Network requirements
Applies to SynapseOS builds from 2026-10-09 (20261009-141152 and later). See What changed.
Inbound: SSH. Outbound: the platform, the update channel, and your log collector.
Open these before the unit is expected to do anything. Every outbound row is a connection the unit opens itself; nothing on the platform connects back in.
Inbound
| Port | Protocol | When | Where it is set |
|---|---|---|---|
| 22 | TCP | Always: SSH, key-only | The base firewall's services chain, see Configuring the appliance |
| 80, 443 | TCP | Only when the proxy mode runs | Opened by you, see Running the proxy |
| VRRP (IP protocol 112) | On the internal leg | Only in a two-unit pair | Set at delivery, see High availability |
| ICMP, ICMPv6 | Always: ping and neighbour discovery are accepted | Base firewall |
Everything else inbound is dropped. The unit answers nothing on the external leg that is not in this table.
Outbound
| Destination | Port | Used by | When |
|---|---|---|---|
api.gen0sec.com | 443/TCP | Synapse | Continuously: registration, detections and telemetry up; access rules, fleet bans and verdicts down |
download.gen0sec.com | 443/TCP | Synapse | Periodically: indicator and threat databases, and their version check |
github.com, raw.githubusercontent.com | 443/TCP | Synapse | Periodically: the GeoIP database the shipped configuration points at |
The host in your UPDATE_BASE_URL | 443/TCP | synapseos-ab-update | Only when you run check or update; never on its own |
| Your log collector | 6514/TCP (TLS), or 514 TCP or UDP | axosyslog | Continuously, if forwarding is configured |
| Your DNS servers | 53 UDP and TCP | systemd-resolved | Always |
All three Gen0Sec hosts and the update host are reached over HTTPS and verified against the system trust store. The update channel and the update archive carry their own signatures on top of that, so the update host needs no trust at all; see Updating.
The GeoIP row comes from the database URL in the geoip section of the shipped Synapse
configuration (/etc/synapse/config.yaml). Point it at a mirror of your own and that row
changes with it; the keys are on the Configuration page.
Time synchronisation
The unit does not synchronise its clock as delivered: systemd-timesyncd is present but
disabled. TLS verification and certificate expiry both depend on the clock, so either
enable it and allow 123/UDP outbound to the servers you name in
/etc/systemd/timesyncd.conf, or set the time from the console after any long power-off:
systemctl enable --now systemd-timesyncd # uses NTP= in /etc/systemd/timesyncd.conf
timedatectl status # "System clock synchronized: yes" once it has a server
Behind an HTTP proxy
synapseos-ab-update fetches with curl, and it sources /etc/synapseos/update.conf
before it does, so a proxy for the update channel goes in that file:
UPDATE_BASE_URL=<provided by Gen0Sec>
UPDATE_CHANNEL=stable
export https_proxy=http://proxy.example.com:3128
export matters: without it the variable is set for the script and not for curl.
Then synapseos-ab-update check proves the path.
Synapse itself has no proxy setting: the agent connects to api.gen0sec.com and
download.gen0sec.com directly. On a network that only allows outbound traffic through a
proxy, allow those two hosts directly for the unit, or the agent runs blind; see
Known limitations.
A private certificate authority
If your log collector, or a TLS-inspecting proxy, presents certificates from your own CA,
the unit has to trust it. The trust store is /etc/ssl/certs, on the writable partition,
and openssl is on the unit:
cp my-ca.pem /etc/ssl/certs/my-ca.pem
openssl rehash /etc/ssl/certs
systemctl reload axosyslog
The file survives updates, which leave /etc alone. Do not put a private CA in front of
api.gen0sec.com or the update host: the agent and the updater pin nothing, but a proxy
that re-signs their traffic is a machine in the middle of your security sensor, and the
update signatures will still verify only against Gen0Sec's keys.
Checking from the unit
curl -sS -o /dev/null -w '%{http_code}\n' https://api.gen0sec.com/ # expect a 2xx or 4xx, not a timeout
synapseos-ab-update check # exercises the update host
journalctl -u axosyslog -n 20 # a collector that is unreachable says so here
A 000 from curl, or cannot reach <base> from the updater, is the network, not the
unit. See Troubleshooting.