What IP addresses need to be allowed on a firewall so Cacheflow can function.

Solutions ID:    KB4830
Version:    3.0
Status:    Published
Published date:    12/19/2011
Updated:    09/19/2013

Problem Description

The Cacheflow product needs to access a number of IP addresses through a firewall in order to do the following functions:

1. Upload diagnostic information such as the sysinfo, eventlog, and sysinfo-stats snapshots

2. Download the Bluecoat web filter database

3. Download Cachepulse

4. Download software updates

5. Allow Remote diagnostics

In most ISP deployments reflect client IP is used and the firewall will allow the client IP addresses access to the internet.  However the firewall may not allow the Cacheflow's IP address to access the internet.  The Cacheflow must use its IP address as it is originating the tcp connection.  Therefore a the Cacheflow's IP address must have access to a list of IP addresses.


The following is the list of IP addresses/names that the Cacheflow needs access to in order to perform the functions listed below:


 Allows the Cacheflow to upload heartbeat information to the heartbeat server.


Used when the send command uploads diagnostic information to bluecoat.


Used when a remote diagnostic sessions is required by support.


Used when downloading Cachepulse and Blue Coat Webfilter databases.  This server has several geographically-distributed PoPs, and is subject to occasional load-balancing changes. It doesn't change often (for a given deployment), but it has changed several times in the past.


Used to download software updates directly to the CacheFlow.


Used to retrieve the "birth-certificate" of a device. 

