IP addresses and ports used by CrashPlan

Overview

This article lists all of the ports and IP addresses used by CrashPlan.

Firewall access

Two firewall filtering methods are described below: FQDN-based and IP-based. The FQDN-based method is simpler to manage for most customers. The IP-based method should be used with firewalls that do not support FQDN-based filtering.

Change the firewall access based on which cloud instance you use:

FQDN-based filtering method

For the cloud instance you use, open access in your firewall to allow outbound TCP/443 to *.crashplan.com. This ensures uninterrupted access to the CrashPlan cloud. (You must use the IP-based filtering method to allow traffic on port 4287.)

IP-based filtering method

For the cloud instance you use, allow outbound TCP/443 and TCP/4287 to CrashPlan IP addresses below.

This ensures uninterrupted access to the CrashPlan cloud when your firewall does not support FQDN-based filtering or TLS inspection is being performed. 

CrashPlan IP addresses

  • 50.93.246.0/23
  • 50.93.255.0/24
  • 64.207.196.0/22
  • 64.207.204.0/23
  • 64.207.222.0/23
  • 67.222.248.0/21
  • 68.65.192.0/21
  • 103.8.239.0/24
  • 149.5.7.0/24
  • 162.222.40.0/21
  • 216.9.196.0/22
  • 216.17.8.0/24
  • 216.223.38.0/24

CrashPlan app ports

List of ports that require outbound traffic to CrashPlan. You must have ports 443, 4285, and 4287 open for use by CrashPlan apps.

Port

Protocol

Source

Destination

Description

443 HTTPS CrashPlan endpoint agents CrashPlan cloud Communication for deployment policy information
HTTPS Web Browsers CrashPlan cloud Web restore (both zip file and device)
TLS CrashPlan endpoint agents CrashPlan cloud

Communication from device to the CrashPlan cloud.

Only applies to CrashPlan environments that sign in to the CrashPlan console at: https://console.us2.crashplan.com.

4285 HTTPS Web Browsers CrashPlan cloud Web restore (both zip file and device), SSO sign in, and authentication API calls.
4287 TLS CrashPlan endpoint agents CrashPlan cloud Communication from the device to the CrashPlan cloud

 

Additional services integrated with CrashPlan

These are some additional ports used by services that are commonly integrated with CrashPlan environments.

Port

Protocol

Source

Destination

Description

8200 and 8201

TLS CrashPlan cloud Vault Communication between a Vault instance and the CrashPlan cloud
443 HTTPS CrashPlan cloud AD FS server Sync with AD FS
636 LDAPS

The CrashPlan User Directory Sync tool

Your directory server Used by the CrashPlan User Directory Sync tool to sync with your directory service

 

Revision history

The table below lists previous updates to this page. 

Date Updates
June 29, 2022

Added the following IP address range to the list of Code42 IP addresses: 

  • 216.9.196.0/22

These addresses will not be used until December 1, 2022. Please update any firewall rules to allow access to the full range of published Code42 network addresses by that date.

April 25, 2022 Removed instructions to allow outbound access to AWS and *.code42.com. All URLs to the Code42 cloud for CrashPlan are now *.crashplan.com.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more