To ensure smooth operation of Enterprise Workloads, it is crucial to configure appropriate exclusions within your environment. Antivirus software, third-party encryption programs, and network firewalls can sometimes interfere with application functionality by locking files, folders, or blocking network traffic. Antivirus programs, especially during real-time scanning, often lock files. If these programs lock files or folders used by the Enterprise Workloads agent, such as configuration or log files, it can interrupt backups and restores.
We strongly recommend configuring exclusions for the Enterprise Workloads agent, Druva storage cluster URLs, AWS S3 storage region URLs, and relevant configuration paths.
Quickest step - wildcard rule
If your firewall supports wildcard rules, allow *.druva.com. You will still need to separately allow the AWS S3 and Azure Storage URLs listed later in this document because they do not use the druva.com domain.
This article covers all the required configurations across four areas:
Step 1: Allow URLs in firewall rules
Step 2: Antivirus and encryption software exclusions
Step 3: Application process exclusions
Step 4: Ports and communication protocols
Before You Begin
Your deployment region, agent version, and Azure usage determine which URL sections apply to your environment.
Determine your deployment region
Your deployment region determines which URLs you need to whitelist. To find your region:
Log in to the Druva Cloud Platform console.
Check the URL in your browser:
If your console URL starts with… | Your deployment region is… |
| US |
| APAC |
| Australia (AU) |
Build your URL whitelist
Use the guided questions first, then use the checklist to confirm you have all required sections.
Answer the questions in order. Each answer adds URL sections to your final whitelist.
Question 1 — What is your deployment region?
My region is… | Start with… |
US | Core Druva URLs (US) |
APAC | Core Druva URLs (APAC) |
AU | Core Druva URLs (AU) |
Always add: Storage Cluster URLs for your region. These are required for all customers.
Question 2 — What is your agent version?
My agent version is… | Also add… |
7.0.0 or later | AWS S3 URLs for your region |
Earlier than 7.0.0 | No additional section from this step |
To check your agent version, go to Administration > Endpoints in the Druva console.
Question 3 — Do you use Azure workloads?
I use… | Also add… |
Azure workloads (general) | Azure Storage URLs |
Azure SQL via Quantum Bridge | Azure Storage URLs and Transient Blob URLs for your deployment region |
Neither | No additional section from this step |
Example: A US-region customer running agent version 7.2 and using Azure SQL via Quantum Bridge should whitelist: Core Druva URLs (US) → Storage Cluster URLs → AWS S3 URLs → Azure Storage URLs → Transient Blob URLs (US column).
Checklist
STEP 1 — Pick your deployment region
[ ] US → Add: Core Druva URLs (US)
[ ] APAC → Add: Core Druva URLs (APAC)
[ ] AU → Add: Core Druva URLs (AU)
Always add:
[ ] Storage Cluster URLs for your region
STEP 2 — Check your agent version
[ ] Agent 7.0.0 or later → Add: AWS S3 URLs for your region
[ ] Agent earlier than 7.0.0 → No extra URLs from this step
STEP 3 — Check Azure usage
[ ] Azure workloads (general) → Add: Azure Storage URLs
[ ] Azure SQL via Quantum Bridge → Add: Azure Storage URLs + Transient Blob URLs for your deployment region
[ ] No Azure workloads → No extra URLs from this step
Existing customers: If you already allow Druva IP ranges, add the required URLs for your region but do not remove the existing IP-based rules.
Step 1: Allow URLs in firewall rules
Core Druva URLs - US
Core Druva URLs - APAC
Core Druva URLs - AU
Core Druva URLs - AU
Log upload and agent upgrade URLs - US
Log upload and agent upgrade URLs - APAC
Log upload and agent upgrade URLs - AU
US deployment region
Core Druva URLs
Core Druva URLs
Required: You must allow the core URLs for your deployment region.
US deployment region
login.druva.com
globalapis.druva.com
phoenix-globalapis.druva.com
phoenix.druva.com
downloads.druva.com
deviceapigw-phoenix.druva.com
backup-phoenix.druva.com
pub-devicemgmt-devicenotifier-dcp.druva.com
devicemgmt-reverseproxy-dcp.druva.com
dtp-c0-uksouth-phoenix.druva.com
If you use VMware application-aware backups, also allow the required proxy URL pattern from the live article.
APAC deployment region
login.druva.com
globalapis.druva.com
phoenix.druva.com
downloads.druva.com
deviceapigw-ap1-phoenix.druva.com
backup-ap1-phoenix.druva.com
pub-devicemgmt-devicenotifier-ap1-dcp.druva.com
devicemgmt-reverseproxy-ap1-dcp.druva.com
If you use VMware application-aware backups, also allow the required proxy URL pattern from the live article.
AU deployment region
au-login.druva.com
au-globalapis.druva.com
au-phoenix.druva.com
downloads.druva.com
au-deviceapigw-phoenix.druva.com
au-backup-phoenix.druva.com
au-pub-devicemgmt-devicenotifier-dcp.druva.com
au-devicemgmt-reverseproxy-dcp.druva.com
Log upload and agent upgrade URLs
Allow both the primary FQDN and the Alias for each function. Both are required for reliable connectivity.
US region — log upload, download and agent upgrade URLs
# Log upload/download (FQDN and Alias)
https://dprod-devicestore-file.s3.us-east-1.amazonaws.com
https://druva-us0-devicefile-zqztwnudbwnx5u8j1bx4x6qbq8dmhuse1a-s3alias.s3.us-east-1.amazonaws.com
# Agent upgrade (FQDN and Alias)
https://dprod-devicestore-package.s3.us-east-1.amazonaws.com
https://druva-us0-devicepack-mkpuot7uiirhb5wrphs1a9h946aeeuse1b-s3alias.s3.us-east-1.amazonaws.com
APAC region — log upload, download and agent upgrade URLs
# Log download (FQDN and Alias)
https://ap1-dprod-devicestore-file.s3.ap-southeast-1.amazonaws.com
https://druva-ap1-devicefile-gkztbhmogjger59x4d8qps3gomasnaps1a-s3alias.s3.ap-southeast-1.amazonaws.com
# Agent upgrade (FQDN and Alias)
https://ap1-dprod-devicestore-package.s3.ap-southeast-1.amazonaws.com
https://druva-ap1-devicepack-4bkkqwrp4harurgb7hrocaya9cme4aps1b-s3alias.s3.ap-southeast-1.amazonaws.com
AU region — log upload, download and agent upgrade URLs
# Log upload and download (FQDN and Alias)
https://au-audprod-devicestore-file.s3.ap-southeast-2.amazonaws.com
https://druva-au-devicefile-ni1pe37xditiu89brrmep38mkgmz4aps2a-s3alias.s3.ap-southeast-2.amazonaws.com
# Agent upgrade (FQDN and Alias)
https://au-audprod-devicestore-package.s3.ap-southeast-2.amazonaws.com
https://druva-au-devicepacka-8uwp59g6gdffarqnszpjwa5j3bu6caps2b-s3alias.s3.ap-southeast-2.amazonaws.com
Storage Cluster URLs (AWS)
Storage Cluster URLs (AWS)
Conditional: You must allow the Storage Cluster URLs only for the storage regions assigned to your account. If you are unsure which regions apply, check your Druva Cloud Platform console under Administration > Storage.
The URLs below represent Druva's regional storage clusters, each corresponding to a specific storage region and its associated storage service.
US Region — Storage Clusters
Storage Region | Storage Cluster URL | Storage Service URL |
Northern Virginia (us-east-1) |
|
|
Ohio (us-east-2) |
|
|
Northern California (us-west-1) |
|
|
Oregon (us-west-2) |
|
|
Ireland (eu-west-1) |
|
|
London (eu-west-2) |
|
|
Paris (eu-west-3) |
|
|
Stockholm (eu-north-1) |
|
|
Frankfurt (eu-central-1) |
|
|
São Paulo (sa-east-1) |
|
|
Montreal (ca-central-1) |
|
|
Hong Kong (ap-east-1) |
|
|
Tokyo (ap-northeast-1) |
|
|
Mumbai (ap-south-1) |
|
|
Singapore (ap-southeast-1) |
|
|
Sydney (ap-southeast-2) |
|
|
UAE (me-central-1) |
|
|
APAC Region — Storage Clusters
Storage Region | Storage Cluster URL | Storage Service URL |
Singapore (ap-southeast-1) |
|
|
Hong Kong (ap-east-1) |
|
|
Mumbai (ap-south-1) |
|
|
Sydney (ap-southeast-2) |
|
|
Tokyo (ap-northeast-1) |
|
|
UAE (me-central-1) |
|
|
AU Region — Storage Clusters
Storage Region | Storage Cluster URL | Storage Service URL |
Sydney (ap-southeast-2)
|
|
|
For Enterprise Workloads agents version 7.0.0 or later, allow the following AWS S3 storage URLs to access storage during backups and restores. Ensure that you configure firewall rules to allow both FQDN and Alias URLs.
Storage Region | S3 FQDN | S3 Alias |
Northern Virginia (us-east-1) |
|
|
Ohio (us-east-2) |
|
|
Northern California (us-west-1) |
|
|
Oregon (us-west-2) |
|
|
Montreal (ca-central-1) |
|
|
Frankfurt (eu-central-1) |
|
|
Ireland (eu-west-1) |
|
|
London (eu-west-2) |
|
|
Paris (eu-west-3) |
|
|
Stockholm (eu-north-1) |
|
|
São Paulo (sa-east-1) |
|
|
Hong Kong (ap-east-1) |
|
|
Mumbai (ap-south-1) |
|
|
Singapore (ap-southeast-1) |
|
|
Sydney (ap-southeast-2) |
|
|
Tokyo (ap-northeast-1) |
|
|
UAE (me-central-1) |
|
|
|
|
|
Region | Whitelisting URL | Live From |
East US |
| 19 May 2025 |
Australia East |
| 19 May 2025 |
West US 2 |
| 26 May 2025 |
UK South |
| 26 May 2025 |
Germany West Central |
|
|
AWS S3 Storage URLs (Agent v7.0.0 or later only)
AWS S3 Storage URLs (Agent v7.0.0 or later only)
Conditional: Applies only to agents version 7.0.0 or later. Allow both the S3 FQDN and S3 Alias for each assigned storage region.
If your agent version is earlier than 7.0.0, skip this section.
US Region — AWS S3 URLs
For Enterprise Workloads agents version 7.0.0 or later, allow the following AWS S3 storage URLs to access storage during backups and restores. Ensure that you configure firewall rules to allow both FQDN and Alias URLs.
Storage Region | S3 FQDN | S3 Alias |
Northern Virginia (us-east-1) |
|
|
Ohio (us-east-2) |
|
|
Northern California (us-west-1) |
|
|
Oregon (us-west-2) |
|
|
Montreal (ca-central-1) |
|
|
Frankfurt (eu-central-1) |
|
|
Ireland (eu-west-1) |
|
|
London (eu-west-2) |
|
|
Paris (eu-west-3) |
|
|
Stockholm (eu-north-1) |
|
|
São Paulo (sa-east-1) |
|
|
Hong Kong (ap-east-1) |
|
|
Mumbai (ap-south-1) |
|
|
Singapore (ap-southeast-1) |
|
|
Sydney (ap-southeast-2) |
|
|
Tokyo (ap-northeast-1) |
|
|
UAE (me-central-1) |
|
|
Region | Whitelisting URL | Live From |
East US |
| 19 May 2025 |
Australia East |
| 19 May 2025 |
West US 2 |
| 26 May 2025 |
UK South |
| 26 May 2025 |
Germany West Central |
|
|
APAC Region — AWS S3 URLs
The following table is for Enterprise Workloads agents version 7.0.0 or later.
Storage Region | S3 FQDN | S3 Alias |
Hong Kong (ap-east-1) |
|
|
Mumbai (ap-south-1) |
|
|
Singapore (ap-southeast-1) |
|
|
Sydney (ap-southeast-2) |
|
|
Tokyo (ap-northeast-1) |
|
|
UAE (me-central-1) |
|
|
AU Region — AWS S3 URLs
The following table is for Enterprise Workloads agents version 7.0.0 or later.
Storage Region | S3 FQDN | S3 Alias |
Sydney (ap-southeast-2) |
|
|
Transient Blob URLs for Azure SQL
Transient Blob URLs for Azure SQL
Conditional: If you use Azure SQL with Quantum Bridge, allow the Transient Blob URLs.
Transient blob storage facilitates data transfer to and from Druva’s Quantum Bridge and must reside in the same Azure region as the source resource. Since we support both APAC and US deployments with globally distributed resources, we maintain separate infrastructure, including storage accounts tied to their respective regions. So, if you are an APAC customer with resources located in a U.S. region (e.g., East US), you may be directed to use a U.S.-based storage URL to ensure proper data transfer. For this, ensure these URLs are allowed in the Network Security Group during the creation of the Druva Quantum Bridge.
Which column applies to me? Use the column that matches your Druva deployment region (US or APAC), not the Azure resource region.
Resource Region | APAC deployment region URLs | US deployment region URLs |
East US (eastus) |
|
|
Asia Pacific (southeastasia) |
|
|
North America (westus) |
|
|
Europe (uksouth) |
|
|
Europe (francecentral) |
|
|
Asia Pacific (australiacentral) |
|
|
Asia Pacific (australiaeast) |
|
|
Asia Pacific (australiasoutheast) |
|
|
South America (brazilsouth) |
|
|
North America (canadacentral) |
|
|
North America (canadaeast) |
|
|
Asia Pacific (centralindia) |
|
|
North America (centralus) |
|
|
Asia Pacific (eastasia) |
|
|
East US (eastus2) |
|
|
Europe (germanywestcentral) |
|
|
Middle East (israelcentral) |
|
|
Asia Pacific (japaneast) |
|
|
Asia Pacific (koreacentral) |
|
|
Asia Pacific (koreasouth) |
|
|
Central America (mexicocentral) |
|
|
North America (northcentralus) |
|
|
Europe (northeurope) |
|
|
Europe (norwayeast) |
|
|
Europe (polandcentral) |
| h |
Africa (southafricanorth) |
|
|
Africa (southafricawest) |
|
|
North America (southcentralus) |
|
|
Asia Pacific (southindia) |
|
|
Europe (swedencentral) |
|
|
Europe (switzerlandnorth) |
|
|
Middle East (uaenorth) |
|
|
Europe (ukwest) |
|
|
North America (westcentralus) |
|
|
Europe (westeurope) |
|
|
Asia Pacific (westindia) |
|
|
North America (westus2) | h |
|
North America (westus3) |
|
|
Step 2: Exclusions for antivirus software and third-party encryption
If you use antivirus software, you must add the following paths to your antivirus exclusions. This will ensure smooth backup and restore operations by granting the antivirus software access to the agent binaries.
Windows
Windows
C:\ProgramData\Phoenix
C:\Program Files\Druva\
C:\ProgramData\PhoenixCloudCache
C:\ProgramData\Druva
C:\ProgramData\phoenixupgrade
<Data Volume folder path configured in TurboTier>
* Data Volume folder path that is configured in TurboTier for exclusion
* For more information on Data Volume configuration, see Configure TurboTier page.
Linux
Linux
/root/Druva
/opt/Druva
/var/Druva
Additional exclusion for Azure VM SQL Server discovery
Additional exclusion for Azure VM SQL Server discovery
C:\Packages\Plugins\Microsoft.CPlat.Core.RunCommandWindows
Step 3: Exclusions for application processes
Storage Cluster URLs
Allow the Storage Cluster URLs for the storage regions assigned to your account.
Deployment region | What to allow |
US | Assigned Storage Cluster URL and Storage Service URL for each active storage region |
APAC | Assigned Storage Cluster URL and Storage Service URL for each active storage region |
AU | Sydney Storage Cluster URL and Storage Service URL |
Populate these values from the live article or from your assigned storage-region mapping.
AWS S3 URLs
Applies only to agents version 7.0.0 or later. Allow both the S3 FQDN and S3 Alias for each assigned storage region.
Deployment region | What to allow |
US | S3 FQDN and S3 Alias for each assigned storage region |
APAC | S3 FQDN and S3 Alias for each assigned storage region |
AU | S3 FQDN and S3 Alias for Sydney |
Azure Storage URLs
If you protect Azure workloads, allow the Azure Storage URLs for the applicable Azure regions in your environment.
Transient Blob URLs for Azure SQL
If you use Azure SQL with Quantum Bridge, allow the Transient Blob URLs. Use the column that matches your Druva deployment region, not the Azure resource region.
Tip: Present the detailed region-specific URL tables in collapsible sections under each category so readers first understand what they need, then expand only the exact URL list they require.
Validate connectivity
After updating firewall rules, verify reachability to the required endpoints.
curl -I https://login.druva.com curl -I https://globalapis.druva.com nslookup <your-storage-cluster-url> nslookup <your-s3-fqdn>
Step 2
What do I need to whitelist?
Use this matrix to identify which URL sections apply to your setup before diving into the full lists.
STEP 1 — Your deployment region (pick one)
☐ US → Add: Core Druva URLs (US)
☐ APAC → Add: Core Druva URLs (APAC)
☐ AU → Add: Core Druva URLs (AU)
✅ Always add: Storage Cluster URLs for your region
──────────────────────────────────────────────────
STEP 2 — Your agent version (pick one)
☐ Agent ≥ 7.0.0 → Add: AWS S3 URLs for your region
☐ Agent < 7.0.0 → Nothing extra
──────────────────────────────────────────────────
STEP 3 — Your Azure usage (pick all that apply)
☐ Azure workloads (general) → Add: Azure Storage URLs
☐ Azure SQL via Quantum Bridge → Add: Azure Storage URLs
+ Transient Blob URLs
(use your deployment region column)
☐ No Azure workloads → Nothing extra
Your Setup | Sections to Whitelist |
US region · AWS storage · Agent < 7.0.0 | Core Druva URLs (US) + Storage Cluster URLs |
US region · AWS storage · Agent ≥ 7.0.0 | Core Druva URLs (US) + Storage Cluster URLs + AWS S3 URLs |
US region · Azure workloads | Core Druva URLs (US) + Storage Cluster URLs + Azure Storage URLs |
US region · Azure SQL (Quantum Bridge) | Core Druva URLs (US) + Storage Cluster URLs + Azure Storage URLs + Transient Blob URLs (US column) |
APAC region · AWS storage · Agent < 7.0.0 | Core Druva URLs (APAC) + Storage Cluster URLs |
APAC region · AWS storage · Agent ≥ 7.0.0 | Core Druva URLs (APAC) + Storage Cluster URLs + AWS S3 URLs |
APAC region · Azure SQL (Quantum Bridge) | Core Druva URLs (APAC) + Storage Cluster URLs + Azure Storage URLs + Transient Blob URLs (APAC column) |
AU region · AWS storage | Core Druva URLs (AU) + Storage Cluster URLs (Sydney) |
AU region · Agent ≥ 7.0.0 | Core Druva URLs (AU) + Storage Cluster URLs + AWS S3 URLs (Sydney) |
Answer the three questions below in order. Each "Yes" adds a section to your list. By the end, you will have a complete, personalised set of sections to whitelist — no guesswork required.
Question 1 — What is your deployment region?
US
US
# ── US Deployment Region: Core Druva URLs ──
login.druva.com
globalapis.druva.com
phoenix-globalapis.druva.com
phoenix.druva.com
downloads.druva.com
deviceapigw-phoenix.druva.com
backup-phoenix.druva.com
pub-devicemgmt-devicenotifier-dcp.druva.com
devicemgmt-reverseproxy-dcp.druva.com
dtp-c0-uksouth-phoenix.druva.com
VMware application-aware backups only: Also allow the following regex pattern to avoid restore failures:
vmacproxy-edge-vmacn.*-c0-us-east-1-phoenix\.druva\.com$
If your firewall does not support regex patterns, contact Support for the equivalent IP addresses.
APAC
APAC
# Core Druva Service URLs — APAC Region
login.druva.com
globalapis.druva.com
phoenix.druva.com
downloads.druva.com
deviceapigw-ap1-phoenix.druva.com
backup-ap1-phoenix.druva.com
pub-devicemgmt-devicenotifier-ap1-dcp.druva.com
devicemgmt-reverseproxy-ap1-dcp.druva.com
VMware application-aware backups only: Also allow:
vmacproxy-edge-vmacn.*-c0-ap-south-1-phoenix\.druva\.com$
AU
AU
# Core Druva Service URLs — AU Region
au-login.druva.com
au-globalapis.druva.com
au-phoenix.druva.com
downloads.druva.com
au-deviceapigw-phoenix.druva.com
au-backup-phoenix.druva.com
au-pub-devicemgmt-devicenotifier-dcp.druva.com
au-devicemgmt-reverseproxy-dcp.druva.com
❗ Important
For existing customers:
If you have already excluded the IP ranges provided by Druva, add all the respective URLs for your region, and do not remove the IP address from your firewall rules.For new customers:
You must exclude all the URLs for your region.
You must exclude
*.druva.comURL in your firewall rules or Contact Support to get the list of IP ranges.If you choose to exclude
*.druva.comURL in your firewall rules, then by default all of the below listed URLs ending withdruva.comdomain are excluded.
Step 1: Allow URLs in the firewall rules
Depending on your deployment regions, US region or APAC region, you must allow the Druva storage cluster URLs and AWS S3 storage region URLs in the network firewall rules.
Determine your deployment region
Click here to determine your deployment region
Click here to determine your deployment region
To determine your deployment region, perform the following steps:
Log in to the Druva Cloud Platform console.
After logging in, check your URL:
If the URL starts with console.druva.com, your account is deployed in the US deployment region.
If the URL starts with ap1-console.druva.com, your account is deployed in the APAC deployment region.
If the URL starts with au-console.druva.com, your account is deployed in the Australia deployment region.
URLs for the US deployment region
Click here to view the URLs
Click here to view the URLs
Allow the following Druva URLs in your network firewall rules:
login.druva.com
globalapis.druva.com
phoenix-globalapis.druva.com
phoenix.druva.com
downloads.druva.com
deviceapigw-phoenix.druva.com
backup-phoenix.druva.com
pub-devicemgmt-devicenotifier-dcp.druva.com
devicemgmt-reverseproxy-dcp.druva.com
dtp-c0-uksouth-phoenix.druva.com
vmacproxy-edge-vmacn.*-c0-us-east-1-phoenix\.druva\.com$
Configure this pattern to avoid any restore failure for application-aware backups. If you are not able to exclude this URL, then contact Support for the IP addresses.
To download agent logs and upgrade Enterprise Workloads agents, you must configure the firewall rules to allow both the FQDN and Alias URLs.
Purpose | FQDN | Alias |
Log upload / download |
|
|
Agent upgrade |
|
|
The URLs below represent Druva's regional storage clusters, each corresponding to a specific storage region and its associated storage service.
Storage Region | Storage Cluster URL | Storage Service URL |
Northern Virginia (us-east-1) |
|
|
Ohio (us-east-2) |
|
|
Northern California (us-west-1) |
|
|
Oregon (us-west-2) |
|
|
Ireland (eu-west-1) |
|
|
London (eu-west-2) |
|
|
Paris (eu-west-3) |
|
|
Stockholm (eu-north-1) |
|
|
Frankfurt (eu-central-1) |
|
|
São Paulo (sa-east-1) |
|
|
Montreal (ca-central-1) |
|
|
Hong Kong (ap-east-1) |
|
|
Tokyo (ap-northeast-1) |
|
|
Mumbai (ap-south-1) |
|
|
Singapore (ap-southeast-1) |
|
|
Sydney (ap-southeast-2) |
|
|
UAE (me-central-1) |
|
|
For Enterprise Workloads agents version 7.0.0 or later, allow the following AWS S3 storage URLs to access storage during backups and restores. Ensure that you configure firewall rules to allow both FQDN and Alias URLs.
Storage Region | S3 FQDN | S3 Alias |
Northern Virginia (us-east-1) |
|
|
Ohio (us-east-2) |
|
|
Northern California (us-west-1) |
|
|
Oregon (us-west-2) |
|
|
Montreal (ca-central-1) |
|
|
Frankfurt (eu-central-1) |
|
|
Ireland (eu-west-1) |
|
|
London (eu-west-2) |
|
|
Paris (eu-west-3) |
|
|
Stockholm (eu-north-1) |
|
|
São Paulo (sa-east-1) |
|
|
Hong Kong (ap-east-1) |
|
|
Mumbai (ap-south-1) |
|
|
Singapore (ap-southeast-1) |
|
|
Sydney (ap-southeast-2) |
|
|
Tokyo (ap-northeast-1) |
|
|
UAE (me-central-1) |
|
|
|
|
|
Region | Whitelisting URL | Live From |
East US |
| 19 May 2025 |
Australia East |
| 19 May 2025 |
West US 2 |
| 26 May 2025 |
UK South |
| 26 May 2025 |
Germany West Central |
|
|
URLs for the APAC deployment region
Click here to view the URLs
Click here to view the URLs
Allow the following Druva URLs in your network firewall rules:
login.druva.com
globalapis.druva.com
phoenix.druva.com
downloads.druva.com
deviceapigw-ap1-phoenix.druva.com
backup-ap1-phoenix.druva.com
pub-devicemgmt-devicenotifier-ap1-dcp.druva.com
devicemgmt-reverseproxy-ap1-dcp.druva.com
vmacproxy-edge-vmacn.*-c0-ap-south-1-phoenix\.druva\.com$
Configure this pattern to avoid any restore failure for application-aware backups. If you are not able to exclude this URL, then contact Support for the IP addresses.
To download agent logs and upgrade Enterprise Workloads agents, you must configure the firewall rules to allow both the FQDN and Alias URLs.
Purpose | FQDN | Alias |
Log download |
|
|
Agent upgrade |
|
|
The URLs below represent Druva's regional storage clusters, each corresponding to a specific storage region and its associated storage service.
Storage Region | Storage Cluster URL | Storage Service URL |
Singapore (ap-southeast-1) |
|
|
Hong Kong (ap-east-1) |
|
|
Mumbai (ap-south-1) |
|
|
Sydney (ap-southeast-2) |
|
|
Tokyo (ap-northeast-1) |
|
|
UAE (me-central-1) |
|
|
For Enterprise Workloads agents version 7.0.0 or later, allow the following AWS S3 storage URLs to access storage during backups and restores. Ensure that you configure firewall rules to allow both FQDN and Alias URLs.
Storage Region | S3 FQDN | S3 Alias |
Hong Kong (ap-east-1) |
|
|
Mumbai (ap-south-1) |
|
|
Singapore (ap-southeast-1) |
|
|
Sydney (ap-southeast-2) |
|
|
Tokyo (ap-northeast-1) |
|
|
UAE (me-central-1) |
|
|
URLs for AU deployment region
Click here to view the URLs
Click here to view the URLs
Allow the following Druva URLs in your network firewall rules:
au-login.druva.com
au-globalapis.druva.com
au-phoenix.druva.com
downloads.druva.com
au-deviceapigw-phoenix.druva.com
au-backup-phoenix.druva.com
au-pub-devicemgmt-devicenotifier-dcp.druva.com
au-devicemgmt-reverseproxy-dcp.druva.com
To download agent logs and upgrade Enterprise Workloads agents, you must configure the firewall rules to allow both the FQDN and Alias URLs.
Purpose | FQDN | Alias |
Log upload / download |
|
|
Agent upgrade |
|
|
To download agent logs and upgrade Enterprise Workloads agents, you must configure the firewall rules to allow both the FQDN and Alias URLs.
Purpose | FQDN | Alias |
Log upload / download |
|
|
Agent upgrade |
|
|
The URLs below represent Druva's regional storage clusters, each corresponding to a specific storage region and its associated storage service.
Storage Region | Storage Cluster URL | Storage Service URL |
Sydney
(ap-southeast-2)
|
|
|
For Enterprise Workloads agents version 7.0.0 or later, allow the following AWS S3 storage URLs to access storage during backups and restores. Ensure that you configure firewall rules to allow both FQDN and Alias URLs.
Storage Region | S3 FQDN | S3 Alias |
Sydney (ap-southeast-2) |
|
|
URLs for Azure Storage for Enterprise Workloads
Click here to view the URLs
Click here to view the URLs
Resource Region | Whitelisting URL |
East US |
|
Australia East |
|
West US 2 |
|
UK South |
|
Germany West Central |
|
Central India |
|
Transient Blob URLs for Azure SQL
Click here to view the URLs
Click here to view the URLs
Transient blob storage facilitates data transfer to and from Druva’s Quantum Bridge and must reside in the same Azure region as the source resource. Since we support both APAC and US deployments with globally distributed resources, we maintain separate infrastructure, including storage accounts tied to their respective regions. So, if you are an APAC customer with resources located in a U.S. region (e.g., East US), you may be directed to use a U.S.-based storage URL to ensure proper data transfer. For this, ensure these URLs are allowed in the Network Security Group during the creation of the Druva Quantum Bridge.
Resource Region | APAC deployment region URLs | US deployment region URLs |
East US (eastus) |
|
|
Asia Pacific (southeastasia) |
|
|
North America (westus) |
|
|
Europe (uksouth) |
|
|
Europe (francecentral) |
|
|
Asia Pacific (australiacentral) |
|
|
Asia Pacific (australiaeast) |
|
|
Asia Pacific (australiasoutheast) |
|
|
South America (brazilsouth) |
|
|
North America (canadacentral) |
|
|
North America (canadaeast) |
|
|
Asia Pacific (centralindia) |
|
|
North America (centralus) |
|
|
Asia Pacific (eastasia) |
|
|
East US (eastus2) |
|
|
Europe (germanywestcentral) |
|
|
Middle East (israelcentral) |
|
|
Asia Pacific (japaneast) |
|
|
Asia Pacific (koreacentral) |
|
|
Asia Pacific (koreasouth) |
|
|
Central America (mexicocentral) |
|
|
North America (northcentralus) |
|
|
Europe (northeurope) |
|
|
Europe (norwayeast) |
|
|
Europe (polandcentral) |
| h |
Africa (southafricanorth) |
|
|
Africa (southafricawest) |
|
|
North America (southcentralus) |
|
|
Asia Pacific (southindia) |
|
|
Europe (swedencentral) |
|
|
Europe (switzerlandnorth) |
|
|
Middle East (uaenorth) |
|
|
Europe (ukwest) |
|
|
North America (westcentralus) |
|
|
Europe (westeurope) |
|
|
Asia Pacific (westindia) |
|
|
North America (westus2) | h |
|
North America (westus3) |
|
|
Step 2. Exclusions for antivirus software and third-party encryption programs
If you use antivirus software, you must add the following paths to your antivirus exclusions. This will ensure smooth backup and restore operations by granting the antivirus software access to the agent binaries.
Click here to view the folders under the Antivirus exclusion section
Click here to view the folders under the Antivirus exclusion section
C:\ProgramData\Phoenix
C:\Program Files\Druva\
C:\ProgramData\PhoenixCloudCache
C:\ProgramData\Druva
C:\ProgramData\phoenixupgrade
Data Volume folder path that is configured in TurboTier for exclusion. For more information on Data Volume configuration, see Configure TurboTier page.
root/Druva
/opt/Druva
/var/Druva
To discover and back up SQL Server on Azure VM, make sure you exclude the following folder under the AntiVirus exclusion section:
C:\Packages\Plugins\Microsoft.CPlat.Core.RunCommandWindows
Step 3. Exclusions for the application processes of workloads
Click the following lists to view application processes for each workload.
Common application processes
Click here to view the processes
Click here to view the processes
Phoenix.exe
PhoenixCPHwnet64.exe (64-bit machines)
PhoenixCPHwnet.exe (32-bit machines)
PhoenixActivate.exe
HybridWorkloadsAgent.exe
HybridWorkloadsAgentApp.exe
HybridWorkloadsCheck.exe
PhoenixOtelPipeline.exe
CheckEngine
EnterpriseWorkloads
EnterpriseWorkloadsAgent
EnterpriseWorkloadsMigrator
EnterpriseWorkloadsUpgrader
EnterpriseWorkloads-*-amd64.deb
Guestossvc.exe
EnterpriseWorkloads-*.msi
EnterpriseWorkloads.exe
EnterpriseWorkloadsAgent.exe
EnterpriseWorkloadsMigrator.exe
EnterpriseWorkloadsUpgrader.exe
CheckEngine.exe
VMware
Click here to view the processes
Click here to view the processes
PhoenixIRAgent
HybridWorkloadUDA
PhoenixVMWareAgent
vmware
VMwareAgentPartner
VMwareFLRCleanupAll
VMwareFLRFuse
ProxyConf
VMwareGetVfatAttr
proxySetup
vsphere-discovery
dr-vmware
init.Druva-EnterpriseWorkloads
proxyFirstBoot
FLRDRSTCommandExecutor
PhoenixDRFailbackAgent
PhoenixFailbackRestServer
PhoenixFbcCli
PhoenixFbcSmbAgent
PhoenixVMWareAgent
cFuse
flrFuse
vmFuse
Druva-EnterpriseWorkloads.conf
Druva-EnterpriseWorkloads.service
Druva-HybridWorkloads.conf
Druva-HybidWorkloads.service
drst
Guestossvc
The following binaries reside on the proxy and run on the guest operating system:
HybridWorkloadScan.exe
HybridWorkloadScanx64
HybridWorkloadScanx86
HybridWorkloadUDA.exe
vguestossvc
guestossvc.exe
bring_disks_online.ps1
PhoenixSQLGuestPlugin.exe
PhoenixFbcWinGuestOSAgent.exe
PhoenixPreflight
Proxmox
Click here to view the processes
Click here to view the processes
proxmox
ProxmoxAgentProcess
File Server
Click here to view the processes
Click here to view the processes
PhoenixFSAgent.exe
fs.exe
scanner-cli.exe
PhoenixFSDtBackupAgent.exe
PhoenixFSDtRestoreAgent.exe
PhoenixFSBackupAgent.exe
PhoenixFSRestoreAgent.exe
PhoenixFSSnapshot.exe
NAS
Click here to view the processes
Click here to view the processes
PhoenixNASAgent.exe
nas.exe
PhoenixNASBackupAgent.exe
PhoenixNASDtBackupAgent.exe
PhoenixNASRestoreAgent.exe
PhoenixNASDtRestoreAgent.exe
PhoenixNASDiscoveryAgent.exe
PhoenixNASControl.exe
PhoenixNasDicovery.exe
scanner-cli.exe
PhoenixS3BackupAgent
PhoenixS3RestoreAgent
PhoenixS3DiscoveryAgent
PhoenixAzBlobDtBackupAgent
PhoenixAzBlobDtRestoreAgent
PhoenixAzureBlobDiscoveryAgent
MS SQL Server
Click here to view the processes
Click here to view the processes
mssql.exe
sqldiscovery.exe
PhoenixSQLAgent.exe
PhoenixSQLGuestPlugin.exe
PhoenixSQLDownloader.exe
PhoenixSQLUploader.exe
sql-ioserver.exe
sql-client.exe
drst-ioserver.exe
sql-client.exe
Oracle DTC
Click here to view the processes
Click here to view the processes
oracle
ioserver
vfsserver
Oracle PBS
Click here to view the processes
Click here to view the processes
dtagent
oracle-pbs
TurboTier (formerly CloudCache)
Click here to view the processes
Click here to view the processes
PhoenixCacheWorker.exe
Phoenix CacheServerSVC.exe
PhoenixCacheControl.exe
PhoenixCacheServer.exe
Cloudcache
PhoenixIRService
PhoenixIRFS
vmac
EWLMountprocess
EWLFuse
turbotier.exe
turbotier
Hyper-V
Click here to view the processes
Click here to view the processes
hyperv.exe
PhoenixHyperVAgent.exe
PhoenixHyperVControl.exe
Step 4. Ports and communication protocols
Druva uses ports and communication protocols to ensure secure connections and communication during backup and restore operations.
📝 Note
Communication happens from a backup proxy to other parties on various ports. Here, the backup proxy is the communication initiator, which is unidirectional. These ports are used for outgoing (unidirectional) communication, not incoming communication. However, data in the form of a response can flow in the opposite direction. Standard system ports such as 22 (SSH) and 2049 (NFS-SERVER) are used for incoming requests.
VMware
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | HTTPS+SSL | Druva uses Port 443 to establish a secure connection and communication between the following:
📝 Note |
902 | TCP/UDP | Druva uses port 902 to establish a connection between the backup proxy and ESXi host registered with Druva through vCenter Server. By default, VMware uses the port 902 for the |
3542 | HTTPS+SSL | For application-aware backups, the backup proxy uses VMware Tools to inject two executables and a few supporting files such as certificates into the guest OS of the virtual machine. When the executables run, they start guest OS processes called |
3545 | HTTPS+SSL | For application-aware backups, the SQL executable service |
3389/22 | TCP/UDP | During the backup cycle, the backup proxy sends network packets to Windows virtual machines (where VMware tools are installed) on port 3389 to identify if the RDP port is open or not. For Linux virtual machines, the port is 22, which is used for SSH. This is used for Disaster Recovery or DR restores. |
123 | UDP | Backup proxy accesses NTP server on Port 123 (UDP) for time synchronization. |
443 | HTTPS+TLS | Druva uses TLS 1.2 or a secure connection that happens between the following:
|
VMware ESX
Source | Type | Protocol | Port range | Target | Description |
VMware Proxy | Custom | TCP | 902 | VMware ESX | Use port 902 to establish a connection between the Backup proxy and ESXi host registered with Druva through vCenter Server. |
VMware Proxy
Source | Type | Protocol | Port range | Target | Description |
Failback VM | HTTPS | HTTP | 443 | VMware Proxy | Failback VM connects to the VMware Proxy over HTTPS 443 port for sending Failback progress updates. |
Disaster Recovery
Click to view the ports and protocols
Click to view the ports and protocols
AWS Proxy (Inbound rules)
Source | Type | Protocol | Port range | Target | Description |
My IP | SSH | TCP | 22 | AWS Proxy | This is an optional inbound rule. |
AWS Proxy ( Outbound rules)
Source | Type | Protocol | Port range | Target | Description |
AWS Proxy | HTTPS | TCP | 443 | 0.0.0.0/0 | Use to communicate with Druva Cloud and AWS Services |
Failover EC2 Instance
Linux Failover EC2 Instance (Inbound rules)
Source | Type | Protocol | Port range | Target | Description |
My IP (Post DR Failover Job) | SSH | TCP | 22 | Failover EC2 Instance | This is an optional inbound rule. You can use this rule to log into the Failover EC2 Instance via SSH client such as Putty. |
Destination VMware Network (Post DR Failback Job) | SSH | TCP | 22 | Destination VMware Failback VM | You need this inbound rule for DR Failback. Use this rule to transfer data during DR Failback from Failover EC2 Instance to VMware Failback VM. |
Linux Failover EC2 Instance (Outbound rules)
Source | Type | Protocol | Port range | Target | Description |
Failover EC2 Instance | All Traffic | ALL | ALL | Anywhere IPv4 (0.0.0.0) | Use this outbound rule for DR Failback. |
Source | Type | Protocol | Port range | Target | Description |
Failover EC2 Instance | SSH | TCP | 22 | Destination VMware Failback VM | You need this outbound rule for DR Failback. Use this rule to transfer data during DR Failback from Failover EC2 Instance to VMware Failback VM. |
Failover EC2 Instance | DNS | TCP | 53 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | DNS | UDP | 53 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | LDAP | TCP | 389 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | LDAPS | TCP | 636 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | LDAP | UDP | 389 | Domain Controller Network | Use this outbound rule to log to the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job |
Failover EC2 Instance | custom TCP | TCP | 88 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | custom UDP | UDP | 88 | Domain Controller Network | Use this outbound rule to log to the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Windows Failover EC2 Instance (Inbound rules)
Source | Type | Protocol | Port range | Target | Description |
Destination VMware Network | SMB | TCP | 445 | Failover EC2 Instance | Use this inbound rule for DR Failback. This connection is used to communicate with the Failover EC2 Instance Admin Share. |
Destination VMware Network | Custom TCP | TCP | 50000 | Failover EC2 Instance | Use this inbound for DR Failback. |
My IP (Post DR Failover Job) | RDP | TCP | 3389 | Failover EC2 Instance | This is an optional inbound rule for DR Failover. This rule is not required for DR Failback. |
Windows Failover EC2 Instance (Outbound rules)
Source | Type | Protocol | Port range | Target | Description |
Failover EC2 Instance | All Traffic | ALL | ALL | Anywhere IPv4 (0.0.0.0) | Use this outbound rule for DR Failback. |
Source | Type | Protocol | Port range | Target | Description |
Failover EC2 Instance | DNS | TCP | 53 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | DNS | UDP | 53 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | LDAP | TCP | 389 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | LDAP | UDP | 389 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | Kerberos | TCP | 88 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | Kerberos | UDP | 88 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | SMB | TCP | 445 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
AWS SQS Endpoint
Source | Type | Protocol | Port range | Target | Description |
Private Subnet of the VPC | HTTPS | HTTPS | 443 | SQS Interface Endpoint | Make sure the Interface Endpoint allows 443 inbound rule. For more information, see Amazon ECS interface VPC endpoints (AWS PrivateLink). |
Hyper-V
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup agent and Druva Cloud. |
Nutanix AHV
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
9440 | HTTPS+SSL | Druva uses Port 9440 to establish a secure connection and communication between the Backup Proxy and Prism. |
3261/3260 | TCP (iSCSI) | Port 3260 and 3261 uses the iSCSI protocol over TCP and is responsible for block-level storage communication between the proxy and the Nutanix cluster. |
443 | TLS | Backup Proxy to Druva Cloud. |
443 | TLS | Backup Proxy to S3 bucket. |
Proxmox
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | HTTPS+SSL | Druva uses Port 443 to establish a secure connection and communication between Backup Proxy and Druva Cloud |
File Server
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup agent and Druva Cloud. |
NAS
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup proxy and Druva Cloud. |
MS SQL Server
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup agent and Druva Cloud. |
Oracle PBS
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between PBS and Druva Cloud. |
Oracle DTC
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup agent and Druva Cloud. |
SAP HANA
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup agent and Druva Cloud. |
20000 to 20100 |
| Used for internal communication within the cluster |
21000 |
| Used for internal communication within the cluster |
TurboTier
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup agent, TurboTier agent, and Druva Cloud. |
2049 | TCP/UDP | This is the main Network File System (NFS) port used for core operations. All file access, directory browsing, and data transfer (reading and writing) between a client and server run directly over this port. For modern NFSv4, this is often the only port required. |
111 | TCP/UDP | This port is used by the rpcbind (or portmapper) service. In older NFS versions (v2/v3), it communicates the correct (and often dynamic) port numbers to the clients for other services, such as the one responsible for mounting. |
📝 Note
Port 8082 is used for internal communications on the host for FS, NAS, Hyper-V, VMware, Oracle DTC, and MS SQL. If port 8082 is unavailable, other available ephemeral ports will be used.
Related keywords
Antivirus configuration, firewall settings, enterprise workloads, URL whitelisting, network ports, security processes, antivirus compatibility, firewall rules, network interference, agent optimization, threat protection, network security, port management, process monitoring, security exceptions, firewall configuration, antivirus troubleshooting, enterprise agent configuration, security best practices, system performance, network traffic, port forwarding, intrusion prevention, application whitelisting, process exclusions, security software, network protocols, secure connections, antivirus exclusion list, firewall policies, scannercli, scancli, scanner cli
certificate validation issue, VM Proxy not registering, re-activation, reactivation, certificate not trusted, Network verification, whitelisted, white listed, Druva applications, Druva and S3 URLs



