Amwell Hospital Carepoint Firewall Rules

This article refers to all Amwell Proprietary Hardware devices - C250, C500, TV Kit 100

Firewall requirements

Amwell Hospital Carepoints must be placed on a network that follows the rules listed below to allow for the appropriate incoming and outgoing traffic. Please supply your network administrator with these details. 

The following mandatory firewall permissions are needed for application functionality.

  • Firewall and Domain Permissions:
    • See the table below for specific domains and IP’s (where available) that need to be whitelisted on your network
  • Ports:
    • The firewall must be configured for outbound HTTP/HTTPS requests on ports listed in the table below

Amwell Hospital Carepoints employ an explicit firewall allow-listing protocol that restrict all traffic on the
device to specific domains and ports.

Required Service Host Protocol Ports Resource Rule

Mandatory

Standard web, redirect to HTTPS *.avizia.com / *.avizia.io TCP 80 WebRTC calls, case creation, American Well Clinical Module Outgoing, established
Mandatory Secure Web

*.avizia.com / *.avizia.io

  • 54.172.60.0-54.172.61.255
  • 34.203.250.0-34.203.251.255
  • 54.244.51.0 - 54.244.51.255
TCP 443 Secure WebRTC calls Outgoing, Inbound
Mandatory    Update Service *.s3.amazonaws.com TCP 443 Application Update Service  Outgoing, Inbound
Mandatory DNS

Google DNS Servers:

  • 8.8.8.8
  • 4.4.4.4
UDP 53 Domain Name Service Outgoing
Recommended TCP

*.clamav.net

UDP 80, 443 Antivirus Signature Database updates (ClamAV Antivirus) Outgoing
Mandatory NTP

pool.ntp.org

TCP 123

Network Time Protocol

Outgoing
Highly Recommended WebRTC

*.avizia.io

TCP, UDP

33000-33499

40000-49999

Preferred Media Servers, best way to whitelist all servers.

Outgoing, established
Mandatory -  Select either Preferred Media servers (recommended) or STUN/TURN servers. 

Preferred Media (RTP / RTCP ) 

 

  • 18.204.64.0-31
  • 18.207.64.121
  • 34.197.115.173
  • 34.197.150.170
  • 34.227.122.4
  • 34.227.122.4
  • 52.45.34.112
  • 52.45.39.156
  • 18.204.64.21
  • 18.204.64.22
  • 18.204.64.23
  • 18.204.64.24
  • 18.204.64.25
  • 18.204.64.26
  • 18.204.64.27
  • 18.211.52.109
  • 18.213.174.39
  • 18.232.19.174
  • 184.72.160.181
  • 23.21.107.38
  • 3.208.130.218
  • 3.222.53.94
  • 3.224.176.73
  • 3.227.223.125
  • 3.228.161.51
  • 34.192.247.143
  • 34.193.245.37
  • 34.195.10.252
  • 34.198.169.26
  • 34.199.81.209
  • 34.200.22.65
  • 34.225.222.244
  • 34.230.136.95
  • 34.232.0.86
  • 34.232.14.147
  • 35.168.195.217
  • 35.168.217.157
  • 35.170.175.232
  • 50.19.207.165
  • 52.1.227.220
  • 52.20.107.20
  • 52.20.130.77
  • 52.20.93.110
  • 52.203.167.103
  • 52.205.163.92
  • 52.205.204.151
  • 52.206.134.222
  • 52.22.214.169
  • 52.22.34.32
  • 52.23.59.95
  • 52.23.7.230
  • 52.45.147.98
  • 52.45.203.222
  • 52.5.222.231
  • 52.72.189.250
  • 54.165.213.9
  • 54.173.28.112
  • 54.175.199.101
  • 54.235.119.232
  • 18.205.132.106
  • 18.208.1.134
  • 18.234.13.247
  • 18.235.238.80
  • 3.219.236.107
  • 3.222.68.91
  • 3.224.89.6
  • 3.231.187.184
  • 3.81.178.239
  • 34.198.118.110
  • 34.198.155.144
  • 34.200.118.224
  • 34.204.230.253
  • 34.205.227.147
  • 34.231.53.231
  • 34.233.104.108
  • 34.234.53.18
  • 52.20.119.210
  • 52.20.171.7
  • 52.23.39.75
  • 52.44.2.73
  • 52.71.213.142
  • 54.157.4.151
  • 54.205.195.32
  • 54.86.41.103
  • 3.235.111.0/27
  • 3.235.111.64/26
  • 3.238.211.64/27
  • 34.75.154.64/26
  • 34.75.18.64/26
  • 34.75.114.64/26
UDP & TCP

40000-49999

33000-33499

Use for best performance and quality Outgoing, Inbound

Media (STUN/TURN)*

 

  • 54.172.60.0-54.172.61.255
  • 34.203.250.0-34.203.251.255
  • 54.244.51.0 - 54.244.51.255
UDP & TCP 443, 3478 (UDP & TCP) 5349 (TCP) Reduces number of ports required, however, increases connection time.  Outgoing, Inbound

2/19/21 Update: Added IP addresses for Conference Servers in Bold.

* Fail-over in case 40000-49999 cannot establish connection.
** If using the Amwell Hospital Carepoint outside of the United States, please consult your Implementation Manager.
† For the most restrictive networks. Note that you will see a performance degradation in video
quality.

Was this article helpful?
0 out of 0 found this helpful
Have more questions? Submit a request