Overview
Lists the internet addresses Catalyst Center must be able to access.
You must provide secure access to the required URLs and Fully Qualified Domain Names (FQDNs) for the appliance to function.
This table describes the features that make use of each URL and FQDN. You must configure either your network firewall or a proxy server so that IP traffic can travel to and from the appliance and these resources.
If you do not provide access to the listed URLs and FQDNs, the associated features will not work as intended.
The appliance interface configured to route internet-bound traffic serves as the source for all communications.
Since the destination domain names for third-party vendors may change without notice, it is mandatory to specify them using wildcards.
For more information about internet proxy access requirements, see Provide secure access to the internet.
| In order to... | ...Catalyst Center must access these URLs and FQDNs |
|---|---|
| Download updates for system software and application packages, and submit user feedback to the product team. |
Recommended: *.ciscoconnectdna.com:4431 To avoid wildcards, specify these URLs instead:
|
| Submit user feedback to the product team. |
|
| Cisco Catalyst Center update package. |
|
| Smart Account and SWIM software downloads. |
|
| Authenticate with the cloud domain. |
|
| Integrate with ThousandEyes. |
Version 3.1.6 and later:
Version 3.1.5 and earlier:
|
| Allow API calls to enable access to Cisco CX Cloud Success Tracks. Otherwise, the enhancements made to extended configuration-based scanning for the Security Advisories, Bug Identifier, and EOX features that Machine Reasoning Engine (MRE) supports will not operate as expected. |
|
| Integrate with Webex. |
|
| User feedback. |
|
| Connectivity with Cisco Catalyst Cloud and apps hosted there (e.g. AppX MS Teams Integration, Talos integration). |
*.cisco.com:443 Otherwise, specific FQDNs are:
|
| Integrate with Cisco Meraki. |
(Version 3.1.5 and earlier) Recommended:
Customers who want to avoid wildcards can specify this URL instead: api.meraki.com:443 |
| (Version 3.1.6 and later) Recommended: *.meraki.com:443 Customers who want to avoid wildcards can specify these URLs instead:
|
|
| Check SSL/TLS certificate revocation status using OCSP/CRL. |
Version 3.1.5 and earlier:
Version 3.1.6 and later:
|
| Allow Cisco authorized specialists to collect troubleshooting data when Catalyst Center Remote Support functionality is enabled. |
wss://prod.radkit-cloud.cisco.com:443 |
| Integrate with cisco.com and Cisco Smart Licensing. |
*.cisco.com:443 To avoid wildcards, specify these URLs instead:
|
| Connect to the Network-Based Application Recognition (NBAR) cloud. |
prod.sdavc-cloud-api.com:443 |
| Enable the Rogue Management application to detect rogue vendor names. |
|
| Enable the Rogue Management application to detect rogue vendor names. |
Version 3.1.6 and later: https://standards-oui.ieee.org/ |
| Render accurate information in site and location maps. |
|
| For Cisco AI Network Analytics data collection, configure your network or HTTP proxy to allow outbound HTTPS (TCP 443) access to the cloud hosts. |
|
| Access a menu of interactive help flows that let you complete specific tasks from the GUI. |
|
| Access the licensing service. |
|
| Integrate with Cisco Spaces. |