Firewall
- Last UpdatedSep 01, 2026
- 1 minute read
To fully secure the use of AVEVA Unified Engineering - Spectrum, including the Edge Connector, it is recommended that you install a firewall. You must configure the firewall to allow the required traffic detailed below.
Inbound traffic
To configure the firewall, use the Claims Service and Page Service the following way.
|
Purpose |
Direction |
Local Port |
Protocol |
Action |
|---|---|---|---|---|
|
Inbound gRPC for page service |
Inbound |
5005 |
TCP |
Allow |
|
Inbound gRPC for claims service |
Inbound |
5006 |
TCP |
Allow |
Note: You can configure the port numbers during installation. If you chose a different port during installation, you need to add the port to the allow-list instead.
The Edge Connector Cloudstore folder must be configured as a file share. See Edge Connector Cloudstore folder for more information.
Outbound traffic
Most outbound traffic requires port 443 to communicate with the cloud service through HTTPS. In restricted network environments using a least privilege approach, allow the following URLs in addition to the URLs listed in CONNECT through your firewall:
Spectrum Edge Connector
-
spectrum.connect.aveva.com
-
central-claims-iothub-prod.azure-devices.net
-
storeblobprod0a01211a.blob.core.windows.net
-
instalblobprod1ee8451e.blob.core.windows.net
Unified Engineering with Spectrum projects
-
spectrum.connect.aveva.com
-
storeblobprod0a01211a.blob.core.windows.net
Unified Engineering – Spectrum Administration dashboard
-
spectrum.connect.aveva.com
-
instalblobprod1ee8451e.blob.core.windows.net
There are a few URLs for validating certificates which use http over port 80. This is standard industry practice as the certificates are required for the https communication. For more information, refer to Manage firewall allowlist for CONNECT - CONNECT.