Firewall, proxy and local-network connectivity requirements for DisplayNote Montage receivers and clients.
Key point
Montage devices initiate outbound connections to DisplayNote cloud services. The requirements below are egress rules; they are not a request to expose inbound services from the public internet. Local discovery and casting traffic is listed separately, as it applies only within the LAN.
1. Required cloud destinations (FQDNs)
Use FQDN-based rules where your firewall supports them. DisplayNote's cloud infrastructure is dynamically provisioned, so the underlying IP addresses can change as services scale, fail over, or are rebalanced.
| FQDN | Purpose / scope |
|---|---|
| netcheck.joinmontage.com | Connectivity and network checks |
| *.displaynote.com | DisplayNote cloud services, including signalling and STUN/TURN infrastructure |
| app.broadcast.online | Broadcast cloud service |
2. Outbound cloud connectivity
Allow the receiver and client devices to initiate outbound connections to the following destinations and ports.
| Protocol / port | Required destination |
|---|---|
| TCP 80 | netcheck.joinmontage.com, *.displaynote.com, app.broadcast.online |
| TCP 443 | netcheck.joinmontage.com, *.displaynote.com, app.broadcast.online |
| UDP 3478 | *.displaynote.com |
| TCP 1935 | *.displaynote.com |
| TCP 7881 | *.displaynote.com |
| TCP 7885 | *.displaynote.com |
| TCP 5080 | *.displaynote.com |
| UDP 41152–65535 | *.displaynote.com |
| TCP 41152–65535 | *.displaynote.com |
Why the dynamic range is required
Ports 41152–65535 are used for dynamic media port allocation during the ICE connection process. STUN determines whether a direct path is available; when a direct connection can't be established, TURN relays the encrypted media traffic and dynamically allocates ports from this range. Because of this, a single fixed media port cannot be specified in advance.
Dynamic STUN/TURN server list: Montage fetches its list of STUN/TURN servers from a dedicated API rather than using a fixed set. This improves the reliability and performance of the casting experience in complex network environments by helping devices find the optimal path for peer-to-peer communication, and it requires no extra configuration from IT administrators.
If Layer 7 filtering or protocol-aware proxying is applied to the ports above, make sure the following protocols are allowed: HTTP, HTTPS, DTLS, XMPP, Bonjour protocols, SRTP, DNS, STUN, TURN, and ICE.
3. Local network discovery and casting
The following traffic is local to the LAN and separate from the outbound cloud requirements above. It should not be interpreted as a requirement to open these ports on your internet-facing firewall — these allowances are only relevant when the corresponding local discovery or casting feature is used.
| Protocol / port | Local use |
|---|---|
| UDP 5353 | mDNS / local service discovery |
| TCP 7000, 7100 | AirPlay-related local connectivity |
Miracast and Chromecast: if these local casting features are enabled in your deployment, additional LAN discovery and streaming traffic may be required by the underlying protocol and device implementation. These are local-network allowances and are not part of the DisplayNote cloud egress allowlist above.
4. Firewall and proxy guidance
- Outbound only: the cloud rules describe connections initiated by Montage clients and receivers. No unsolicited inbound internet access is required.
- FQDN allowlisting: use the FQDNs above rather than fixed IP addresses, where your firewall platform supports it.
- Segmented networks: if the sender and receiver sit on separate VLANs or security zones, direct openings between those segments aren't required for cloud-relayed connectivity — each endpoint connects outbound to the DisplayNote cloud independently.
- Proxy / Layer 7 inspection: if HTTPS traffic is proxied or inspected, make sure the required DisplayNote services and protocols aren't blocked or altered.
The Montage Windows/macOS software supports the following proxy configurations:
- HTTP Proxy (with or without authentication)
- SOCKS 5 (with or without authentication)
- Proxy with Auto-Configuration File (PAC) — Windows only
- System proxy — Windows only
5. Regions and hosting
- API and signalling: Azure — West Europe
- Broadcasting services (AWS): West Europe, New York, San Francisco
- Media relay (AWS): Ireland (Dublin), India (Mumbai), US East Coast (New York/New Jersey area), US West Coast (San Francisco/Santa Clara), Singapore
Need help validating a deployment?
DisplayNote Support can review the firewall, proxy and LAN requirements for your network topology and help confirm which rules apply.
Comments
0 comments
Please sign in to leave a comment.