Introduction
Seqrite Endpoint Protection Platform (EPP) requires network access to specific URLs and ports in order to operate correctly across all deployment modes — single server, distributed, and high availability. Before deploying Seqrite EPP, your network team must configure perimeter firewalls, internal firewalls, proxy servers, and web gateways to permit the destinations listed in this document.
File extensions to allow
Required on all firewalls, proxies, and content filters for definition and engine packages to download correctly (EPP Server + All endpoints) – .dat & .bin
Network Allow-List
Blocking any resource listed below may result in broken or degraded functionality, including failure to activate licenses, deliver virus definitions, apply patches, or enforce policies on roaming endpoints.
| No. | Purpose | Source | Destination | Protocol | Port | Traffic Direction |
|---|---|---|---|---|---|---|
| 1 | Activation & Licensing | EPP Server | actnexgen.quickheal.com | TCP | 443 | Outbound connection from EPP server |
| 2 | Product package Update | EPP Server | dlupdate.quickheal.com download.quickheal.com | TCP | 443 | Outbound connection from EPP server |
| 3 | Definition Update (Client, UpdateManager, Update Agent) | Endpoint | dlupdate.quickheal.com Download.quickheal.com | TCP | 443 | Outbound connection from Endpoint |
| 4 | Host Integrity | EPP Server | dlfiles.quickheal.com | TCP | 443 | Outbound connection from Endpoint |
| 5 | Web Categorization | EPP Server and Endpoint | prourl.itsecure.co.in encurl.itsecure.co.in klassify.itsecure.co.in Prourl.itonlinesecure.in encurl.itonlinesecure.in | TCP | 443 | Outbound connection from endpoint |
| 6 | Console Access | EPP Server | EPP Server | TCP | 443 | Outbound connection from endpoint |
| 7 | Roaming | EPP Server & Endpoint | epsngrp.seqrite.com | TCP | 443 | Outbound connection from EPP server and endpoint |
| 8 | Client Communication | Endpoint | EPP Server | TCP | 443 | Outbound connection from endpoint |
| 9 | Patch Management | Patch Server / WSUS | windowsupdate.microsoft.com download.windowsupdate.com wustat.windows.com ntservicepack.microsoft.com download.quickheal.com dlupdate.quickheal.com patsrv.itonlinesecure.in go.microsoft.com update.microsoft.com | TCP | 6201, 8963, 443, 80, 3698 | Outbound connection from endpoint |
| 10 | File Sandboxing | EPP Server | cbsapifw.seqrite.com | TCP | 443 | Outbound connection from endpoint |
| 11 | Seqrite Labs | Endpoint | virusmap.quickheal.com license4.quickheal.com | TCP | 443 | Outbound connection from endpoint |
| 12 | Vulnerability Catalog | EPP Server | ovaldbru.altx-soft.ru | TCP | 443 | Outbound connection from endpoint |
| 13 | Seqrite Malware Analysis | EPP Server | Smap.seqrite.com smapv1.seqrite.com | TCP | 443 | Outbound connection from endpoint |
| 14 | Web Categorization Identification | EPP Server | https://www.quickheal.com/miscat_report/miscat.html | TCP | 443 | Outbound connection from endpoint and EPP Server |
| 15 | Remote Shell | EPP server to endpoint | EPP server to endpoint | TCP | 8448 | Bi-directional traffic |
NOTE:
- Single Server: All component communication remains internal to the same server host; no additional firewall rules needed between nodes.
- Distributed: Ports must be open between designated server role nodes per the deployment topology.
- High Availability (HA): All listed ports must be permitted bidirectionally between every participating node to support replication, synchronization, and failover.