Overview
Because the DSPM (also known as Netskope One DSPM) application is hosted and managed by Netskope (instead of being self-hosted), you may need to update your firewall/security group settings in order for Netskope DSPM to connect to your Data Stores.
– For Direct Connections (no sidecar): Apply the rules in the DSPM Application Egress section.
– For Single Appliance Deployments: Apply the rules in the DSPM Application Egress, Sidecar Egress and Ports, and DLP Service Egress sections. All three apply to the same host.
– For Distributed Deployments (separate sidecars + DLP appliance): Apply the rules in the Sidecar Egress and Ports and DLP Service Egress sections to their respective hosts.
DSPM Application Egress
All Data Store scans will originate from these IP addresses, so you need to whitelist them:
| 35.86.53.159 |
| 44.226.200.72 |
| 44.236.251.30 |
| 44.243.172.80 |
| 52.27.197.60 |
| 52.27.67.30 |
| 52.39.117.251 |
| 52.39.99.174 |
| 52.40.249.64 |
| 52.43.227.202 |
| 54.189.99.166 |
| Home POP | CIDR |
|---|---|
| SJC1 | 18.98.10.112/28 |
| SJC2 | 18.98.10.112/28 |
| SV5 | 18.98.10.112/28 |
| DFW3 | 18.98.10.112/28 |
| AM2 | 18.96.33.16/28 |
| FR4 | 18.96.33.16/28 |
| FRA2 | 18.96.33.16/28 |
| ZUR2 | 18.98.224.160/28 |
| LON3 | 18.98.162.192/28 |
| SIN2 | 18.99.40.96/28 |
| MEL2 | 18.98.196.32/28 |
Sidecar Egress and Ports
If you are using sidecars to connect with your Data Stores, you may need to update your firewall/security group settings in order to provide outbound egress for sidecars to communicate with DSPM.
Additionally, in the distributed deployment model, the sidecar must be able to communicate with the DLP appliance via HTTPS (port 443). In the Single Appliance model, this communication happens locally on the same host.
For more information, please visit any of our sidecar installation articles in the Netskope DSPM Deployment Guides.
DLP Service Egress
The DLP appliance requires its own outbound egress to the internet. This connectivity is necessary for the appliance to validate its license and download configurations.

