Configuring your firewall
Version:
| Applies to | Content Management and Content Delivery |
|---|
You must always keep your Content Management (CM) and Content Delivery (CD) roles secure behind a firewall. The firewall requirements differ between the two roles and are described below.
- Content Management role - The CM role must not be publicly accessible. Restrict all inbound access to trusted IP addresses only, for example, the IP ranges of your internal network or VPN. Use IP allowlisting at the firewall or network level to enforce this. Unauthorized inbound access to CM must be blocked by default.
- Content Delivery role - The CD role must be publicly accessible so that it can serve website content to visitors. Your firewall must allow inbound HTTP/HTTPS traffic from any source. All other inbound traffic to the CD role should be blocked.
Both CM and CD must be able to reach essential Sitecore cloud services. The following topics describe the specific outbound rules required for each service:
- Configure Sitecore Device Detection for the CD and Processing roles.
- Set up Sitecore IP Geolocation for the CD role.
- Use the EXM Delivery Cloud service for the CM and Dedicated Dispatch Server roles.
- The Update Center
If you create a Support Package, and you want to analyze it with the Sitecore Diagnostics Service, you must open your firewall for https://diagnostics.cloud.sitecore.net.
If you do not have enough seat licenses, and you want to temporarily boost the seat limit, you must open your firewall for http://www.sitecore.net/boost/queryboost.aspx.
If you have suggestions for improving this article, let us know!