# Firewall Rules for updates and patches

**URL:** <https://forums.suse.com/t/firewall-rules-for-updates-and-patches/28554>\
**Category:** SLES Updates\
**Created:** [August 23, 2016, 9:11am UTC](https://forums.suse.com/t/firewall-rules-for-updates-and-patches/28554 "2016-08-23T09:11:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cr\_ibix](https://avatars.discourse-cdn.com/v4/letter/c/cab0a1/32.png) [@cr\_ibix](https://forums.suse.com/u/cr_ibix)\
**Post date:** [August 23, 2016, 9:11am UTC](https://forums.suse.com/t/firewall-rules-for-updates-and-patches/28554/1 "2016-08-23T09:11:20Z")

</div>

Hello,

i have a SLES 11 SP4 server behind a third party firewall. Now i have to tell the firewall maintainer which adresses and ports sles need to load updates and patches from the internet.  
I want to use all features of yast (updates/patches AND registration on the SCC).

Can anyone help me? I found NOTHING about this topic.

thanks

---

<div class="post-metadata">

**Author:** ![ab1](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@ab1](https://forums.suse.com/u/ab1)\
**Post date:** [August 23, 2016, 12:47pm UTC](https://forums.suse.com/t/firewall-rules-for-updates-and-patches/28554/2 "2016-08-23T12:47:09Z")

</div>

The patches all come in via HTTPS, so I believe TCP 443 is the only port  
that SLES will access, and that would be a solicited response, so no  
unsolicited inbound ports need to be open on your SLES box.

Which addresses… well patches come from a content distribution network,  
so I do not know exactly how precise that can be. Maybe somebody else does.

–  
Good luck.

If you find this post helpful and are logged into the web interface,  
show your appreciation and click on the star below…

---

<div class="post-metadata">

**Author:** ![cr\_ibix](https://avatars.discourse-cdn.com/v4/letter/c/cab0a1/32.png) [@cr\_ibix](https://forums.suse.com/u/cr_ibix)\
**Post date:** [August 23, 2016, 2:33pm UTC](https://forums.suse.com/t/firewall-rules-for-updates-and-patches/28554/3 "2016-08-23T14:33:03Z")

</div>

Thank you very much. Maybe you know the domain the CDN have? Maybe all servers are reachable under [https://_.suse.com/_](https://.suse.com/) or soemthing like this?

---

<div class="post-metadata">

**Author:** ![ab1](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@ab1](https://forums.suse.com/u/ab1)\
**Post date:** [August 23, 2016, 3:33pm UTC](https://forums.suse.com/t/firewall-rules-for-updates-and-patches/28554/4 "2016-08-23T15:33:33Z")

</div>

Section 4.3 of the SUSE Mahager documentation  
[https://www.suse.com/documentation/suse-manager-3/singlehtml/suse\_manager21/book\_susemanager\_install/book\_susemanager\_install.html#sec.manager.inst.setup](https://www.suse.com/documentation/suse-manager-3/singlehtml/suse_manager21/book_susemanager_install/book_susemanager_install.html#sec.manager.inst.setup)  
has the following information:

```auto
Note: Accessing SCC scc.suse.com

scc.suse.com uses proxy technologies to provide a fast download service
world-wide. Depending on the location, the real hostname and the IP
address is different.

To correctly setup company firewalls, to allow access to the repositories,
check which proxy you are using with the following command:

nslookup scc.suse.com
```

–  
Good luck.

If you find this post helpful and are logged into the web interface,  
show your appreciation and click on the star below…
