azure-devices.net
speedtest.in.ztna.trendmicro.com
ztnaextacr.azurecr.io
0.pool.ntp.org
1.pool.ntp.org
2.pool.ntp.org
3.pool.ntp.org
Private Access Connector
(if not using the Trend Cloud Proxy service)
Australia
20.5.69.128/28
Europe
20.4.51.32/28
India
20.219.254.160/28
Israel
20.217.194.0/28
Japan
52.140.246.128/28
Singapore
52.187.118.64/28
United States
20.7.52.240/28
Brazil
4.228.193.144/28
MEA
20.74.229.224/28
United Kingdom
20.0.229.192/28
Canada
40.82.166.0/28

Service Gateway Exceptions

Service
Region
Exceptions
Firmware
  • All
sgi-tunneling.in.xdr.trendmicro.com
sgi-iot.in.xdr.trendmicro.com
api.in.xdr.trendmicro.com
upload.in.xdr.trendmicro.com
Smart Protection Network proxy: On
  • All
ctapi.trendmicro.com
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Smart Protection Network proxy: Off
  • All
sg-tmsps10-en.url.trendmicro.com
sg-tmsps10-en-wis.trendmicro.com
sg-tmsps100-en-census.trendmicro.com
sg-tmsps100-en-domaincensus.trendmicro.com
grid-global.trendmicro.com
rest.mars.trendmicro.com
sg-tmsps10-en.gfrbridge.trendmicro.com
sg-tmsps10-p.activeupdate.trendmicro.com
sg-tmsps10-en-backup.url.trendmicro.com
activeupdate.trendmicro.com
Local ActiveUpdate
  • All
Refer to ActiveUpdate session of each product/agent

Forensics and Analysis

Service / Agent
Region
Exceptions
IR Tool Download for Agent
  • India
resources.prod-ap-south-1.irs.trendmicro.com

TrendAI Vision One™ Container Security

Service
Region
Exceptions
Mandatory for Container Security
  • All
api.in.xdr.trendmicro.com
vcs-storage-in.xdr.trendmicro.com
Artifact Scanner
  • All
api.in.xdr.trendmicro.com
ast-upload-in.xdr.trendmicro.com
ast-report-in.xdr.trendmicro.com
ast-cli.xdr.trendmicro.com
antimalware.in-1.cloudone.trendmicro.com
Runtime Security
  • All
api.in.xdr.trendmicro.com
vcs-iot-in.xdr.trendmicro.com
vcs-storage-in.xdr.trendmicro.com
Runtime Malware Scanning
  • All
activeupdate.trendmicro.com
Default Container Image Access
  • All
public.ecr.aws
*.cloudfront.net

TippingPoint Exceptions

Service
Region
Exceptions
TippingPoint
Australia
a1mmnfkx71i3sj-ats.iot.ap-southeast-2.amazonaws.com
Europe
a1mmnfkx71i3sj-ats.iot.eu-central-1.amazonaws.com
India
a1mmnfkx71i3sj-ats.iot.ap-south-1.amazonaws.com
Japan
a1mmnfkx71i3sj-ats.iot.ap-northeast-1.amazonaws.com
Singapore
a1mmnfkx71i3sj-ats.iot.ap-southeast-1.amazonaws.com
United Kingdom
a1mmnfkx71i3sj-ats.iot.eu-west-2.amazonaws.com
United States
a1mmnfkx71i3sj-ats.iot.us-east-1.amazonaws.com

Network Inventory

Service
Region
Exceptions
Virtual Network Sensor
India
xns-p.activeupdate.trendmicro.com
gp.fbs.trendmicro.com
xlogr-as1.xdr.trendmicro.com
api.in.xdr.trendmicro.com
licenseupdate.trendmicro.com
For customers with "Send to Sandbox" enabled, add the following as well:
ctapi.trendmicro.com
api.ddcloud.trendmicro.com
api.in.ddcloud.trendmicro.com
Deep Discovery Inspector version 6.8 Service Pack 1 / 6.8 Service Pack 2
India
api.ddcloud.trendmicro.com
api.in.ddcloud.trendmicro.com
api.in.xdr.trendmicro.com
ctapi.trendmicro.com
ddaaas.trendmicro.com
ddi681.retroscan.trendmicro.com
ddi68-p.activeupdate.trendmicro.com/activeupdate
gp.fbs.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
xlogr-as1.xdr.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Deep Discovery Inspector version 6.8
India
api-ni-in.xdr.trendmicro.com
api.ddcloud.trendmicro.com
api.in.ddcloud.trendmicro.com
api.in.xdr.nacloud.trendmicro.com
api.in.xdr.trendmicro.com
ddaaas.trendmicro.com
gp.fbs.trendmicro.com
grid-global.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
rest.mars.trendmicro.com
xlogr-as1.xdr.trendmicro.com
ddi68-en-f.trx.trendmicro.com
ddi68-p.activeupdate.trendmicro.com/activeupdate
ddi68.retroscan.trendmicro.com
ddi6-8-en-t0.url.trendmicro.com
ddi6-8-en-wis.trendmicro.com
ddi6-8-en.url.trendmicro.com
ddi680-en-census.trendmicro.com
ddi680-en-domaincensus.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Deep Discovery Inspector version 6.7 / 6.7 Service Pack 1
India
api-ni-in.xdr.trendmicro.com
api.ddcloud.trendmicro.com
api.in.ddcloud.trendmicro.com
api.in.xdr.nacloud.trendmicro.com
api.in.xdr.trendmicro.com
ddaaas.trendmicro.com
gp.fbs.trendmicro.com
grid-global.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
rest.mars.trendmicro.com
xlogr-as1.xdr.trendmicro.com
ddi67-en-f.trx.trendmicro.com
ddi67-p.activeupdate.trendmicro.com/activeupdate
ddi67.retroscan.trendmicro.com
ddi6-7-en-t0.url.trendmicro.com
ddi6-7-en-wis.trendmicro.com
ddi6-7-en.url.trendmicro.com
ddi670-en-census.trendmicro.com
ddi670-en-domaincensus.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Deep Discovery Inspector version 6.6
India
api-ni-in.xdr.trendmicro.com
api.ddcloud.trendmicro.com
api.in.ddcloud.trendmicro.com
api.in.xdr.nacloud.trendmicro.com
ddaaas.trendmicro.com
gp.fbs.trendmicro.com
grid-global.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
rest.mars.trendmicro.com
xlogr-as1.xdr.trendmicro.com
ddi66-en-f.trx.trendmicro.com
ddi66-p.activeupdate.trendmicro.com/activeupdate
ddi66.retroscan.trendmicro.com
ddi6-6-en-t0.url.trendmicro.com
ddi6-6-en-wis.trendmicro.com
ddi6-6-en.url.trendmicro.com
ddi660-en-census.trendmicro.com
ddi660-en-domaincensus.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Deep Discovery Inspector version 6.5
India
api-ni-in.xdr.trendmicro.com
api.ddcloud.trendmicro.com
api.in.ddcloud.trendmicro.com
api.in.xdr.nacloud.trendmicro.com
ddaaas.trendmicro.com
gp.fbs.trendmicro.com
grid-global.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
rest.mars.trendmicro.com
xlogr-as1.xdr.trendmicro.com
ddi65-en-f.trx.trendmicro.com
ddi65-p.activeupdate.trendmicro.com/activeupdate
ddi65.retroscan.trendmicro.com
ddi6-5-en-t0.url.trendmicro.com
ddi6-5-en-wis.trendmicro.com
ddi6-5-en.url.trendmicro.com
ddi650-en-census.trendmicro.com
ddi650-en-domaincensus.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Deep Discovery Inspector version 6.2
India
api-ni-in.xdr.trendmicro.com
api.ddcloud.trendmicro.com
api.in.ddcloud.trendmicro.com
api.in.xdr.nacloud.trendmicro.com
ddaaas.trendmicro.com
gp.fbs.trendmicro.com
grid-global.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
rest.mars.trendmicro.com
xlogr-as1.xdr.trendmicro.com
ddi62-en-f.trx.trendmicro.com
ddi62-p.activeupdate.trendmicro.com/activeupdate
ddi62.retroscan.trendmicro.com
ddi6-2-en-t0.url.trendmicro.com
ddi6-2-en-wis.trendmicro.com
ddi6-2-en.url.trendmicro.com
ddi620-en-census.trendmicro.com
ddi620-en-domaincensus.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Deep Discovery Inspector version 6.0
India
api-ni-in.xdr.trendmicro.com
api.ddcloud.trendmicro.com
api.in.ddcloud.trendmicro.com
api.in.xdr.nacloud.trendmicro.com
ddaaas.trendmicro.com
gp.fbs.trendmicro.com
grid-global.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
rest.mars.trendmicro.com
xlogr-as1.xdr.trendmicro.com
ddi60-en-f.trx.trendmicro.com
ddi60-p.activeupdate.trendmicro.com/activeupdate
ddi60.retroscan.trendmicro.com
ddi6-0-en-t0.url.trendmicro.com
ddi6-0-en-wis.trendmicro.com
ddi6-0-en.url.trendmicro.com
ddi600-en-census.trendmicro.com
ddi600-en-domaincensus.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com

Mobile Seciurity for Android

Server
Region
Port
Exceptions
TrendMicro Mobile Security Backend
All
  • 80
  • 443
*.mobile.trendmicro.com
*.xdr.trendmicro.com
https://portal.mobile.trendmicro.com/ui/ami/mobile/h5/worryfree/openAndroidApp.html?productCode=wfbss&authCode=HWQj7aab&userPrincipalName=
rest.mars.trendmicro.com
rest-g.mars.trendmicro.com
rest-g-au.mars.trendmicro.com
mint.mars.trendmicro.com
portal-sg.mobile.trendmicro.com
*.ztna.trendmicro.com
*.ztsa-iag.trendmicro.com
logs.trendmicro.com
spnsupport.trendmicro.com
mxdr1-0.url.trendmicro.com mxdr1-0-im.url.trendmicro.com
http://*.trendmicro.com
https://*.trendmicro.com
GooglePlay / Firebase Server
All
  • 443
  • 5228
  • 5229
  • 5230
*.google.com
*.firebase.com
*.googleapis.com
*.firebaseio.com
Log feedback
All
  • 443
https://cognito-identity.us-west-2.amazonaws.com

Mobile Security for iOS

Server
Region
Port
Exceptions
TrendMicro Mobile Security Backend
All
  • 22
  • 80
  • 443
*.trendmicro.com
*.mobile.trendmicro.com
*.xdr.trendmicro.com
rest.mars.trendmicro.com
rest-g.mars.trendmicro.com
rest-g-au.mars.trendmicro.com
mint.mars.trendmicro.com
portal-sg.mobile.trendmicro.com
*.ztna.trendmicro.com
*.ztsa-iag.trendmicro.com
logs.trendmicro.com
spnsupport.trendmicro.com
mxdr1-0.url.trendmicro.com
mxdr1-0-im.url.trendmicro.com
mxdr1-0-ios.url.trendmicro.com
http://*.trendmicro.com
https://*.trendmicro.com
Apple Server
All
  • 443
  • 80
  • 5223
  • 2197
  • 123
*.apple.com
*.mzstatic.com
*.icloud.com
Firebase Server
All
  • 443
  • 5228
  • 5229
  • 5230
*.google.com
*.firebase.com
*.googleapis.com
*.firebaseio.com
Log feedback
All
  • 443
https://cognito-identity.us-west-2.amazonaws.com

TrendAI Vision One™ Agentless Vulnerability & Threat Detection Exceptions

Service
Region
Exceptions
Agentless Vulnerability and Threat Detection
India
googlecode.l.googleusercontent.com
sentry.in-1.cloudone.trendmicro.com
xlogr-as1.xdr.trendmicro.com

Security Awareness Exceptions

Service
Region
Exceptions
Security awareness
All
cdn.tiny.cloud

Cloud Risk Management

Service
Region
Exceptions
Real-Time Posture Monitoring
India
rtpm.apm-in.xdr.trendmicro.com
a2sx2v445s9fxl-ats.iot.ap-south-1.amazonaws.com

Executive Dashboard

Service
Region
Exceptions
XDR
All
download.xdr.trendmicro.com

LaunchDarkly exceptions

Service
Region
Exceptions
LaunchDarkly
  • All
For the complete list of required LaunchDarkly domains, see the LaunchDarkly domain list.