Allowlist for outbound connections to Twingate infrastructure

Last updated: September 2, 2026

Applicable to:

  • Twingate Component: Client | Connector

Overview

Twingate Client and Connectors requires outbound connectivity on the following ports–

Reference: Endpoint Requirements - Firewall Rules

  • Outbound initiated TCP *:443 (basic communication with the Twingate Controller and Relay infrastructure)

  • Outbound initiated TCP *:[30000-31000] (opening connections with Twingate Relay infrastructure in case peer-to-peer is unavailable)

  • Outbound initiated UDP *:* (allows for peer-to-peer connectivity for optimal performance)

IP Allowlist

Twingate-owned IP block: 167.254.176.0/21

Static IP ranges are available to Enterprise customers only. If you'd like to use a static IP range, please reach out to your Twingate representative.

Allowlisting this IP block alone is not sufficient — you must also allowlist the relevant FQDNs (below). You can allowlist FQDNs only, or both IPs and FQDNs together, but IPs alone will not work.

FQDN allowlist

Some users might wish to have stricter limits with outbound connectivity from their environments. If possible, a wild card could be used and *.twingate.com would suffice. If wildcards are not possible, the FQDNs below can be used. Please keep in mind that this list is subject to change at any time.

  • subdomain.twingate.com <--- This is your network name and should be changed to match.

  • admin.twingate.com

  • analytics.twingate.com

  • api.twingate.com

  • binaries.twingate.com

  • dns.twingate.com

  • docs.twingate.com

  • get.twingate.com

  • h2.pubnubapi.com

  • help.twingate.com

  • oauth.twingate.com

  • pubsub.pubnub.com

  • ps.pndsn.com

  • relays.twingate.com

  • relays-prm.twingate.com

  • saml.twingate.com

  • sst-preview-server.twingate.com

  • sst.twingate.com

  • stape.twingate.com

  • support.twingate.com

  • twingate.com

  • url6332.twingate.com

  • Plus your tenant's regional URL — see below.

Regional URLs

Twingate infrastructure is now segmented by region — currently us1 and us2, with more regions planned as we grow. Each tenant's traffic resolves to a region-specific domain in the form:

[your-network-name].[region].twingate.com

Because the list of shards will keep growing, we recommend identifying your tenant's specific regional URL rather than relying on a list of every region that exists today:

  • If you allowlist using the *.twingate.com wildcard, this is already covered — no action needed.

  • If you allowlist explicit FQDNs, note your tenant's region URL (check the URL when logged into your admin console) and add it to your allowlist.

    e.g. [your-network-name].us1.twingate.com

GCP regions:

  • relays443.twingate.com  

  • relays443-prm.twingate.com

  • stun.africa-south1-a.twingate.com

  • stun-alt.africa-south1-a.twingate.com

  • stun.asia-east1-a.twingate.com

  • stun-alt.asia-east1-a.twingate.com

  • stun.asia-east2-a.twingate.com

  • stun-alt.asia-east2-a.twingate.com

  • stun.europe-west4-a.twingate.com

  • stun-alt.europe-west4-a.twingate.com

  • stun.northamerica-northeast2-a.twingate.com

  • stun-alt.northamerica-northeast2-a.twingate.com

  • stun-alt.asia-northeast1-a.twingate.com

  • stun-alt.asia-south1-a.twingate.com

  • stun-alt.asia-southeast1-a.twingate.com

  • stun-alt.australia-southeast1-a.twingate.com

  • stun-alt.europe-north1-a.twingate.com

  • stun-alt.europe-west2-a.twingate.com

  • stun-alt.europe-west3-a.twingate.com

  • stun-alt.europe-west6-b.twingate.com

  • stun-alt.me-west1-a.twingate.com

  • stun-alt.southamerica-east1-a.twingate.com

  • stun-alt.us-central1-a.twingate.com

  • stun-alt.us-east1-d.twingate.com

  • stun-alt.us-east4-a.twingate.com

  • stun-alt.us-east4-b.twingate.com

  • stun-alt.us-east5-a.twingate.com

  • stun-alt.us-west1-a.twingate.com

  • stun-alt.us-west2-a.twingate.com

  • stun.asia-northeast1-a.twingate.com

  • stun.asia-south1-a.twingate.com

  • stun.asia-southeast1-a.twingate.com

  • stun.australia-southeast1-a.twingate.com

  • stun.europe-north1-a.twingate.com

  • stun.europe-west2-a.twingate.com

  • stun.europe-west3-a.twingate.com

  • stun.europe-west6-b.twingate.com

  • stun.me-west1-a.twingate.com

  • stun.southamerica-east1-a.twingate.com

  • stun.us-central1-a.twingate.com

  • stun.us-east1-d.twingate.com

  • stun.us-east4-a.twingate.com

  • stun.us-east4-b.twingate.com

  • stun.us-east5-a.twingate.com

  • stun.us-west1-a.twingate.com

  • stun.us-west2-a.twingate.com
      

Digital Ocean regions:

  • relays-do.twingate.com

  • relays-prm-do.twingate.com

  • stun.ams3.twingate.com

  • stun-alt.ams3.twingate.com

  • stun.atl1.twingate.com

  • stun-alt.atl1.twingate.com

  • stun.blr1.twingate.com

  • stun-alt.blr1.twingate.com

  • stun.fra1.twingate.com

  • stun-alt.fra1.twingate.com

  • stun.lon1.twingate.com

  • stun-alt.lon1.twingate.com

  • stun.nyc1.twingate.com

  • stun-alt.nyc1.twingate.com

  • stun.nyc2.twingate.com

  • stun-alt.nyc2.twingate.com

  • stun.ric1.twingate.com

  • stun-alt.ric1.twingate.com

  • stun.sfo2.twingate.com

  • stun-alt.sfo2.twingate.com

  • stun.sgp1.twingate.com

  • stun-alt.sgp1.twingate.com

  • stun.syd1.twingate.com

  • stun-alt.syd1.twingate.com

  • stun.tor1.twingate.com

  • stun-alt.tor1.twingate.com