Allowlist for outbound connections to Twingate infrastructure
Last updated: September 2, 2026
Applicable to:
Twingate Component: Client | Connector
Overview
Twingate Client and Connectors requires outbound connectivity on the following ports–
Reference: Endpoint Requirements - Firewall Rules
Outbound initiated TCP
*:443(basic communication with the Twingate Controller and Relay infrastructure)Outbound initiated TCP
*:[30000-31000](opening connections with Twingate Relay infrastructure in case peer-to-peer is unavailable)Note– Relay connections will be set directly to an ephemeral IP within the Google Cloud's IP ranges for Relay Cluster Locations
Google's maintained list of IP ranges– Global and regional external IP address ranges for customers' Google Cloud resources
Outbound initiated UDP
*:*(allows for peer-to-peer connectivity for optimal performance)
IP Allowlist
Twingate-owned IP block: 167.254.176.0/21
Static IP ranges are available to Enterprise customers only. If you'd like to use a static IP range, please reach out to your Twingate representative.
Allowlisting this IP block alone is not sufficient — you must also allowlist the relevant FQDNs (below). You can allowlist FQDNs only, or both IPs and FQDNs together, but IPs alone will not work.
FQDN allowlist
Some users might wish to have stricter limits with outbound connectivity from their environments. If possible, a wild card could be used and *.twingate.com would suffice. If wildcards are not possible, the FQDNs below can be used. Please keep in mind that this list is subject to change at any time.
subdomain.twingate.com <--- This is your network name and should be changed to match.admin.twingate.com
analytics.twingate.com
api.twingate.com
binaries.twingate.com
dns.twingate.com
docs.twingate.com
get.twingate.com
h2.pubnubapi.com
help.twingate.com
oauth.twingate.com
pubsub.pubnub.com
ps.pndsn.com
relays.twingate.com
relays-prm.twingate.com
saml.twingate.com
sst-preview-server.twingate.com
sst.twingate.com
stape.twingate.com
support.twingate.com
twingate.com
url6332.twingate.com
Plus your tenant's regional URL — see below.
Regional URLs
Twingate infrastructure is now segmented by region — currently us1 and us2, with more regions planned as we grow. Each tenant's traffic resolves to a region-specific domain in the form:
[your-network-name].[region].twingate.com
Because the list of shards will keep growing, we recommend identifying your tenant's specific regional URL rather than relying on a list of every region that exists today:
If you allowlist using the
*.twingate.comwildcard, this is already covered — no action needed.If you allowlist explicit FQDNs, note your tenant's region URL (check the URL when logged into your admin console) and add it to your allowlist.
e.g.
[your-network-name].us1.twingate.com
GCP regions:
relays443.twingate.com
relays443-prm.twingate.com
stun.africa-south1-a.twingate.com
stun-alt.africa-south1-a.twingate.com
stun.asia-east1-a.twingate.com
stun-alt.asia-east1-a.twingate.com
stun.asia-east2-a.twingate.com
stun-alt.asia-east2-a.twingate.com
stun.europe-west4-a.twingate.com
stun-alt.europe-west4-a.twingate.com
stun.northamerica-northeast2-a.twingate.com
stun-alt.northamerica-northeast2-a.twingate.com
stun-alt.asia-northeast1-a.twingate.com
stun-alt.asia-south1-a.twingate.com
stun-alt.asia-southeast1-a.twingate.com
stun-alt.australia-southeast1-a.twingate.com
stun-alt.europe-north1-a.twingate.com
stun-alt.europe-west2-a.twingate.com
stun-alt.europe-west3-a.twingate.com
stun-alt.europe-west6-b.twingate.com
stun-alt.me-west1-a.twingate.com
stun-alt.southamerica-east1-a.twingate.com
stun-alt.us-central1-a.twingate.com
stun-alt.us-east1-d.twingate.com
stun-alt.us-east4-a.twingate.com
stun-alt.us-east4-b.twingate.com
stun-alt.us-east5-a.twingate.com
stun-alt.us-west1-a.twingate.com
stun-alt.us-west2-a.twingate.com
stun.asia-northeast1-a.twingate.com
stun.asia-south1-a.twingate.com
stun.asia-southeast1-a.twingate.com
stun.australia-southeast1-a.twingate.com
stun.europe-north1-a.twingate.com
stun.europe-west2-a.twingate.com
stun.europe-west3-a.twingate.com
stun.europe-west6-b.twingate.com
stun.me-west1-a.twingate.com
stun.southamerica-east1-a.twingate.com
stun.us-central1-a.twingate.com
stun.us-east1-d.twingate.com
stun.us-east4-a.twingate.com
stun.us-east4-b.twingate.com
stun.us-east5-a.twingate.com
stun.us-west1-a.twingate.com
stun.us-west2-a.twingate.com
Digital Ocean regions:
relays-do.twingate.com
relays-prm-do.twingate.com
stun.ams3.twingate.com
stun-alt.ams3.twingate.com
stun.atl1.twingate.com
stun-alt.atl1.twingate.com
stun.blr1.twingate.com
stun-alt.blr1.twingate.com
stun.fra1.twingate.com
stun-alt.fra1.twingate.com
stun.lon1.twingate.com
stun-alt.lon1.twingate.com
stun.nyc1.twingate.com
stun-alt.nyc1.twingate.com
stun.nyc2.twingate.com
stun-alt.nyc2.twingate.com
stun.ric1.twingate.com
stun-alt.ric1.twingate.com
stun.sfo2.twingate.com
stun-alt.sfo2.twingate.com
stun.sgp1.twingate.com
stun-alt.sgp1.twingate.com
stun.syd1.twingate.com
stun-alt.syd1.twingate.com
stun.tor1.twingate.com
stun-alt.tor1.twingate.com