# Domains required for Agent communication
## Domains required for Agent communication
This document provides the list of approved domains and IP addresses which are required for seamless agent-server communication.
- [Domain Whitelist](https://www.manageengine.com/desktop-management-msp/help/cloud/server/domains-required-for-agent-communication.html#approved-domain-a)
- [IP Whitelist](https://www.manageengine.com/desktop-management-msp/help/cloud/server/domains-required-for-agent-communication.html#approved-ip-a)
### Domain Whitelist
Communication across remote offices is possible in the following ways:
- [Endpoint Central MSP domains to be excluded in Roaming agent](https://www.manageengine.com/desktop-management-msp/help/cloud/server/domains-required-for-agent-communication.html#roaming-users-a)
- [Endpoint Central MSP domains that should be whitelisted in the domain itself](https://www.manageengine.com/desktop-management-msp/help/cloud/server/domains-required-for-agent-communication.html#distribution-server-a)
- [The following domains should be whitelisted in agents that are under the distribution server.](https://www.manageengine.com/desktop-management-msp/help/cloud/server/domains-required-for-agent-communication.html#ds-agents-a)
**Endpoint Central MSP domains to be excluded in Roaming agent**
Roaming users directly contact the cloud server. Since these users are constantly roaming, they can't be managed by a central server. Therefore, the roaming agents should connect to these websites:
**Endpoint Central MSP domains that should be whitelisted in the domain itself**
Distribution server is a component which allows you to download patch binaries from the respective vendor websites and distribute it to all the remote office computers managed under the DS. The Distribution server should connect to these websites:
**The following domains should be whitelisted in agents that are under the distribution server.**
The agents which belong to remote office/WAN should connect to these domains:
### IP Whitelist
Here's the list of IP addresses that are required to be added to the whitelist
### Ports
These Ports must be enabled for communication between the agent and the server
| Port | Purpose | Type | Connection |
|---|---|---|---|
| 443 | For communication between the agent or distribution server and the Endpoint Central MSP server.
Source: Agent/Distribution server
Destination: Endpoint Central MSP server | HTTPS | Outbound from Agent/DS |
| 443 | The Notification server port is responsible for communicating on-demand operations from the server to the agent.
Source: Agent/Distribution server
Destination: Notification server | WSS | Outbound from Agent/DS |
| 8384 | For communication between remote agent and distribution server
Source: Agent
Destination: distribution server | HTTPS | Inbound to distribution server
Outbound from Agent/DS |
### Module Wise Configurations
Refer to [this page](https://www.manageengine.com/products/desktop-central/help/configuring_desktop_central/domains-required-for-patching.html) to know about domains required for patching.
**Note:** If agents are managed through a Distribution Server, the domains listed must be whitelisted on the Distribution Server. If no Distribution Server is configured, the exclusions should be applied directly on the agent.
### Exclusions (File Extensions) to be made in Endpoint Central MSP Agents and Distribution Server
The below file extensions must be excluded in the Endpoint Central MSP Agent/Distribution Server for patch detection, deployment and other agent functionalities.
| Windows | Mac | Linux |
|---|---|---|
| .xml, .xml.gz, .gz, .7z, .Json, .zip, .Json.gz, .dll.gz, .exe, .exe.gz, .crt, .pem, .json, .properties, .xz, .tar, .tar.gz, .svg, .gif, .bin, .txt, .list, .ISO, .yaml.gz, .yml.gz, .repo, .bz2, .config, .conf, .manifest, .BAT, .VBS, .PY | .json, .plist, .properties, .xml, .py, .sh, .scpt, .pl, .command, .7z, .bz, .bz2, .gz, .pkg, .mpkg, .tar, .tar.gz, .xml.gz, .zip, .jpg, .gif, .png, .mobileconfig, .otf, .ttf | .json, .xml, .zip, .xz, .tar, .tar.gz, .gz, .bin, .py, .bz, .properties, .xml.gz, .repo, .sh, .bash, .ksh, .csh, .tcsh |