# Configuring the firewall for Test Cloud Public Sector

> For general network configuration and firewall information, refer to [Configuring the firewall](https://docs.uipath.com/test-cloud/automation-cloud/latest/admin-guide/configuring-firewall#configuring-the-firewall)

For general network configuration and firewall information, refer to [Configuring the firewall](https://docs.uipath.com/test-cloud/automation-cloud/latest/admin-guide/configuring-firewall#configuring-the-firewall)

## Test Cloud Public Sector Portal

The following table lists the domains used by Test Cloud Public Sector Portal:

 <colgroup>
  <col/>
  <col/>
 </colgroup>
 
  
    Scenario 
    Domains to Allow 
  
 
 
  
    UiPath Test Cloud Public Sector 
   
      <code>https://govcloud.uipath.us</code><code>https://govcloud.uipath.us/portal_/cloudrpa</code><code>https://govcloud.uipath.us/portal_/signinwithsso</code><code>https://govcloud.uipath.us/&lt;accountname&gt;/</code><code>https://govcloud.uipath.us/&lt;accountname&gt;/&lt;tenantname&gt;/portal</code>

  
  
    Login flows (configured via SSO) 
   
      <code>https://login.microsoftonline.com</code>

  
  
    Sign in with Azure Active Directory (Azure AD) 
   
      <code>https://aadcdn.msftauth.net</code><code>https://govcloud.uipath.us</code><code>https://login.microsoftonline.com</code>

  
  
    Sign in with UiPath Assistant (basic email) 
   
      <code>*-signalr.service.signalr.net</code>
 For events related to signing in with basic authentication: 
      <code>https://account.uipath.com</code><code>https://govcloud.uipath.us</code><code>https://platform-cdn.uipath.com</code>

  
  
    Sign in with UiPath Studio (basic email) 
   
      <code>https://api.nuget.org</code><code>*-signalr.service.signalr.net</code><code>https://gallery.uipath.com</code><code>https://pkgs.dev.azure.com</code>
 For events related to signing in with basic authentication: 
      <code>https://account.uipath.com</code><code>https://govcloud.uipath.us</code><code>https://platform-cdn.uipath.com</code>

  
  
    Static assets: Fonts, Styling and CDN hosted scripts 
     Fonts: 
      <code>https://use.typekit.net</code><code>https://fonts.gstatic.com</code><code>https://platform-cdn.uipath.com</code>
 Images: 
      <code>https://s.gravatar.com</code><code>https://secure.gravatar.com</code><code>https://*.wp.com</code><code>https://*.googleusercontent.com</code><code>https://i.ytimg.com</code><code>https://platform-cdn.uipath.com</code>
 CSS: 
      <code>https://fonts.googleapis.com/css</code><code>https://use.typekit.net</code><code>https://p.typekit.net</code><code>https://platform-cdn.uipath.com</code><code>https://staticresources.uipath.us</code>
 Scripts: 
      <code>https://primer.typekit.net</code><code>https://use.typekit.net</code><code>https://platform-cdn.uipath.com</code>

  
  
    Sign in via Auth0 (for EU) 
   
      <code>uipath.eu.auth0.com</code>

  
  
    Update services 
   
      <code>ctldl.windowsupdate.com</code>
 To configure network connections, use  Microsoft documentation  .  
  
  
    App Insights / Google Tag Manager 
   
      <code>https://usgovvirginia-0.in.applicationinsights.azure.us</code><code>https://www.googletagmanager.com/gtm.js?id=GTM-PLLP8P</code><code>https://code.jquery.com/jquery-3.5.1.min.js</code>

  
 

:::important
If you use Azure buckets, they must not be located in the tenant's region or in the failover region.
:::

### Outbound IP ranges

To ensure proper functionality for UiPath services, we recommend allowing the following IPs:

<pre><code>52.247.128.100
52.227.65.197
52.245.221.122</code></pre>

## Action Center

### Domains

The following table lists the domains used by Action Center that we recommend allowing, based on the functionality you plan to use:

 <colgroup>
  <col/>
  <col/>
 </colgroup>
 
  
    Scenario 
    Domains to Allow 
  
 
 
  
    Navigate to Action Center page 
   
      <code>https://govcloud.uipath.us/&lt;accountName&gt;/&lt;tenantName&gt;/actions_</code><code>https://govcloud.uipath.us/&lt;accountName&gt;/&lt;tenantName&gt;/processes_</code><code>https://govcloud.uipath.us/&lt;accountName&gt;/&lt;tenantName&gt;/bupproxyservice_</code><code>https://uipath-acc-pgov.uipath.us</code>

  
 

## Automation Cloud Robots - Serverless

### Static IP configuration

Static IP for Cloud Robot - Serverless enables you to route outbound network traffic through a dedicated, static IP address range managed by UiPath. This allows you to whitelist or securely integrate with external systems that restrict incoming connections to known IPs.

### Configuration

You can enable Static IP while [creating the Serverless template](https://docs.uipath.com/orchestrator/automation-cloud/latest/user-guide/executing-unattended-automations-with-serverless-robots#step-2-adding-serverless-robots-to-your-tenant) and going to the **Network Configuration** page.

### Availability

The Stable IP feature is available for Cloud Robot - Serverless in supported regions.

These static IP addresses can sometimes change as a result of infrastructure deployments. To help keep you on top of any changes, we have compiled a list of up-to-date static egress IPs, which you can check in the following tables.

Table 1. Community users

 
  
   Region
   CIDR
   Outbound IP ranges
  
 
 
  
   Europe
   <pre><code>20.191.43.0/30
20.191.42.240/30</code></pre>
   <pre><code>20.191.43.0
20.191.43.1
20.191.43.2
20.191.43.3
20.191.42.240
20.191.42.241
20.191.42.242
20.191.42.243</code></pre>
  
 

Table 2. Enterprise users

 
  
   Region
   CIDR
   Outbound IP ranges
  
 
 
  
   Australia
   <pre><code>20.53.170.116/30
20.53.170.208/30</code></pre>
   <pre><code>20.53.170.116
20.53.170.117
20.53.170.118
20.53.170.119
20.53.170.208
20.53.170.209
20.53.170.210
20.53.170.211</code></pre>
  
  
   United States
   <pre><code>20.102.5.168/30
20.102.0.76/30</code></pre>
   <pre><code>20.102.5.168
20.102.5.169
20.102.5.170
20.102.5.171
20.102.0.76
20.102.0.77
20.102.0.78
20.102.0.79</code></pre>
  
  
   Japan
   <pre><code>20.44.188.168/30
20.44.185.192/30</code></pre>
   <pre><code>20.44.188.168
20.44.188.169
20.44.188.170
20.44.188.171
20.44.185.192
20.44.185.193
20.44.185.194
20.44.185.195</code></pre>
  
  
   Europe (European Union)
   <pre><code>20.191.46.104/30
20.191.43.60/30</code></pre>
   <pre><code>20.191.46.104
20.191.46.105
20.191.46.106
20.191.46.107
20.191.43.60
20.191.43.61
20.191.43.62
20.191.43.63</code></pre>
  
 

## Automation Hub

### Domains

The following table lists the domains used by Automation Hub:

 <colgroup>
  <col/>
  <col/>
 </colgroup>
 
  
    Scenario 
    Domains to Allow 
  
 
 
  
    Navigate to the Automation Hub page 
   
      <code>https://govcloud.uipath.us</code><code>http://*.userpilot.io</code><code>https://dc.services.visualstudio.com</code><code>https://ah-prod-ts-blue-eu.uipath.com</code><code>https://ah-prod-ts-blue-us.uipath.com</code><code>https://ah-prod-ts-blue-ja.uipath.com</code><code>https://ah-prod-ts-blue-au.uipath.com</code><code>https://ah-prod-ts-blue-ca.uipath.com</code><code>https://ah-prod-ts-blue-sea.uipath.com</code><code>https://ah-prod-ts-blue-uk.uipath.com</code><code>https://ah-prod-ts-blue-in.uipath.com</code><code>https://ah-gxp-ts-blue-us.uipath.com</code>

  
  
    Use OpenAPI for Automation Hub 
   
      <code>https://automation-hub.uipath.com</code><code>http://ah-gxp-openapi-us.uipath.com</code>

  
  
    Access Public Sector in Automation Hub 
   
      <code>https://govcloud.uipath.us</code>

  
 

## Automation Ops

### Domains

The following table lists the domains used by Automation Ops:

 <colgroup>
  <col/>
  <col/>
 </colgroup>
 
  
    Scenario 
    Domains to Allow 
  
 
 
  
    Navigate to the Automation Ops page 
   
      <code>https://usgovvirginia-0.in.applicationinsights.azure.us</code><code>https://govcloud.uipath.us</code><code>https://staticresources.uipath.us</code><code>*-signalr.signalr.azure.us</code><code>https://use.typekit.net</code><code>https://p.typekit.net</code>

  
 

## Data Service

### Domains

The following table lists the domains used by Data Service:

 <colgroup>
  <col/>
  <col/>
 </colgroup>
 
  
    Scenario 
    Domains to Allow 
  
 
 
  
    All Data Service operations 
   
      <code>https://govcloud.uipath.us</code>

  
  
    Fetching static frontend content 
   
      <code>https://staticds.uipath.us</code>

  
 

## Document Understanding

### Domains

The following table lists the domains used by Document Understanding:

| Module or Scenario | Domains to Allow |
| --- | --- |
| Network and Storage | `https://*.uipath.us` |
| Telemetry and SignalR | `https://*.azure.us` |
| Public endpoints | Check the [Public endpoints](https://docs.uipath.com/document-understanding/automation-cloud-public-sector/latest/user-guide/public-endpoints) page for the full list of public endpoints URLs. |

## Insights

### Domains

The following table lists the domains used by Insights:

 <colgroup>
  <col/>
  <col/>
 </colgroup>
 
  
    Scenario 
    Domains to Allow 
  
 
 
  
    Navigate to the Insights page 
   
      <code>https://govcloud.uipath.us</code><code>https://*.lookercdn.com</code><code>https://uipath-insights-statics.azureedge.net/</code><code>https://*.looker.uipath.com/</code>

  
 

### Outbound static IP ranges

Outbound static IP ranges allow you to add a list of IPs for the Log Export functionality to the allowlist and not open your network to all external IPs.

To ensure proper performance for the Log Export functionality, make sure to add the [Outbound IP ranges](https://docs.uipath.com/test-cloud/automation-cloud/latest/admin-guide/configuring-the-firewall-for-public-sector#outbound-ip-ranges) from the **Test Cloud Public Sector Portal** section to the allowlist.

Due to a limitation on Microsoft side for Log Export, you cannot set up inbound IP restriction when your Azure blob storage account and the Insights infrastructure is under the same region in Azure. Because of this, you cannot use the USGov Virginia region for the blob storage account. For more information on this limitation, check the [Restrictions for IP network rules](https://learn.microsoft.com/en-us/azure/storage/common/storage-network-security?tabs=azure-portal#restrictions-for-ip-network-rules) page from the Microsoft Azure Blob Storage documentation.

## Orchestrator

### Domains

Robots send traffic to these Test Cloud Public Sector Orchestrator domains. We recommend that you allow them to ensure proper functioning of your automations, as described in the following table:

 <colgroup>
  <col/>
  <col/>
 </colgroup>
 
  
    Module or Functionality 
    Domains to Allow 
  
 
 
  
    UiPath Orchestrator 
   
      <code>https://govcloud.uipath.us</code><code>https://orch-cdn.uipath.com</code><code>https://account.uipath.com</code>

  
  
    Automation Cloud Public Sector Robots - VM 
   
      <code>https://govcloud.uipath.us</code><code>https://download.uipath.com</code>

  
  
    Storage 
     If using Amazon s3 buckets: 
      <code>*.s3.amazonaws.com</code>

  
  
     Package and library feeds  (library, tenant processes, and others)  
   
      <code>https://pkgs.dev.azure.com</code>

  
  
    Azure SignalR 
   
      <code>*.service.signalr.net</code>

  
  
    Studio and Robot auto-update functionality 
   
      <code>https://download.uipath.com</code>

  
  
    Traffic Manager (internal) 
   
      <code>*.trafficmanager.net</code>

  
 

## Process Mining

### Domains

The following table lists the domains used by Process Mining:

 <colgroup>
  <col/>
  <col/>
 </colgroup>
 
  
    Module or Scenario 
    Domains to Allow 
  
 
 
  
    Identity Server 
   
      <code>https://govcloud.uipath.us</code>

  
  
    Static assets 
   
      <code>https://fonts.googleapis.com</code><code>https://fonts.gstatic.com</code><code>https://content.usage.uipath.com</code><code>https://s.gravatar.com</code><code>https://i1.wp.com</code>

  
  
    Azure SignalR 
   
      <code>*.signalr.azure.us</code>

  
  
    Telemetry 
   
      <code>https://*.in.applicationinsights.azure.us</code>

  
  
    Upload files 
   
      <code>*.blob.core.usgovcloudapi.net</code>

  
 

## Test Manager

### Domains

The following table lists the domains used by Test Manager that we recommend allowing, based on the functionality you plan to use:

 <colgroup>
  <col/>
  <col/>
 </colgroup>
 
  
    Module or functionality 
    Domains to allow 
  
 
 
  
    UiPath Test Manager 
   
      <code>https://govcloud.uipath.us</code>

  
  
    Azure SignalR 
   
      <code>*.signalr.azure.us</code>
