3.6 Network & Firewall Requirements
When deploying Flocks in a restricted network, allow the minimum access required for the actual scenario. The table below is intended for customer firewall or security group configuration. ThreatBook domains list the currently complete resolved IPs; other public domains list a current partial set of resolved IPs.
Local or Internal Network Access to Flocks
- Client access to Flocks WebUI and same-origin API: 5173/tcp
- The API path is under
/apion the unified service entry point. There is no need to additionally open 8000/tcp. - If a reverse proxy is placed in front, allow 80/443 according to the actual proxy address.
| Online Installation: Mainland China Path (using the install_zh script) | ||||
|---|---|---|---|---|
| Target IP | Protocol | Port | Access Description | Domain |
180.76.198.77180.76.198.225180.76.199.13 | tcp | 443 | Source code and installation script download | gitee.com |
155.102.209.201155.102.209.202155.102.209.203 | tcp | 443 | Python package download | mirrors.aliyun.com |
155.102.209.201155.102.209.202155.102.209.203 | tcp | 443 | npm package download | registry.npmmirror.com |
155.102.209.201155.102.209.202155.102.209.203 | tcp | 443 | Browser dependency download | cdn.npmmirror.com |
62.146.173.132 | tcp | 443 | uv installation script download | astral.org.cn |
104.21.25.131172.67.134.65 | tcp | 443 | uv backup source | uv.agentsmirror.com |
104.26.12.77104.26.13.77172.67.68.3 | tcp | 443 | uv official fallback source | astral.sh |
| Online Installation: International Path (using the install script) | ||||
| Target IP | Protocol | Port | Access Description | Domain |
20.27.177.113 | tcp | 443 | Source repository, archives, and Release download | github.com |
185.199.108.133185.199.109.133185.199.110.133 | tcp | 443 | One-click installation script and nvm installation script download | raw.githubusercontent.com |
151.101.0.223151.101.64.223151.101.128.223 | tcp | 443 | Python package download | pypi.org |
104.16.0.34104.16.1.34104.16.2.34 | tcp | 443 | npm package download | registry.npmjs.org |
104.26.12.77104.26.13.77172.67.68.3 | tcp | 443 | uv installation script download | astral.sh |
104.16.212.131104.16.213.131 | tcp | 443 | Node.js package download | nodejs.org |
| ThreatBook Capabilities | ||||
| Target IP | Protocol | Port | Access Description | Domain |
106.75.20.76 | tcp | 443 | Call ThreatBook model service | llm.threatbook.cn |
165.154.193.42 | tcp | 443 | Call ThreatBook model service | llm.threatbook.io |
106.75.9.53106.75.12.3117.50.12.40117.50.19.28 | tcp | 443 | X community, onboarding page, or service access | x.threatbook.com |
199.60.103.26199.60.103.126 | tcp | 443 | Onboarding page or service access | threatbook.io |
106.75.36.224106.75.36.226123.59.51.113123.59.72.253 | tcp | 443 | MCP service access | mcp.threatbook.cn |
106.75.93.64 | tcp | 443 | Check intelligence updates | static.threatbook.cn |
106.75.86.162106.75.109.189 | tcp | 443 | Download intelligence updates | static-js.threatbook.cn |
106.75.109.119 | tcp | 443 | Cloud static resources | static-css.threatbook.cn |
117.50.2.211 | tcp | 443 | Platform update resources | static-img.threatbook.cn |
106.75.36.224106.75.36.226123.59.51.113123.59.72.253 | tcp | 443 | Threat intelligence cloud API | api.threatbook.cn |
106.75.21.133106.75.62.233106.75.85.91106.75.87.106 | tcp | 443 | Cloud sandbox | s.threatbook.com |
| Flocks Pro Cloud Account | ||||
| Target IP | Protocol | Port | Access Description | Domain |
106.75.36.224106.75.36.226123.59.51.113123.59.72.253 | tcp | 443 | Cloud account login page | passport.threatbook.cn |
106.75.19.23 | tcp | 443 | Console API, login exchange, heartbeat, and node sync | portalflocks.threatbook.cn |
| Flocks Hub Online Download | ||||
| Target IP | Protocol | Port | Access Description | Domain |
106.75.19.23 | tcp | 443 | Cloud plugin catalog, plugin package download, or enterprise delivery Hub download service | portalflocks.threatbook.cn |
20.27.177.113 | tcp | 443 | GitHub repository and source download | github.com |
20.27.177.116 | tcp | 443 | GitHub catalog API | api.github.com |
20.27.177.114 | tcp | 443 | GitHub source archive download | codeload.github.com |
185.199.108.133185.199.109.133185.199.110.133 | tcp | 443 | GitHub raw file download | raw.githubusercontent.com |
185.199.108.133185.199.109.133185.199.110.133 | tcp | 443 | GitHub large file resource download | objects.githubusercontent.com |
185.199.108.154185.199.109.154185.199.110.154 | tcp | 443 | GitHub Release asset download | github-releases.githubusercontent.com |
216.150.1.1 | tcp | 443 | clawhub Skill search | clawhub.com |
104.18.10.59104.18.11.59 | tcp | 443 | clawhub Skill package download | wry-manatee-359.convex.site |
64.239.109.12964.239.123.1 | tcp | 443 | skills.sh Skill search or resolution | skills.sh |
64.239.109.6564.239.123.129 | tcp | 443 | skills.sh Skill search or resolution | www.skills.sh |
106.75.6.154 | tcp | 443 | SafeSkill CLI search or download | safeskill.cn |
| IM Channels | ||||
| Target IP | Protocol | Port | Access Description | Domain |
139.177.246.206139.177.246.207 | tcp | 443 | Feishu bot or open-platform API | open.feishu.cn |
173.222.248.68173.222.248.72 | tcp | 443 | Lark international bot or open-platform API | open.larksuite.com |
161.117.70.119 | tcp | 443 | DingTalk bot or open-platform API | api.dingtalk.com |
43.163.165.94 | tcp | 443 | WeCom bot WebSocket / callback capability | openws.work.weixin.qq.com |
| Resolve according to the MCP Host returned by WeCom | tcp | 443 | MCP URL returned by the WeCom wecom_mcp runtime | Resolve according to the MCP Host returned by WeCom |
43.163.165.18743.163.179.90 | tcp | 443 | WeChat channel | ilinkai.weixin.qq.com |
114.221.149.151114.222.112.72121.229.91.162 | tcp | 443 | WeChat channel CDN | novac2c.cdn.weixin.qq.com |
| Resolve according to Slack service | tcp | 443 | Slack API and Socket Mode WebSocket | slack.comapi.slack.comwss.slack.com |
149.154.166.110 | tcp | 443 | Telegram Bot API | api.telegram.org |
| Resolve according to customer mail service | tcp | 993587465 | Email integration IMAP receiving and SMTP sending | Customer email provider or enterprise email IMAP / SMTP domain |
IP resolution results may change with DNS scheduling. If the egress policy supports domain allowlists, allow by domain first. If IP allowlisting is the only option, use the resolution results from the customer site.
Minimum Required Runtime Egress
- Allow the Flocks unified service port plus the model service Host.
- Open other network domains only as required by actual usage.