Allowlist requirements for IP addresses and URLs

Datto RMM requires that you review and configure your and your customer's infrastructure to allow it to work at its full potential. This is especially true because of the ever-present inclusion of firewalls and robust antivirus programs that keep your devices safe.

Proper allowlisting configuration for Datto RMM requires you to follow a multi-step process, ensuring that you allow Datto RMM access to all needed information on managed devices, while still keeping them safe.

This article outlines the requirements for allowing Datto RMM the network access it needs to work at its full potential if devices are behind a firewall, as well as additional information related to network connectivity for various Datto RMM functions.

By default, this page shows information for all Datto RMM platforms. To only show information related to one platform, where relevant, select your platform from the drop-down below: 

Required allowlisting for Datto RMM

IMPORTANT  To ensure the networks your managed devices are on are properly configured, follow the steps below in order.

Allowlisting step Description
Step 1: Inbound traffic Allow inbound traffic from Datto RMM to your managed devices. For more information, refer to Allowing the Datto RMM Agent access to the internet.
Step 2: Outbound traffic Configure outbound rules to allow your managed devices to send information to the Datto RMM service. Refer to IP addresses and FQDNs per platform.

Step 3: Datto RMM web interface

Allow access to the Datto RMM web interface, refer to Connecting to the Datto RMM web interface. You can also learn how to allow UI access on restricted networks in this section.
Step 4: Web Remote Allow Web Remote to connect to your remote devices, refer to Web Remote communication.
Step 5: Datto RMM processes and services Allow Datto RMM services and processes to access the internet. Refer to Inbound and outbound rules.
Step 6: Ports Various ports are used for key Datto RMM functions. Refer to Port usage.

Allowing the Datto RMM Agent access to the internet

Allowlisting for additional Datto RMM functions

Allowlisting information is available for the following additional features in Datto RMM: 

Additional information

Information on the following topics can be reviewed below: 

  • Temporary directory location: Many operations performed by Datto RMM do not use the operating system's (OS) default temp folder location. Refer to Change of temporary directory.
  • Connecting agents through the tunnel grid: To learn more about how connections are established with remote Agents, refer to Connecting Agents through the tunnel server grid.
  • UI access on restricted networks: In certain cases, depending on your network setup, users may be locked out of accessing the UI. To learn how to resolve this, refer to UI access on restricted networks.
  • AV Exclusions: Depending on your antivirus, you may need to set up exclusions to certain file or folder locations to ensure Datto RMM can operate uninterrupted. Refer to Folders and file paths used by Datto RMM.
  • Receiving emails from Datto RMM: To ensure you are not blocking emails from Datto RMM, ensure you are not blocking emails from the rmm.datto.com email domain.

    EXAMPLE  alerts@rmm.datto.com for alerts, reports@rmm.datto.com for reports, etc.

  • Internet protocol: The Datto RMM Agent communicates with the platform using the IPv4 protocol

    NOTE  IPv6 connections are not supported at this time

  • Stateful packet inspection: It is strongly recommended that any Stateful Packet Inspection be turned off for access to any centrastage.net address, and that all attempts possible are made to guarantee that TCP connections to the cc.centrastage.net addresses are not terminated in cases of inactivity (these connections may be inactive for up to 180 seconds at a time if no client activity is detected).
  • Blocklist: Some countries are not permitted access to the Datto RMM web interface. For more information, refer to Blocklist.