WHITECORE.AI

For your IT department

Firewall Rules & Notes

The ports, hostnames and local camera rules an IT administrator needs to allow WhiteCore dashboard access, media delivery, player connectivity and Vision AI.

Outbound connections onlyNo inbound internet portsFQDN allow-list recommended

WhiteCore does not require public inbound access

Do not create inbound firewall rules, internet-facing router port forwards or public camera/NVR ports. The browser and each WhiteCore media player initiate secure outbound connections. Camera traffic stays on the customer's private LAN or VLAN.

Internet access

Cloud and internet allow-list

These rules apply to the customer's browser and each WhiteCore media player. “Outbound” means from the customer network to the listed destination.

WhiteCore dashboard

Required
Direction
Outbound
Protocol
HTTPS / TCP
Port
443
Destination
app1.dev.whitecore.ai

Sign-in and web dashboard access.

WhiteCore API, live preview and remote support

Required
Direction
Outbound
Protocol
HTTPS + WSS / TCP
Port
443
Destination
api1.dev.whitecore.ai

Pairing, heartbeats, commands, analytics, preview and secure support. Permit WebSocket Upgrade.

Media, maps and player updates

Required
Direction
Outbound
Protocol
HTTPS / TCP
Port
443
Destination
whitecore-app1-media.nyc3.digitaloceanspaces.com

Uploads, content downloads, venue maps, screenshots and signed player updates.

WhiteCore website, help and installers

Required
Direction
Outbound
Protocol
HTTPS / TCP
Port
443
Destination
whitecore.ai, www.whitecore.ai

Public website, documentation and installer downloads.

Player installation dependencies

Install / repair
Direction
Outbound
Protocol
HTTPS / TCP
Port
443
Destination
whitecore-dev-website.nyc3.cdn.digitaloceanspaces.com

Downloads signed WhiteCore player dependencies during installation or repair.

WhiteCore interface fonts

Required
Direction
Outbound
Protocol
HTTPS / TCP
Port
443
Destination
fonts.googleapis.com, fonts.gstatic.com

Loads the approved interface and Studio presentation fonts.

Weather widget

When used
Direction
Outbound
Protocol
HTTPS / TCP
Port
443
Destination
geocoding-api.open-meteo.com, api.open-meteo.com

Resolves a location and retrieves live weather for presentations.

Stripe billing

Billing users
Direction
Outbound
Protocol
HTTPS / TCP
Port
443
Destination
checkout.stripe.com, billing.stripe.com, js.stripe.com, api.stripe.com

Secure plan checkout, payment-method and subscription management.

DNS resolution

Required
Direction
Outbound
Protocol
DNS / UDP + TCP
Port
53
Destination
Your organisation's approved DNS resolvers

Resolves WhiteCore and content hostnames through the organisation's normal resolver.

System time

Required
Direction
Outbound
Protocol
NTP / UDP
Port
123
Destination
Your organisation's approved NTP service

Keeps TLS certificates, 2FA codes, schedules and reporting times accurate.

Customer web pages and IPTV

When used
Direction
Outbound
Protocol
HTTPS / TCP
Port
443
Destination
Customer-selected webpage, HLS and IPTV hostnames

Allows Studio webpage and IPTV widgets to load. TCP 80 is needed only for an explicitly configured HTTP source.

Private network

Local camera and NVR access

Permit only the WhiteCore media-player IP or VLAN to reach the required RTSP port. Never publish these camera ports to the internet.

USB camera

None
Direction
Device local
Protocol
USB
Destination
Camera attached directly to the WhiteCore media player

No firewall or network-camera rule is required.

UniFi Protect NVR

7447
Direction
Media player → camera/NVR LAN
Protocol
RTSP / TCP
Destination
Local UniFi console/NVR IP address

WhiteCore converts the copied UniFi RTSPS 7441 share link to the supported local RTSP 7447 stream.

Dahua, Hikvision, Axis or generic RTSP

554 (default)
Direction
Media player → camera/NVR LAN
Protocol
RTSP / TCP
Destination
Local camera or NVR IP address

Use the configured RTSP port if the installer changed the default. WhiteCore forces RTSP over TCP.

Proxy and security notes

  • Permit WebSocket Upgrade over TCP 443 to api1.dev.whitecore.ai.
  • Do not rewrite or cache short-lived signed media and player-update URLs.
  • Bypass TLS inspection for listed WhiteCore hosts if it interferes with login, WebSockets or downloads.
  • Allow-list hostnames, not fixed IP addresses; cloud endpoints may change.

If WhiteCore cannot be reached

  1. 1.Confirm the device can resolve all WhiteCore hostnames through DNS.
  2. 2.Confirm outbound TCP 443 and WebSockets are not blocked.
  3. 3.Confirm the device date, time and timezone are accurate.
  4. 4.For cameras, confirm the media player can reach the camera/NVR IP on its local port.

Need help with an enterprise firewall?

Send your IT team this page or contact WhiteCore before installation.

Contact support