Skip to main content

Network requirements

Applies to SynapseOS builds from 2026-10-09 (20261009-141152 and later). See What changed.

Inbound: SSH. Outbound: the platform, the update channel, and your log collector.

Open these before the unit is expected to do anything. Every outbound row is a connection the unit opens itself; nothing on the platform connects back in.

Inbound​

PortProtocolWhenWhere it is set
22TCPAlways: SSH, key-onlyThe base firewall's services chain, see Configuring the appliance
80, 443TCPOnly when the proxy mode runsOpened by you, see Running the proxy
VRRP (IP protocol 112)On the internal legOnly in a two-unit pairSet at delivery, see High availability
ICMP, ICMPv6Always: ping and neighbour discovery are acceptedBase firewall

Everything else inbound is dropped. The unit answers nothing on the external leg that is not in this table.

Outbound​

DestinationPortUsed byWhen
api.gen0sec.com443/TCPSynapseContinuously: registration, detections and telemetry up; access rules, fleet bans and verdicts down
download.gen0sec.com443/TCPSynapsePeriodically: indicator and threat databases, and their version check
github.com, raw.githubusercontent.com443/TCPSynapsePeriodically: the GeoIP database the shipped configuration points at
The host in your UPDATE_BASE_URL443/TCPsynapseos-ab-updateOnly when you run check or update; never on its own
Your log collector6514/TCP (TLS), or 514 TCP or UDPaxosyslogContinuously, if forwarding is configured
Your DNS servers53 UDP and TCPsystemd-resolvedAlways

All three Gen0Sec hosts and the update host are reached over HTTPS and verified against the system trust store. The update channel and the update archive carry their own signatures on top of that, so the update host needs no trust at all; see Updating.

The GeoIP row comes from the database URL in the geoip section of the shipped Synapse configuration (/etc/synapse/config.yaml). Point it at a mirror of your own and that row changes with it; the keys are on the Configuration page.

Time synchronisation​

The unit does not synchronise its clock as delivered: systemd-timesyncd is present but disabled. TLS verification and certificate expiry both depend on the clock, so either enable it and allow 123/UDP outbound to the servers you name in /etc/systemd/timesyncd.conf, or set the time from the console after any long power-off:

systemctl enable --now systemd-timesyncd # uses NTP= in /etc/systemd/timesyncd.conf
timedatectl status # "System clock synchronized: yes" once it has a server

Behind an HTTP proxy​

synapseos-ab-update fetches with curl, and it sources /etc/synapseos/update.conf before it does, so a proxy for the update channel goes in that file:

/etc/synapseos/update.conf
UPDATE_BASE_URL=<provided by Gen0Sec>
UPDATE_CHANNEL=stable
export https_proxy=http://proxy.example.com:3128

export matters: without it the variable is set for the script and not for curl. Then synapseos-ab-update check proves the path.

Synapse itself has no proxy setting: the agent connects to api.gen0sec.com and download.gen0sec.com directly. On a network that only allows outbound traffic through a proxy, allow those two hosts directly for the unit, or the agent runs blind; see Known limitations.

A private certificate authority​

If your log collector, or a TLS-inspecting proxy, presents certificates from your own CA, the unit has to trust it. The trust store is /etc/ssl/certs, on the writable partition, and openssl is on the unit:

cp my-ca.pem /etc/ssl/certs/my-ca.pem
openssl rehash /etc/ssl/certs
systemctl reload axosyslog

The file survives updates, which leave /etc alone. Do not put a private CA in front of api.gen0sec.com or the update host: the agent and the updater pin nothing, but a proxy that re-signs their traffic is a machine in the middle of your security sensor, and the update signatures will still verify only against Gen0Sec's keys.

Checking from the unit​

curl -sS -o /dev/null -w '%{http_code}\n' https://api.gen0sec.com/ # expect a 2xx or 4xx, not a timeout
synapseos-ab-update check # exercises the update host
journalctl -u axosyslog -n 20 # a collector that is unreachable says so here

A 000 from curl, or cannot reach <base> from the updater, is the network, not the unit. See Troubleshooting.