KB: Network Requirements for Altium Products

Altium Designer Altium Designer
Altium products rely on various cloud services for authentication, licensing, workspace connectivity, component intelligence, software installation, updates, and embedded web content. In environments where outbound network traffic is restricted, the required services must be allowed through firewalls, proxy servers, and security appliances. This article provides an overview of the network requirements for Altium products and links to detailed articles covering specific deployment scenarios. It serves as the primary reference point for IT administrators planning firewall and proxy configurations.

At a Glance

Altium products rely on various cloud services for authentication, licensing, workspace connectivity, component intelligence, software installation, updates, and embedded web content.

In environments where outbound network traffic is restricted, the required services must be allowed through firewalls, proxy servers, and security appliances.

This article provides an overview of the network requirements for Altium products and links to detailed articles covering specific deployment scenarios. It serves as the primary reference point for IT administrators planning firewall and proxy configurations.
Go Deeper with AI:

Solution Details

Overview

Applies to: Altium Designer (AD), Altium 365 (A365), and Altium Enterprise Server (AES)

Tested with: Altium Designer 26.7 and AES 8.1.x. Endpoint requirements may differ for older product versions and may change in future releases.

This article helps IT administrators determine the exact FQDNs and ports that must be allowed through firewalls, proxies, or VPN rules for Altium products to function correctly. Most cloud connections use HTTPS/443; certificate-revocation checks may also require outbound HTTP/80 for CRL and OCSP endpoints. All connections are client-initiated (outbound from the client perspective). No inbound firewall rules are required on end-user machines. Note that WebSocket connections (used for real-time notifications) are upgraded from standard HTTPS and remain outbound-initiate

Critical — SSL/TLS inspection: Traffic to Altium services must bypass SSL inspection, HTTPS inspection, SSL decryption, or break-and-inspect. SSL-intercepted traffic can be interpreted as a man-in-the-middle attack and connections may fail. Configure proxy/firewall exceptions for Altium, Ciiva, Octopart, Nexar, and required AWS S3 endpoints.

Important: Use FQDN-based DNS allowlisting rather than IP addresses wherever possible. IP addresses behind Altium cloud services may change without notice. Only api3.ciiva.com currently has confirmed stable fixed IPs.

Minimum Required Connectivity

The following HTTPS (TCP/443) endpoints represent the minimum required allowlist for most Altium Designer and Altium 365 environments. Additional endpoint requirements for specific regions and features are covered in the companion articles listed below.

EndpointPurpose
auth.altium.com
actionwait.altium.com
Authentication
*.365.altium.comWorkspace connectivity, regional services, VCS
portal365.altium.comLicensing
store.altium.comSubscription related operations
workspaces.altium.comWorkspace discovery
api3.ciiva.comManufacturer Part Search
api.nexar.comSupply-chain data
*.amazonaws.com
See link for region-specific
S3 bucket FQDNs
Component data, 3D models, and S3-hosted assets
cdn.365.altium.comWorkspace web UI assets

Workspace Regions

Altium 365 workspaces are hosted in multiple geographic regions. In addition to the common endpoints listed above, IT administrators should allow the required region-specific services.

Workspace regionProtocol/PortAWS regionAdditional region-specific endpoints to allow
EUHTTPS/443eu-central-1eur.365.altium.com
afs-vcs-eu1.365.altium.com
ccv-eu.s3.eu-central-1.amazonaws.com
adworkspaces-eu.altium.com
prod-afs-viewer-data-eu1.s3.eu-central-1.amazonaws.com
US EastHTTPS/443us-east-1use.365.altium.com
afs-vcs-ue1.365.altium.com
ccv-us-east-1.s3.us-east-1.amazonaws.com
adworkspaces-ue.altium.com
prod-afs-viewer-data-ue1.s3.us-east-1.amazonaws.com
US WestHTTPS/443us-west-2usw.365.altium.com
afs-vcs-uw1.365.altium.com
ccv-us-west-2.s3.us-west-2.amazonaws.com
adworkspaces-uw.altium.com
prod-afs-viewer-data-uw2.s3.us-west-2.amazonaws.com
AsiaHTTPS/443ap-southeast-1asp.365.altium.com
afs-vcs-as1.365.altium.com
ccv-asia.s3.ap-southeast-1.amazonaws.com
adworkspaces-as.altium.com
prod-afs-viewer-data-as1.s3.ap-southeast-1.amazonaws.com

Find the Requirements for Your Environment

Choose the article that best matches your deployment scenario or the issue being investigated.

Note: For questions related to legacy product versions or Altium 365 GovCloud, please contact Altium Support.

If you find an issue, select the text/image and pressCtrl + Enterto send us your feedback.