Come join our live training webinar every other Wednesday at 11am PST and hear LogicMonitor experts explain best practices and answer common questions. We understand these are uncertain times, and we are here to help!
Every LogicMonitor customer has a DNS record of [customername].logicmonitor.com. This record resolves to two or more public IP addresses at any given time. Because these IP addresses can and do change over time, it’s imperative that your network’s firewall(s) permit access to all of our public IP addresses.
There are two methods for adding LogicMonitor’s public IP addresses to your allow list:
Note: The above list of addresses does not include LogicMonitor’s external test locations for website monitoring. If you are performing website monitoring and need to explicitly allow for our external test location IP addresses, you can find the list of addresses in What Is Website Monitoring.
Some customers manually update their Collectors’ /etc/hosts files with static IP addresses. This is not a recommended (or sustainable) practice because these IP addresses can and do change over time. If for some reason a Collector cannot use DNS, then periodic checks (e.g. every five minutes) should be made to ensure the static entry remains up to date.
The only external communications needed for a LogicMonitor Collector is outbound 443/tcp to the IP addresses/DNS names noted above. If communications are sent to port 80 then a redirect to 443 can be expected. In order to use our remote session functionality, you will also need RDP or SSH on port 443.
Note: Bootstrap executables for Collector installation are delivered via CDN (AWS CloudFront). It is recommended to allow the DNS in order to support this process. However, if it is required that IP addresses be added to your allow list individually, you will need to review and add CloudFront’s IP ranges, as discussed in CloudFront’s
Note: LogicMonitor has four individual proxy endpoints dedicated to routing collected data around disruptions in the public internet to your portal. If your Collectors are unable to reach our data centers, collected data will be rerouted through these proxies until it can be delivered to your portal via the normal path.
In This Article