To ensure smooth operation of Enterprise Workloads, it is crucial to configure appropriate exclusions within your environment. We strongly recommend configuring exclusions for the Enterprise Workloads agent, Druva storage cluster URLs, and AWS S3 storage region URLs.
This article covers all the required configurations across two areas:
Follow the below sections to identify your environment parameters and copy the required rules for each step.
Before You Begin
Your deployment region, agent version, and Azure usage determine which URL sections apply to your environment.
Determine your deployment region
Your deployment region determines which URLs you need to whitelist. To find your region:
Log in to the Druva Cloud Platform console.
Check the URL in your browser:
| If your console URL contains… | Your deployment region is… |
| :--- | :--- |
| `console.druva.com` | **US** |
| `ap1-console.druva.com` | **APAC** |
| `au-console.druva.com` | **Australia (AU)** |
If your console URL (address bar of the browser) contains… | Your deployment region is… |
| US |
| APAC |
| Australia (AU) |
Quickly check your region URLs
❗ Important
For existing customers
If you have already excluded the IP ranges provided by Druva, add all the respective URLs for your region, and do not remove the IP address from your firewall rules.
For new customers:
You must exclude all the URLs for your region.
You must exclude
*.druva.comURL in your firewall rules or Contact Support to get the list of IP ranges.If you choose to exclude
*.druva.comURL in your firewall rules, then by default all of the below listed URLs ending withdruva.comdomain are excluded.You will still need to separately allow the AWS S3 storage URLs and Azure Storage URLs listed later in this document because they do not use the
druva.comdomain.
Deployment Scenarios and Required URLs
💡 New to Setup?
Refer the following matrix to check your Region (US, APAC, AU), Agent Version (v7.0.0+ vs v6.x) and Storage Setup. Locate your matching row in the matrix to see your required URL sections. If your setup isn't listed, refer to the individual regional sections to copy the URLs.
How to identify storage and agent version?
How to identify storage and agent version?
Navigate to Storage > Provisioned Storages on the Management Console to check the provisioned storage.
For more information on agent version, see Agents and Proxies.
Deployment Region | Agent | Storage | Allow URLs | Ports |
|
|
|
|
|
|
|
(with Azure SQL via Quantum Bridge) |
|
|
US |
6.x |
AWS storage only |
|
|
APAC |
Any |
Azure VMs (Azure Storage Only) |
|
|
Step 1: Allow URLs in Firewall Rules
Important: You must add Common URLs and Storage Cluster URLs for your region. These are required for all customers. Depending on your setup, you may also need AWS S3 / Azure.
US Region Requirements
Common URLs (US)
Common URLs (US)
You must allow the Common URLs for your deployment region.
login.druva.com
globalapis.druva.com
phoenix-globalapis.druva.com
phoenix.druva.com
downloads.druva.com
deviceapigw-phoenix.druva.com
backup-phoenix.druva.com
pub-devicemgmt-devicenotifier-dcp.druva.com
devicemgmt-reverseproxy-dcp.druva.com
dtp-c0-uksouth-phoenix.druva.com
vmacproxy-edge-vmacn.*-c0-us-east-1-phoenix\.druva\.com$
Configure the pattern, vmacproxy-edge-vmacn.*-c0-us-east-1-phoenix\.druva\.com$, to avoid any restore failure for application-aware backups. If you are not able to exclude this URL, then contact Support for the IP addresses.
Agent and Log URLs (US)
Agent and Log URLs (US)
Allow both the primary FQDN and the Alias for each function. Both are required for reliable connectivity.
Purpose | FQDN | Alias |
Log upload / download |
|
|
Agent upgrade |
|
|
Storage Cluster URLs (US)
Storage Cluster URLs (US)
You must allow the Storage Cluster URLs only for the storage regions assigned to your account. If you are unsure which regions apply, navigate to Storage > Provisioned Storages on the Management Console and check it.
The URLs below represent Druva's regional storage clusters, each corresponding to a specific storage region and its associated storage service.
Storage Region | Storage Cluster URL | Storage Service URL |
Northern Virginia (us-east-1) |
|
|
Ohio (us-east-2) |
|
|
Northern California (us-west-1) |
|
|
Oregon (us-west-2) |
|
|
Ireland (eu-west-1) |
|
|
London (eu-west-2) |
|
|
Paris (eu-west-3) |
|
|
Stockholm (eu-north-1) |
|
|
Frankfurt (eu-central-1) |
|
|
São Paulo (sa-east-1) |
|
|
Montreal (ca-central-1) |
|
|
Hong Kong (ap-east-1) |
|
|
Tokyo (ap-northeast-1) |
|
|
Mumbai (ap-south-1) |
|
|
Singapore (ap-southeast-1) |
|
|
Sydney (ap-southeast-2) |
|
|
UAE (me-central-1) |
|
|
AWS S3 URLs (US)
AWS S3 URLs (US)
Applies only to agents version 7.0.0 or later. Allow both the S3 FQDN and S3 Alias for each assigned storage region.
If your agent version is earlier than 7.0.0, skip this section.
For Enterprise Workloads agents version 7.0.0 or later, allow the following AWS S3 storage URLs to access storage during backups and restores. Ensure that you configure firewall rules to allow both FQDN and Alias URLs.
Storage Region | S3 FQDN | S3 Alias |
Northern Virginia (us-east-1) |
|
|
Ohio (us-east-2) |
|
|
Northern California (us-west-1) |
|
|
Oregon (us-west-2) |
|
|
Montreal (ca-central-1) |
|
|
Frankfurt (eu-central-1) |
|
|
Ireland (eu-west-1) |
|
|
London (eu-west-2) |
|
|
Paris (eu-west-3) |
|
|
Stockholm (eu-north-1) |
|
|
São Paulo (sa-east-1) |
|
|
Hong Kong (ap-east-1) |
|
|
Mumbai (ap-south-1) |
|
|
Singapore (ap-southeast-1) |
|
|
Sydney (ap-southeast-2) |
|
|
Tokyo (ap-northeast-1) |
|
|
UAE (me-central-1) |
|
|
Region | Whitelisting URL | Live From |
East US |
| 19 May 2025 |
Australia East |
| 19 May 2025 |
West US 2 |
| 26 May 2025 |
UK South |
| 26 May 2025 |
Germany West Central |
|
|
APAC Region Requirements
Common URLs (APAC)
Common URLs (APAC)
You must allow the Common URLs for your deployment region.
login.druva.com
globalapis.druva.com
phoenix.druva.com
downloads.druva.com
deviceapigw-ap1-phoenix.druva.com
backup-ap1-phoenix.druva.com
pub-devicemgmt-devicenotifier-ap1-dcp.druva.com
devicemgmt-reverseproxy-ap1-dcp.druva.com
vmacproxy-edge-vmacn.*-c0-ap-south-1-phoenix\.druva\.com$
Configure the pattern, vmacproxy-edge-vmacn.*-c0-ap-south-1-phoenix\.druva\.com$ to avoid any restore failure for application-aware backups. If you are not able to exclude this URL, then contact Support for the IP addresses.
Agent and Log URLs (APAC)
Agent and Log URLs (APAC)
Allow both the primary FQDN and the Alias for each function. Both are required for reliable connectivity.
Purpose | FQDN | Alias |
Log download |
|
|
Agent upgrade |
|
|
Storage Cluster URLs (APAC)
Storage Cluster URLs (APAC)
You must allow the Storage Cluster URLs only for the storage regions assigned to your account. If you are unsure which regions apply, navigate to Storage > Provisioned Storages on the Management Console and check it.
The URLs below represent Druva's regional storage clusters, each corresponding to a specific storage region and its associated storage service.
Storage Region | Storage Cluster URL | Storage Service URL |
Singapore (ap-southeast-1) |
|
|
Hong Kong (ap-east-1) |
|
|
Mumbai (ap-south-1) |
|
|
Sydney (ap-southeast-2) |
|
|
Tokyo (ap-northeast-1) |
|
|
UAE (me-central-1) |
|
|
AWS S3 Storage URLs (APAC)
AWS S3 Storage URLs (APAC)
For Enterprise Workloads agents version 7.0.0 or later, allow the following AWS S3 storage URLs to access storage during backups and restores. Ensure that you configure firewall rules to allow both FQDN and Alias URLs.
The following table is for Enterprise Workloads agents version 7.0.0 or later.
Storage Region | S3 FQDN | S3 Alias |
Hong Kong (ap-east-1) |
|
|
Mumbai (ap-south-1) |
|
|
Singapore (ap-southeast-1) |
|
|
Sydney (ap-southeast-2) |
|
|
Tokyo (ap-northeast-1) |
|
|
UAE (me-central-1) |
|
|
AU Region Requirements
Common URLs (AU)
Common URLs (AU)
You must allow the Common URLs for your deployment region.
au-login.druva.com
au-globalapis.druva.com
au-phoenix.druva.com
downloads.druva.com
au-deviceapigw-phoenix.druva.com
au-backup-phoenix.druva.com
au-pub-devicemgmt-devicenotifier-dcp.druva.com
au-devicemgmt-reverseproxy-dcp.druva.com
Agent and Log URLs (AU)
Agent and Log URLs (AU)
Allow both the primary FQDN and the Alias for each function. Both are required for reliable connectivity.
Purpose | FQDN | Alias |
Log upload / download |
|
|
Agent upgrade |
|
|
Storage Cluster URLs (AU)
Storage Cluster URLs (AU)
You must allow the Storage Cluster URLs only for the storage regions assigned to your account. If you are unsure which regions apply, navigate to Storage > Provisioned Storages on the Management Console and check it.
The URLs below represent Druva's regional storage clusters, each corresponding to a specific storage region and its associated storage service.
Storage Region | Storage Cluster URL | Storage Service URL |
Sydney (ap-southeast-2)
|
|
|
AWS S3 Storage URLs (AU)
AWS S3 Storage URLs (AU)
Applies only to agents version 7.0.0 or later. Allow both the S3 FQDN and S3 Alias for each assigned storage region.
If your agent version is earlier than 7.0.0, skip this section.
For Enterprise Workloads agents version 7.0.0 or later, allow the following AWS S3 storage URLs to access storage during backups and restores. Ensure that you configure firewall rules to allow both FQDN and Alias URLs.
The following table is for Enterprise Workloads agents version 7.0.0 or later.
Storage Region | S3 FQDN | S3 Alias |
Sydney (ap-southeast-2) |
|
|
Azure / Quantum Bridge URLs
Azure Storage URLs
Azure Storage URLs
Applies to Azure workloads only.
If you protect Azure workloads, allow the Azure Storage URLs for the applicable Azure regions in your environment.
Resource Region | Whitelisting URL |
East US |
|
Australia East |
|
West US 2 |
|
UK South |
|
Germany West Central |
|
Central India |
|
Transient Blob URLs for Azure SQLs
Transient Blob URLs for Azure SQLs
If you use Azure SQL or Azure Storage accounts (Files/Blob/Data Lake) with private access (via Quantum Bridge), allow the Transient Blob URLs.
Transient blob storage facilitates data transfer to and from Druva’s Quantum Bridge and must reside in the same Azure region as the source resource. Since we support both APAC and US deployments with globally distributed resources, we maintain separate infrastructure, including storage accounts tied to their respective regions. So, if you are an APAC customer with resources located in a U.S. region (e.g., East US), you may be directed to use a U.S.-based storage URL to ensure proper data transfer. For this, ensure these URLs are allowed in the Network Security Group during the creation of the Quantum Bridge.
Which column applies to me in the following table?
Use the column that matches your Druva deployment region (US or APAC), not the Azure resource region.
Resource Region | APAC deployment region URLs | US deployment region URLs |
East US (eastus) |
|
|
Asia Pacific (southeastasia) |
|
|
North America (westus) |
|
|
Europe (uksouth) |
|
|
Europe (francecentral) |
|
|
Asia Pacific (australiacentral) |
|
|
Asia Pacific (australiaeast) |
|
|
Asia Pacific (australiasoutheast) |
|
|
South America (brazilsouth) |
|
|
North America (canadacentral) |
|
|
North America (canadaeast) |
|
|
Asia Pacific (centralindia) |
|
|
North America (centralus) |
|
|
Asia Pacific (eastasia) |
|
|
East US (eastus2) |
|
|
Europe (germanywestcentral) |
|
|
Middle East (israelcentral) |
|
|
Asia Pacific (japaneast) |
|
|
Asia Pacific (koreacentral) |
|
|
Asia Pacific (koreasouth) |
|
|
Central America (mexicocentral) |
|
|
North America (northcentralus) |
|
|
Europe (northeurope) |
|
|
Europe (norwayeast) |
|
|
Europe (polandcentral) |
| h |
Africa (southafricanorth) |
|
|
Africa (southafricawest) |
|
|
North America (southcentralus) |
|
|
Asia Pacific (southindia) |
|
|
Europe (swedencentral) |
|
|
Europe (switzerlandnorth) |
|
|
Middle East (uaenorth) |
|
|
Europe (ukwest) |
|
|
North America (westcentralus) |
|
|
Europe (westeurope) |
|
|
Asia Pacific (westindia) |
|
|
North America (westus2) | h |
|
North America (westus3) |
|
|
Next you must proceed to the Ports section to open the required ports for your workloads.
Step 2. Allow ports and communication protocols
Druva uses ports and communication protocols to ensure secure connections and communication during backup and restore operations.
📝 Note
Communication happens from a backup proxy to other parties on various ports. Here, the backup proxy is the communication initiator, which is unidirectional. These ports are used for outgoing (unidirectional) communication, not incoming communication. However, data in the form of a response can flow in the opposite direction. Standard system ports such as 22 (SSH) and 2049 (NFS-SERVER) are used for incoming requests.
VMware
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | HTTPS+SSL | Druva uses Port 443 to establish a secure connection and communication between the following:
📝 Note |
902 | TCP/UDP | Druva uses port 902 to establish a connection between the backup proxy and ESXi host registered with Druva through vCenter Server. By default, VMware uses the port 902 for the |
3542 | HTTPS+SSL | For application-aware backups, the backup proxy uses VMware Tools to inject two executables and a few supporting files such as certificates into the guest OS of the virtual machine. When the executables run, they start guest OS processes called |
3545 | HTTPS+SSL | For application-aware backups, the SQL executable service |
3389/22 | TCP/UDP | During the backup cycle, the backup proxy sends network packets to Windows virtual machines (where VMware tools are installed) on port 3389 to identify if the RDP port is open or not. For Linux virtual machines, the port is 22, which is used for SSH. This is used for Disaster Recovery or DR restores. |
123 | UDP | Backup proxy accesses NTP server on Port 123 (UDP) for time synchronization. |
443 | HTTPS+TLS | Druva uses TLS 1.2 or a secure connection that happens between the following:
|
VMware ESX
Source | Type | Protocol | Port range | Target | Description |
VMware Proxy | Custom | TCP | 902 | VMware ESX | Use port 902 to establish a connection between the Backup proxy and ESXi host registered with Druva through vCenter Server. |
VMware Proxy
Source | Type | Protocol | Port range | Target | Description |
Failback VM | HTTPS | HTTP | 443 | VMware Proxy | Failback VM connects to the VMware Proxy over HTTPS 443 port for sending Failback progress updates. |
Disaster Recovery
Click to view the ports and protocols
Click to view the ports and protocols
AWS Proxy (Inbound rules)
Source | Type | Protocol | Port range | Target | Description |
My IP | SSH | TCP | 22 | AWS Proxy | This is an optional inbound rule. |
AWS Proxy ( Outbound rules)
Source | Type | Protocol | Port range | Target | Description |
AWS Proxy | HTTPS | TCP | 443 | 0.0.0.0/0 | Use to communicate with Druva Cloud and AWS Services |
Failover EC2 Instance
Linux Failover EC2 Instance (Inbound rules)
Source | Type | Protocol | Port range | Target | Description |
My IP (Post DR Failover Job) | SSH | TCP | 22 | Failover EC2 Instance | This is an optional inbound rule. You can use this rule to log into the Failover EC2 Instance via SSH client such as Putty. |
Destination VMware Network (Post DR Failback Job) | SSH | TCP | 22 | Destination VMware Failback VM | You need this inbound rule for DR Failback. Use this rule to transfer data during DR Failback from Failover EC2 Instance to VMware Failback VM. |
Linux Failover EC2 Instance (Outbound rules)
Source | Type | Protocol | Port range | Target | Description |
Failover EC2 Instance | All Traffic | ALL | ALL | Anywhere IPv4 (0.0.0.0) | Use this outbound rule for DR Failback. |
Source | Type | Protocol | Port range | Target | Description |
Failover EC2 Instance | SSH | TCP | 22 | Destination VMware Failback VM | You need this outbound rule for DR Failback. Use this rule to transfer data during DR Failback from Failover EC2 Instance to VMware Failback VM. |
Failover EC2 Instance | DNS | TCP | 53 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | DNS | UDP | 53 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | LDAP | TCP | 389 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | LDAPS | TCP | 636 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | LDAP | UDP | 389 | Domain Controller Network | Use this outbound rule to log to the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job |
Failover EC2 Instance | custom TCP | TCP | 88 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | custom UDP | UDP | 88 | Domain Controller Network | Use this outbound rule to log to the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Windows Failover EC2 Instance (Inbound rules)
Source | Type | Protocol | Port range | Target | Description |
Destination VMware Network | SMB | TCP | 445 | Failover EC2 Instance | Use this inbound rule for DR Failback. This connection is used to communicate with the Failover EC2 Instance Admin Share. |
Destination VMware Network | Custom TCP | TCP | 50000 | Failover EC2 Instance | Use this inbound for DR Failback. |
My IP (Post DR Failover Job) | RDP | TCP | 3389 | Failover EC2 Instance | This is an optional inbound rule for DR Failover. This rule is not required for DR Failback. |
Windows Failover EC2 Instance (Outbound rules)
Source | Type | Protocol | Port range | Target | Description |
Failover EC2 Instance | All Traffic | ALL | ALL | Anywhere IPv4 (0.0.0.0) | Use this outbound rule for DR Failback. |
Source | Type | Protocol | Port range | Target | Description |
Failover EC2 Instance | DNS | TCP | 53 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | DNS | UDP | 53 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | LDAP | TCP | 389 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | LDAP | UDP | 389 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | Kerberos | TCP | 88 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | Kerberos | UDP | 88 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
Failover EC2 Instance | SMB | TCP | 445 | Domain Controller Network | Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job. |
AWS SQS Endpoint
Source | Type | Protocol | Port range | Target | Description |
Private Subnet of the VPC | HTTPS | HTTPS | 443 | SQS Interface Endpoint | Make sure the Interface Endpoint allows 443 inbound rule. For more information, see Amazon ECS interface VPC endpoints (AWS PrivateLink). |
Hyper-V
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup agent and Druva Cloud. |
Nutanix AHV
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
9440 | HTTPS+SSL | Druva uses Port 9440 to establish a secure connection and communication between the Backup Proxy and Prism. |
3261/3260 | TCP (iSCSI) | Port 3260 and 3261 uses the iSCSI protocol over TCP and is responsible for block-level storage communication between the proxy and the Nutanix cluster. |
443 | TLS | Backup Proxy to Druva Cloud. |
443 | TLS | Backup Proxy to S3 bucket. |
Proxmox
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | HTTPS+SSL | Druva uses Port 443 to establish a secure connection and communication between Backup Proxy and Druva Cloud |
File Server
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup agent and Druva Cloud. |
NAS
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup proxy and Druva Cloud. |
MS SQL Server
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup agent and Druva Cloud. |
Oracle PBS
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between PBS and Druva Cloud. |
Oracle DTC
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup agent and Druva Cloud. |
SAP HANA
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup agent and Druva Cloud. |
20000 to 20100 |
| Used for internal communication within the cluster |
21000 |
| Used for internal communication within the cluster |
TurboTier
Click to view the ports and protocols
Click to view the ports and protocols
Port | Communication protocol | Description |
443 | TLS | Druva uses Port 443 to establish a secure connection and communication between Backup agent, TurboTier agent, and Druva Cloud. |
2049 | TCP/UDP | This is the main Network File System (NFS) port used for core operations. All file access, directory browsing, and data transfer (reading and writing) between a client and server run directly over this port. For modern NFSv4, this is often the only port required. |
111 | TCP/UDP | This port is used by the rpcbind (or portmapper) service. In older NFS versions (v2/v3), it communicates the correct (and often dynamic) port numbers to the clients for other services, such as the one responsible for mounting. |
📝 Note
Port 8082 is used for internal communications on the host for FS, NAS, Hyper-V, VMware, Oracle DTC, and MS SQL. If port 8082 is unavailable, other available ephemeral ports will be used.

