Firewall rules required for Hexnode UEM endpoint device communicationSolved

Participant
Discussion
1 day ago Sep 05, 2026

I’m setting up firewall rules for devices managed with Hexnode UEM. I only need the rules for the endpoint devices that have Hexnode installed, not access to the management portal.

Which ports and destination domains should be allowed so devices can register, receive policies, run commands, and get payloads correctly?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
1 day ago Sep 05, 2026
Marked SolutionPending Review

For Hexnode UEM endpoint device communication, allow outbound traffic from the managed devices to Hexnode server domains.

Required endpoint communication rules:

  • TCP 443: HTTPS over TLS 1.2 or later
  • TCP 8883: MQTT over TLS
  • Destination: *.hexnodemdm.com

These connections are used for device registration, policy evaluation, telemetry, remote command execution, and file or payload distribution.

The above rules are for device-to-Hexnode server communication only. They do not include rules for accessing the Hexnode management portal from an administrator browser.

Regards,
Isabel Lora
Hexnode UEM

Save