Skip to content

Network & Connectivity

Monozu Cloud is hosted by Monozu at cloud.monozu.io. Your organization does not deploy the cloud stack. Edge appliances at your sites are supplied by Monozu; this page lists what your network team must allow for browsers, those appliances, and optional integrations. For on-site setup, see Connect & Register.

Allow outbound HTTPS from your site and from user workstations to:

HostUsed byPurpose
cloud.monozu.ioBrowsers, edge appliancesWeb app, control plane (registration, config, commands)
ingest.cloud.monozu.ioEdge appliancesTelemetry, logs, alerts, discovery uploads
VPN Hub hostname (provided at onboarding)Edge appliances, VPN clientsWireGuard remote access

The exact VPN Hub hostname is provided by Monozu during onboarding and may appear in Settings for your tenant.

SourceDestinationProtocolNotes
Edge applianceCloud hosts aboveHTTPS (443)Always outbound from customer site
Edge applianceVPN HubWireGuard (UDP)Outbound; no inbound port forwarding on the appliance
User browsercloud.monozu.ioHTTPS (443)Standard web access
User browserCloudWSS (443)Real-time VPN session status and security alert inbox
  • Browsers and edge appliances must trust the certificate chain presented by Monozu endpoints.
  • If you terminate TLS on a corporate proxy, allowlist the hosts above or configure the proxy to pass through without breaking certificate pinning used by the edge agent.
  • Test from a representative VLAN after any proxy policy change.

Ensure forward DNS resolution works for all hosts your deployment uses. Blocklists or split-horizon DNS that resolve Monozu hosts to incorrect IPs will break registration and ingest.

Each customer organization (tenant) has separate data in Monozu Cloud. Users only see assets, incidents, and settings for their tenant. Cross-tenant access is not available to tenant administrators.