Running the Agent Behind a Proxy or Firewall
The outbound network access the SeqOps server agent needs, and why no inbound rules are required.
The SeqOps server agent needs outbound HTTPS only. It needs no inbound firewall rules, no open ports, and no cloud credentials on the server.
Required Outbound Access
| Destination | Port | Used by |
|---|---|---|
sepi.seqops.io | 443 (HTTPS) | Linux agents |
sepi.seqops.io | 8443 (HTTPS) | Windows agent provisioning |
These are the server URLs used by the provisioning helper in the SeqOps Agent Installation Guide.
What the Agent Does Not Need
- •Inbound firewall rules — The agent opens every connection itself, outbound. Nothing needs to connect in to the server.
- •Open listening ports — The agent does not accept incoming connections.
- •Cloud credentials — The server holds only its own agent registration. Cloud environments are connected separately, with read-only credentials entered in SeqOps.
Behind a Proxy
If outbound traffic from the server passes through a proxy, the proxy must allow HTTPS to sepi.seqops.io on the ports above. If the proxy blocks it, the agent can't connect and the server shows as offline.
Checking Connectivity
From the server, confirm that it can reach sepi.seqops.io on the required port — for example with curl on Linux or Test-NetConnection on Windows.
Need Help?
If the agent can't connect after the firewall and proxy allow this traffic, see Agent Shows Offline: Step-by-Step Diagnosis or contact support@seqops.io or use the Contact Us page.