Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Netskope Private Access
    Local Broker Management
    Deploy a Local Broker
    Local Broker Requirements and Recommendations

    Local Broker Requirements and Recommendations

    Before deploying a Local Broker, factor these requirements and recommendations:

    Hardware Requirements

    CPU CoresRAMHDD
    48 GB (minimum)
    16 GB (recommended)
    50 GB (minimum)
    80 GB (recommended)

    The Local Broker OVA and Hyper-V are built on top of Ubuntu 22.04.

    Important

    A Local Broker needs to be installed as a separate instance. Installing the Local Broker on a Publisher instance is not supported.

    Software Requirements

    • Client: v131 or above.
    • Publisher: v131 or above.
    • Local Broker: v133 or above.

    Connectivity Requirements

    ComponentSourceDestinationServiceActionNotes
    Management AccessAdmin IP subnetsLocal Broker IPs/hostnameSSH (TCP/22)AllowAllow TCP 22 from sources where SSH connectivity (management) is required.
    ClientClient IP subnetsLocal Broker IPs/hostnameHTTPS (TCP/443)
    TCP 2443
    AllowAllow TCP 443 from internal subnets where clients would connect to the LBR Client Gateway.
    Allow TCP 2443 from internal subnets where clients would connect to the LBR Client Gateway. This is needed when Latency Based Local Broker selection is enabled.
    PublisherPublisher IPsLocal Broker IPs/hostnameTCP 1443
    TCP 2443
    AllowAllow TCP 1443 from internal subnets from where Publishers would connect to the LBR Publisher Gateway (Stitcher).
    Allow TCP 2443 from internal subnets from where Publishers would connect to the LBR Publisher Gateway (Stitcher). This is needed when Latency Based Local Broker selection is enabled.
    Local BrokerLBR1, LBR2LBR1, LBR2TCP 5000AllowAllow TCP 5000 bi-directional between Local Brokers for inter Local Broker connectivity.
    Local BrokerLBR IPsNTP Server(s)NTP UDP 123AllowAllow NTP outbound from a Local Broker.
    Local BrokerLBR IPsDNS ResolverDNSAllowAllow DNS outbound from a Local Broker.
    Local BrokerLBR IPs
    • *.docker.com
    • *.docker.io
    • *.ubuntu.com
    • *.k8s.io
    • *.pkg.dev
    • events.goskope.com
    • events.govskope.us (for Netskope NewEdge Government - US tenants)
    • events.govskope.ca (for Netskope NewEdge Government - CA tenants)
    • api.snapcraft.io
    • .cdn.snapcraftcontent.com
    •  ns-<tenant-ID>.<POP-name>.npa.goskope.com
    • ns-<tenant-id>.lbr.<POP-name>.npa.goskope.com
    • ns-<tenant-id>.lbr.<POP-name>.npa.govskope.us (for Netskope NewEdge Government - US tenants)
    • ns-<tenant-id>.lbr.<POP-name>.npa.govskope.ca (for Netskope NewEdge Government - CA tenants)
    • redis.lbr.<POP-name>.npa.goskope.com
    • redis.lbr.<POP-name>.npa.govskope.us (for Netskope NewEdge Government - US tenants)
    • redis.lbr.<POP-name>.npa.govskope.ca (for Netskope NewEdge Government - CA tenants)
    • s3.us-west-2.amazonaws.com (for the installer script)

    Contact your Netskope SE, TSM, or Support for your tenant-ID and POP-name, and if IP subnets are needed instead of FQDNs.

    HTTPS

    Note

    HTTP (for *.ubuntu.com only)

    TCP 443 (HTTPS) and TCP 8443 (HTTPS) for ns-<tenant-id>.lbr.<POP-name>.npa.govskope.us (for Netskope NewEdge Government - US tenants).

    TCP 443 (HTTPS) and TCP 8443 (HTTPS) for ns-<tenant-id>.lbr.<POP-name>.npa.govskope.ca (for Netskope NewEdge Government - CA tenants).

    TCP 443 (HTTPS) and TCP 8443 (HTTPS) for ns-<tenant-id>.lbr.sa-ruh1.npa.goskope.com (for Kingdom of Saudi Arabia tenants).

    AllowAllow HTTPS and HTTP outbound from a Local Broker.
    Tenant-ID would be the typical ID, such as 1234, etc. POP-name represents the Home PoP Name.For example:
    ns-1234.us-sjc1.npa.goskope.com,
    ns-1234.lbr.us-sjc1.npa.goskope.com.MP-Name Variables:

    • us-sv5 (SV5)
    • us-sjc1 (SJC1)
    • us-sjc2 (SJC2)
    • de-fr4 (FR4)
    • nl-am2 (AM2)
    • au-mel2 (MEL2)
    • ch-zur2 (ZUR2)
    • uk-lon3 (LON3)
    • sg-sin2 (SIN2)
    • de-fra2 (FRA2)
    • us-dfw3 (DFW3)
    • sa-ruh1 (RUH1)

    For allowlisting ns-<tenant-ID>.<MP-name>.npa.<tenant-domain> based on IP addresses, refer to the  Netskope Private Access List for Allowlisting.

    Note

    A Local Broker needs reachability to the official Ubuntu Mirrors during the update process. Please review and allow the appropriate destinations for a successful Local Broker software update.

    Local Broker Capacity

    When factoring Local Broker capacity and scaling, consider these key points:

    • Each Local Broker instance can handle up to 500 Mbps of throughput.
    • Each Local Broker instance can accept up to 2000 unique client connections.
    • Each tenant has the capability to enable a default maximum limit of 100 local brokers, with a default limit set at 2. If you require an increase in this limit, please reach out to your Netskope Account team.
    • A notification will be displayed on the Local Brokers page as you near the maximum limit.
    In this Topic
    • Local Broker Requirements and Recommendations