Views:
The following firewall exceptions apply to networks with:

TrendAI Vision One™ Authentication

Service
Region
Exceptions
TrendAI Vision One™
  • All
signin.v1.trendmicro.com
tm.login.trendmicro.com
iamservice.trendmicro.com
Other custom IDP services
Google reCAPTCHA:
www.gstatic.com
fonts.gstatic.com
Plus one of the following:
www.google.com (recommended)
www.recaptcha.net

Endpoint Security Exceptions

Service / Agent
Region
Exceptions
Endpoint Sensor features
  • Singapore
assessment-ap3.mgcp.trendmicro.com
release-us1.mgcp.trendmicro.com
api-ap3.xbc.trendmicro.com
cdn-api-ap3.xbc.trendmicro.com
a1bz7u2flvp09t-ats.iot.ap-southeast-1.amazonaws.com
tgw-ap3.mgcp.trendmicro.com
support-connector-api.manage.trendmicro.com
supportconnectorpacks.manage.trendmicro.com
rpcollectedthings.manage.trendmicro.com
cloudendpoint-ap3.mgcp.trendmicro.com
er-ws-ase1.xdr.trendmicro.com
era-ase1.xdr.trendmicro.com
endpointpolicy-cdn-ap3.xbc.trendmicro.com
files.trendmicro.com
xlogr-ase1.xdr.trendmicro.com
api.sg.xdr.trendmicro.com
api-cert.sg.xdr.trendmicro.com
upload.sg.xdr.trendmicro.com
ipv6-iaus.trendmicro.com
ipv6-iaus.activeupdate.trendmicro.com
iaus.activeupdate.trendmicro.com
iaus.trendmicro.com
Browser extension
Important
Important
Apply these exceptions if you enable the feature using Endpoint Sensor or the Web Reputation module in Standard Endpoint Protection.
  • All
clients2.google.com/service/update2/crx
edge.microsoft.com/extensionwebstorebase/v1/crx
Sandbox Analysis
  • All
sandbox-threatconnect.trendmicro.com
Standard Endpoint Protection features
Important
Important
If you enable endpoint sensor detection and response, you must also add the Endpoint Sensor features exceptions.
  • All
<Apex One console_DNS>.manage.trendmicro.com
licenseupdate.trendmicro.com
asm01-nabu-prod.aot.trendmicro.com
api-nabu.aot.trendmicro.com
osce14-p.activeupdate.trendmicro.com
tmsm35-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
osce14.icrc.trendmicro.com
osce14-0-en.url.trendmicro.com
osce140-en.fbs25.trendmicro.com
osce14-en.gfrbridge.trendmicro.com
osce14-en-census.trendmicro.com
osce14bak-en-census.trendmicro.com
osce140-en-f.trx.trendmicro.com
oscecmp140-en-f.trx.trendmicro.com
osce140-en-b.trx.trendmicro.com
mcs.trendmicro.com
www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/
files.trendmicro.com
aurd-test2.activeupdate.trendmicro.com
support-connector-api.manage.trendmicro.com
support-connector-service.manage.trendmicro.com
supportconnectorpacks.manage.trendmicro.com
rpcollectedthings.blob.core.windows.net
tmsm35.icrc.trendmicro.com
tmsm3-5-tc.url.trendmicro.com
tmsm350-tc.fbs25.trendmicro.com
tmsm35-tc.gfrbridge.trendmicro.com
macOS Agents:
tmsm35.icrc.trendmicro.com/ss
tmsm3-5-cs.url.trendmicro.com
tmsm3-5-de.url.trendmicro.com
tmsm3-5-en.url.trendmicro.com
tmsm3-5-es.url.trendmicro.com
tmsm3-5-fr.url.trendmicro.com
tmsm3-5-it.url.trendmicro.com
tmsm3-5-pl.url.trendmicro.com
tmsm3-5-tc.url.trendmicro.com
tmsm35-cs.gfrbridge.trendmicro.com
tmsm35-de.gfrbridge.trendmicro.com
tmsm35-en.gfrbridge.trendmicro.com
tmsm35-es.gfrbridge.trendmicro.com
tmsm35-fr.gfrbridge.trendmicro.com
tmsm35-it.gfrbridge.trendmicro.com
tmsm35-pl.gfrbridge.trendmicro.com
tmsm35-tc.gfrbridge.trendmicro.com
tmsm350-cs.fbs25.trendmicro.com
tmsm350-de.fbs25.trendmicro.com
tmsm350-en.fbs25.trendmicro.com
tmsm350-es.fbs25.trendmicro.com
tmsm350-fr.fbs25.trendmicro.com
tmsm350-it.fbs25.trendmicro.com
tmsm350-pl.fbs25.trendmicro.com
tmsm350-tc.fbs25.trendmicro.com
Server & Workload Protection features
Important
Important
If you enable endpoint sensor detection and response, you must also add the Endpoint Sensor features exceptions.
  • All
workload.sg-1.cloudone.trendmicro.com
agents.workload.sg-1.cloudone.trendmicro.com
<agents-001 through agents-010>.workload.sg-1.cloudone.trendmicro.com
agent-comm.workload.sg-1.cloudone.trendmicro.com
dsmim.workload.sg-1.cloudone.trendmicro.com
relay.workload.sg-1.cloudone.trendmicro.com
xdr-resp-ioc.workload.sg-1.cloudone.trendmicro.com
files.trendmicro.com
iaus.activeupdate.trendmicro.com
iaus.trendmicro.com
ipv6-iaus.trendmicro.com
ipv6-iaus.activeupdate.trendmicro.com
dsaas1100-en-census.trendmicro.com
ds200-en.fbs25.trendmicro.com
ds200-jp.fbs25.trendmicro.com
dsaas.icrc.trendmicro.com
dsaas-en-f.trx.trendmicro.com
dsaas-en-b.trx.trendmicro.com
deepsecaas11-en.gfrbridge.trendmicro.com
dsaas.url.trendmicro.com
gateway.workload.sg-1.cloudone.trendmicro.com
gateway-control.workload.sg-1.cloudone.trendmicro.com
relay.deepsecurity.trendmicro.com
Firewall EIP Block
workload.sg-1.cloudone.trendmicro.com (13.214.15.0/27, 18.99.38.64/27)
agents.workload.sg-1.cloudone.trendmicro.com (13.214.15.0/27, 18.99.38.64/27)
relay.workload.sg-1.cloudone.trendmicro.com (13.214.15.0/27, 18.99.38.64/27)
dsmim.workload.sg-1.cloudone.trendmicro.com (13.214.15.0/27, 18.99.38.64/27)
<agents-001 through agents-010>.workload.sg-1.cloudone.trendmicro.com (13.214.15.0/27, 18.99.38.64/27)
Zero Trust Secure Access Exceptions
Important
Important
You must also specify the exceptions for the Endpoint Sensor Agents. These exceptions are found at Endpoint Sensor Agents.
.
Service
Region
Exceptions
Access Module
  • All
prod.ztsaagent.trendmicro.com
upload.sg.xdr.trendmicro.com
event-sg.ztsaagent.trendmicro.com
Authentication
  • All
agent-sg-rel.ztna.trendmicro.com
signin.v1.trendmicro.com
tm.login.trendmicro.com
iamservice.trendmicro.com
Other custom IDP services
Google reCAPTCHA:
www.gstatic.com
fonts.gstatic.com
Plus one of the following:
www.google.com (recommended)
www.recaptcha.net
Internet Access Service
  • All
auth.ztsa-iag.trendmicro.com
pac.sg.ztsa-iag.trendmicro.com
auth.sg.ztsa-iag.trendmicro.com
Internet Access Cloud Gateway
  • All
proxy.ztsa-iag.trendmicro.com
proxy.sg.ztsa-iag.trendmicro.com
proxy-id.sg.ztsa-iag.trendmicro.com
proxy-tw.sg.ztsa-iag.trendmicro.com
d9vbqsel5dvrs.cloudfront.net
Internet Access On-Premises Gateway with Smart Protection Network: Off
  • All
xlogr-ase1.xdr.trendmicro.com
api.ap-southeast-1.sg.ddcloud.trendmicro.com
iwsh30-en.url.trendmicro.com
api-ap-southeast-1.crs.trendmicro.com
iwsh300-en.census.trendmicro.com
iwsaas30-en-f.trx.trendmicro.com
iwsh30-p.activeupdate.trendmicro.com
d9vbqsel5dvrs.cloudfront.net
Internet Access On-Premises Gateway with Smart Protection Network: On
  • All
xlogr-ase1.xdr.trendmicro.com
api.ap-southeast-1.sg.ddcloud.trendmicro.com
ctapi.trendmicro.com
iwsh30-p.activeupdate.trendmicro.com
d9vbqsel5dvrs.cloudfront.net
Private Access Connector
  • All
agent-mea-rel.ztna.trendmicro.com
saseztnaprodsgsagen2.blob.core.windows.net
saseztnaprodsgsa.blob.core.windows.net
sase-ztna-prod-sg-iothub-cntevt.azure-devices.net
speedtest.sg.ztna.trendmicro.com
ztnaextacr.azurecr.io
0.pool.ntp.org
1.pool.ntp.org
2.pool.ntp.org
3.pool.ntp.org
Private Access Connector
(if not using the Trend Cloud Proxy service)
Australia
20.5.69.128/28
Europe
20.4.51.32/28
India
20.219.254.160/28
Israel
20.217.194.0/28
Japan
52.140.246.128/28
Singapore
52.187.118.64/28
United States
20.7.52.240/28
Brazil
4.228.193.144/28
MEA
20.74.229.224/28
United Kingdom
20.0.229.192/28
Canada
40.82.166.0/28

Service Gateway Exceptions

Service
Region
Exceptions
Firmware
  • All
sgi-tunneling.sg.xdr.trendmicro.com
sgi-iot.sg.xdr.trendmicro.com
api.sg.xdr.trendmicro.com
upload.sg.xdr.trendmicro.com
Smart Protection Network proxy: On
  • All
ctapi.trendmicro.com
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Smart Protection Network proxy: Off
  • All
sg-tmsps10-en.url.trendmicro.com
sg-tmsps10-en-wis.trendmicro.com
sg-tmsps100-en-census.trendmicro.com
sg-tmsps100-en-domaincensus.trendmicro.com
grid-global.trendmicro.com
rest.mars.trendmicro.com
sg-tmsps10-en.gfrbridge.trendmicro.com
sg-tmsps10-p.activeupdate.trendmicro.com
sg-tmsps10-en-backup.url.trendmicro.com
activeupdate.trendmicro.com
Local ActiveUpdate
  • All
Refer to ActiveUpdate session of each product/agent

Forensics and Analysis

Service / Agent
Region
Exceptions
IR Tool Download for Agent
  • Singapore
resources.prod-ap-southeast-1.irs.trendmicro.com

TrendAI Vision One™ Container Security

Service
Region
Exceptions
Mandatory for Container Security
  • All
api.sg.xdr.trendmicro.com
vcs-storage-sg.xdr.trendmicro.com
Artifact Scanner
  • All
api.sg.xdr.trendmicro.com
ast-upload-sg.xdr.trendmicro.com
ast-report-sg.xdr.trendmicro.com
ast-cli.xdr.trendmicro.com
antimalware.sg-1.cloudone.trendmicro.com
antimalware-ase1.xdr.trendmicro.com
Runtime Security
  • All
api.sg.xdr.trendmicro.com
vcs-iot-sg.xdr.trendmicro.com
vcs-storage-sg.xdr.trendmicro.com
Runtime Malware Scanning
  • All
activeupdate.trendmicro.com
Default Container Image Access
  • All
public.ecr.aws
*.cloudfront.net

TippingPoint Exceptions

Service
Region
Exceptions
TippingPoint
Australia
a1mmnfkx71i3sj-ats.iot.ap-southeast-2.amazonaws.com
Europe
a1mmnfkx71i3sj-ats.iot.eu-central-1.amazonaws.com
India
a1mmnfkx71i3sj-ats.iot.ap-south-1.amazonaws.com
Japan
a1mmnfkx71i3sj-ats.iot.ap-northeast-1.amazonaws.com
Singapore
a1mmnfkx71i3sj-ats.iot.ap-southeast-1.amazonaws.com
United Kingdom
a1mmnfkx71i3sj-ats.iot.eu-west-2.amazonaws.com
United States
a1mmnfkx71i3sj-ats.iot.us-east-1.amazonaws.com

Network Inventory

Service
Region
Exceptions
Virtual Network Sensor
Singapore
xns-p.activeupdate.trendmicro.com
gp.fbs.trendmicro.com
xlogr-ase1.xdr.trendmicro.com
api.sg.xdr.trendmicro.com
licenseupdate.trendmicro.com
For customers with "Send to Sandbox" enabled, add the following as well:
ctapi.trendmicro.com
api.ddcloud.trendmicro.com
api.sg.ddcloud.trendmicro.com
Deep Discovery Inspector version 6.8 Service Pack 1 / 6.8 Service Pack 2
Singapore
api.ddcloud.trendmicro.com
api.sg.ddcloud.trendmicro.com
api.sg.xdr.trendmicro.com
ctapi.trendmicro.com
ddaaas.trendmicro.com
ddi681.retroscan.trendmicro.com
ddi68-p.activeupdate.trendmicro.com/activeupdate
gp.fbs.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
xlogr-ase1.xdr.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Deep Discovery Inspector version 6.8
Singapore
api-ni-sg.xdr.trendmicro.com
api.ddcloud.trendmicro.com
api.sg.ddcloud.trendmicro.com
api.sg.xdr.nacloud.trendmicro.com
api.sg.xdr.trendmicro.com
ddaaas.trendmicro.com
gp.fbs.trendmicro.com
grid-global.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
rest.mars.trendmicro.com
xlogr-ase1.xdr.trendmicro.com
ddi68-en-f.trx.trendmicro.com
ddi68-p.activeupdate.trendmicro.com/activeupdate
ddi68.retroscan.trendmicro.com
ddi6-8-en-t0.url.trendmicro.com
ddi6-8-en-wis.trendmicro.com
ddi6-8-en.url.trendmicro.com
ddi680-en-census.trendmicro.com
ddi680-en-domaincensus.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Deep Discovery Inspector version 6.7 / 6.7 Service Pack 1
Singapore
api-ni-sg.xdr.trendmicro.com
api.ddcloud.trendmicro.com
api.sg.ddcloud.trendmicro.com
api.sg.xdr.nacloud.trendmicro.com
api.sg.xdr.trendmicro.com
ddaaas.trendmicro.com
gp.fbs.trendmicro.com
grid-global.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
rest.mars.trendmicro.com
xlogr-ase1.xdr.trendmicro.com
ddi67-en-f.trx.trendmicro.com
ddi67-p.activeupdate.trendmicro.com/activeupdate
ddi67.retroscan.trendmicro.com
ddi6-7-en-t0.url.trendmicro.com
ddi6-7-en-wis.trendmicro.com
ddi6-7-en.url.trendmicro.com
ddi670-en-census.trendmicro.com
ddi670-en-domaincensus.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Deep Discovery Inspector version 6.6
Singapore
api-ni-sg.xdr.trendmicro.com
api.ddcloud.trendmicro.com
api.sg.ddcloud.trendmicro.com
api.sg.xdr.nacloud.trendmicro.com
ddaaas.trendmicro.com
gp.fbs.trendmicro.com
grid-global.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
rest.mars.trendmicro.com
xlogr-ase1.xdr.trendmicro.com
ddi66-en-f.trx.trendmicro.com
ddi66-p.activeupdate.trendmicro.com/activeupdate
ddi66.retroscan.trendmicro.com
ddi6-6-en-t0.url.trendmicro.com
ddi6-6-en-wis.trendmicro.com
ddi6-6-en.url.trendmicro.com
ddi660-en-census.trendmicro.com
ddi660-en-domaincensus.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Deep Discovery Inspector version 6.5
Singapore
api-ni-sg.xdr.trendmicro.com
api.ddcloud.trendmicro.com
api.sg.ddcloud.trendmicro.com
api.sg.xdr.nacloud.trendmicro.com
ddaaas.trendmicro.com
gp.fbs.trendmicro.com
grid-global.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
rest.mars.trendmicro.com
xlogr-ase1.xdr.trendmicro.com
ddi65-en-f.trx.trendmicro.com
ddi65-p.activeupdate.trendmicro.com/activeupdate
ddi65.retroscan.trendmicro.com
ddi6-5-en-t0.url.trendmicro.com
ddi6-5-en-wis.trendmicro.com
ddi6-5-en.url.trendmicro.com
ddi650-en-census.trendmicro.com
ddi650-en-domaincensus.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Deep Discovery Inspector version 6.2
Singapore
api-ni-sg.xdr.trendmicro.com
api.ddcloud.trendmicro.com
api.sg.ddcloud.trendmicro.com
api.sg.xdr.nacloud.trendmicro.com
ddaaas.trendmicro.com
gp.fbs.trendmicro.com
grid-global.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
rest.mars.trendmicro.com
xlogr-ase1.xdr.trendmicro.com
ddi62-en-f.trx.trendmicro.com
ddi62-p.activeupdate.trendmicro.com/activeupdate
ddi62.retroscan.trendmicro.com
ddi6-2-en-t0.url.trendmicro.com
ddi6-2-en-wis.trendmicro.com
ddi6-2-en.url.trendmicro.com
ddi620-en-census.trendmicro.com
ddi620-en-domaincensus.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com
Deep Discovery Inspector version 6.0
Singapore
api-ni-sg.xdr.trendmicro.com
api.ddcloud.trendmicro.com
api.sg.ddcloud.trendmicro.com
api.sg.xdr.nacloud.trendmicro.com
ddaaas.trendmicro.com
gp.fbs.trendmicro.com
grid-global.trendmicro.com
intelliconnect.trendmicro.com
licenseupdate.trendmicro.com
portal-01.dddxdr.trendmicro.com
portal-02.dddxdr.trendmicro.com
rest.mars.trendmicro.com
xlogr-ase1.xdr.trendmicro.com
ddi60-en-f.trx.trendmicro.com
ddi60-p.activeupdate.trendmicro.com/activeupdate
ddi60.retroscan.trendmicro.com
ddi6-0-en-t0.url.trendmicro.com
ddi6-0-en-wis.trendmicro.com
ddi6-0-en.url.trendmicro.com
ddi600-en-census.trendmicro.com
ddi600-en-domaincensus.trendmicro.com
Note
Note
If you connect Deep Discovery Inspector using Service Gateway with Smart Protection Network Proxy enabled, add the following exceptions in addition to the above ones:
sg-tmsps10-p.activeupdate.trendmicro.com
activeupdate.trendmicro.com

Mobile Seciurity for Android

Server
Region
Port
Exceptions
TrendMicro Mobile Security Backend
All
  • 80
  • 443
*.mobile.trendmicro.com
*.xdr.trendmicro.com
https://portal.mobile.trendmicro.com/ui/ami/mobile/h5/worryfree/openAndroidApp.html?productCode=wfbss&authCode=HWQj7aab&userPrincipalName=
rest.mars.trendmicro.com
rest-g.mars.trendmicro.com
rest-g-au.mars.trendmicro.com
mint.mars.trendmicro.com
portal-sg.mobile.trendmicro.com
*.ztna.trendmicro.com
*.ztsa-iag.trendmicro.com
logs.trendmicro.com
spnsupport.trendmicro.com
mxdr1-0.url.trendmicro.com mxdr1-0-im.url.trendmicro.com
http://*.trendmicro.com
https://*.trendmicro.com
GooglePlay / Firebase Server
All
  • 443
  • 5228
  • 5229
  • 5230
*.google.com
*.firebase.com
*.googleapis.com
*.firebaseio.com
Log feedback
All
  • 443
https://cognito-identity.us-west-2.amazonaws.com

Mobile Security for iOS

Server
Region
Port
Exceptions
TrendMicro Mobile Security Backend
All
  • 22
  • 80
  • 443
*.trendmicro.com
*.mobile.trendmicro.com
*.xdr.trendmicro.com
rest.mars.trendmicro.com
rest-g.mars.trendmicro.com
rest-g-au.mars.trendmicro.com
mint.mars.trendmicro.com
portal-sg.mobile.trendmicro.com
*.ztna.trendmicro.com
*.ztsa-iag.trendmicro.com
logs.trendmicro.com
spnsupport.trendmicro.com
mxdr1-0.url.trendmicro.com
mxdr1-0-im.url.trendmicro.com
mxdr1-0-ios.url.trendmicro.com
http://*.trendmicro.com
https://*.trendmicro.com
Apple Server
All
  • 443
  • 80
  • 5223
  • 2197
  • 123
*.apple.com
*.mzstatic.com
*.icloud.com
Firebase Server
All
  • 443
  • 5228
  • 5229
  • 5230
*.google.com
*.firebase.com
*.googleapis.com
*.firebaseio.com
Log feedback
All
  • 443
https://cognito-identity.us-west-2.amazonaws.com

TrendAI Vision One™ Agentless Vulnerability & Threat Detection Exceptions

Service
Region
Exceptions
Agentless Vulnerability and Threat Detection
Singapore
googlecode.l.googleusercontent.com
sentry.sg-1.cloudone.trendmicro.com
xlogr-ase1.xdr.trendmicro.com

Security Awareness Exceptions

Service
Region
Exceptions
Security awareness
All
cdn.tiny.cloud

Cloud Risk Management

Service
Region
Exceptions
Real-Time Posture Monitoring
Singapore
rtpm.apm-sg.xdr.trendmicro.com
a2sx2v445s9fxl-ats.iot.ap-southeast-1.amazonaws.com

Executive Dashboard

Service
Region
Exceptions
XDR
All
download.xdr.trendmicro.com

LaunchDarkly exceptions

Service
Region
Exceptions
LaunchDarkly
  • All
For the complete list of required LaunchDarkly domains, see the LaunchDarkly domain list.