Some EvTrack features make EvTrack Cloud connect to systems on your own network - an access control server, a webhook endpoint, your mail server or a device on site. Your firewall sees those connections arrive from a small set of fixed public IP addresses. Add them to your firewall’s allowlist so the connections get through.

Allow these addresses

Allow all of the addresses below. EvTrack Cloud runs in several regions, and allowing every address means your integrations keep working if your system is ever moved to a different region.

IP address Cloud provider Region
35.177.220.68 Amazon Web Services Europe (London)
63.176.153.77 Amazon Web Services Europe (Frankfurt)
13.246.112.3 Amazon Web Services Africa (Cape Town)
129.151.154.228 Oracle Cloud Middle East (Abu Dhabi)

This page lists the current addresses.

What connects from these addresses

Allow the addresses on the systems and ports that EvTrack Cloud needs to reach:

  • Access control integrations - Gallagher Command Centre (REST API, usually port 8904), Genetec Security Center (Web SDK, default port 4590), HikVision HikCentral (OpenAPI, port 443), Suprema BioStar 2 (HTTPS API) and Cisco ISE (ERS API, usually port 9060)
  • Webhooks - HTTPS requests to the URL you configure
  • Email through your own mail server - when EvTrack sends email through your SMTP server (port 25, 587 or 465)
  • Devices on your site that EvTrack calls directly - for example Hikvision, Dahua, Akuvox, 2N and Axis devices and ANPR cameras, over HTTP or HTTPS (usually port 80 or 443)

What does not need an allowlist entry

These connections are opened from your side towards EvTrack Cloud, so your firewall only needs to allow outbound traffic for them:

  • EvTrack Connect agents
  • the Kiosk and Guard apps, and FrontDesk devices
  • devices that push their events to EvTrack

If you would rather not open any inbound access to your network, use EvTrack Connect: the agent runs on your network and connects out to EvTrack Cloud, so no allowlist entry is needed.

Notes

  • These addresses are for traffic from EvTrack Cloud to your network only. They are not the address of the EvTrack web portal and are not needed to reach EvTrack.
  • Allow the IP addresses themselves. Do not rely on reverse DNS names for these addresses.
  • An integration’s Test Connection fails with a timeout - check your firewall log for blocked connections from the addresses above, and confirm the port is open.

Back to top

Copyright EvTrack. All rights reserved.

Page last modified: 2026-10-05 18:32.