Introduction
Seqrite Endpoint Protection Platform (EPP) requires network access to specific URLs and ports in order to operate correctly across all deployment modes — single server, distributed, and high availability. Before deploying Seqrite EPP, your network team must configure perimeter firewalls, internal firewalls, proxy servers, and web gateways to permit the destinations listed in this document.
File extensions to allow
Required on all firewalls, proxies, and content filters for definition and engine packages to download correctly (EPP Server + All endpoints) – .dat & .bin
Network Allow-List
Blocking any resource listed below may result in broken or degraded functionality, including failure to activate licenses, deliver virus definitions, apply patches, or enforce policies on roaming endpoints.
| Purpose | Source | Destination | Protocol | URL(s) / Address | Port(s) |
|---|---|---|---|---|---|
| External — Internet-Bound Traffic (EPP Server & Clients → Seqrite Cloud) | |||||
| Definition Updates & Upgrades | Server & Client | Seqrite Cloud | TCP |
dlupdate.quickheal.com download.quickheal.com |
443, 8765 |
| Cloud Security Services Reputation, classification & threat intelligence |
Server & Client | Seqrite Cloud | TCP |
prourl.itsecure.co.in encurl.itsecure.co.in klassify.itsecure.co.in prourl.itonlinesecure.in encurl.itonlinesecure.in protecti.quickheal.com |
443 |
| Roaming Management Policy enforcement for off-network endpoints |
Server & Client | Seqrite Cloud | TCP | epsngrp.seqrite.com | 443 |
| Seqrite EPP Server — Internal Component Communication | |||||
| Endpoint & Admin Console → EPP Server Console access, policy push, agent communication |
Endpoints / Admin | EPP Server | TCP | EPP Server IP / FQDN |
443 |
| EPP Service Components Database · Cache · App · Coordination · Event streaming |
EPP Server / Node(s) | EPP Server / Node(s) | TCP | EPP Server IP / FQDN |
443, 8080, 8443, 27017, 6379, 4222, 8222 |
| Seqrite Patch Server — Microsoft Update Services & Endpoint Distribution | |||||
| Windows Update (HTTPS) Metadata sync, content downloads, reporting |
WSUS / Patch Server | Microsoft Update | TCP |
.windowsupdate.microsoft.com .update.microsoft.com *.download.windowsupdate.com wustat.windows.com |
443 |
| Secure Update Services (HTTPS) Delivery optimization, patch downloads, service dependencies |
WSUS / Patch Server | Microsoft Update | TCP |
.windowsupdate.microsoft.com .update.microsoft.com .download.windowsupdate.com .delivery.mp.microsoft.com *.dl.delivery.mp.microsoft.com www.microsoft.com catalog.update.microsoft.com |
443 |
| Patch Distribution to Endpoints Patch server → managed endpoint delivery |
Patch Server | Endpoints | TCP | Seqrite Patch Server IP / FQDN |
6201, 3698 |
| Activation | |||||
| Seqrite EPP Activation | EPP Server | Endpoints | TCP | https://license4.quickheal.com | 443 |
| License | EPP Server | Endpoints | TCP | https://license12.quickheal.com/WebAPI/FileVault/sendOTP.php | 443 |
| Forums and Websites | |||||
| Default Website | EPP Server | Seqrite Cloud | TCP | https://www.seqrite.com | 443 |
| Forums | EPP Server | Seqrite Cloud | TCP | https://forums.seqrite.com/ | 443 |
NOTE:
- Single Server: All component communication remains internal to the same server host; no additional firewall rules needed between nodes.
- Distributed: Ports must be open between designated server role nodes per the deployment topology.
- High Availability (HA): All listed ports must be permitted bidirectionally between every participating node to support replication, synchronization, and failover.