EloView 4 (EV4) Network Connectivity, Firewall Allowlist & Port Configuration Guide
Audience: Public / Elo Customers, Network Engineers, IT & Security Administrators, Solutions Architects & Integrators
Article Type: Network Infrastructure, Port Mapping & Cloud Security Architecture Reference
To ensure seamless communication, device enrollment, over-the-air (OTA) OS updates, content deployment, real-time telemetry, and remote management, devices running EloView® 4 from Elo — Now part of Zebra Technologies require unrestricted outbound access to specific cloud endpoints, content delivery networks (CDNs), and network ports.
⚠️ Critical Architecture Notice (EloView 3 vs. EloView 4):
Static Armor IP addresses apply strictly to legacy EloView 3 environments. EloView 4 is built upon a modern, dynamic, multi-cloud infrastructure (leveraging AWS, Microsoft Azure, Google Cloud Platform, and Cloudflare CDN). Because underlying cloud IP addresses change dynamically, network firewall policies must allow traffic based on Fully Qualified Domain Names (FQDNs) and URLs rather than static IP ranges.
Required Network Ports & Communication Protocols
All communication between EloView-enabled Android devices and the cloud is strictly outbound device-initiated (via HTTPS, WebSockets, and secure MQTT). No inbound firewall port openings or external NAT port forwards are ever required.
| Port / Protocol | Direction | Purpose & Functional Description |
|---|---|---|
| 443 (TCP / HTTPS) | Outbound | REST API communication, OAuth authentication, web portal access, secure WebSocket (WSS) tunnels, and content/APK package downloads. |
| 8883 (TCP / MQTTS) | Outbound | Secure MQTT over TLS for low-latency live device command routing, status heartbeats, settings pushes, and real-time telemetry. |
| 123 (UDP / NTP) | Outbound | Network Time Protocol (NTP) for device clock synchronization required for valid SSL/TLS certificate negotiation. |
Core EloView 4 Production Endpoints & Cloud Infrastructure
Ensure the following core domain names, storage repositories, and API endpoints are fully allowlisted on your firewall, content filter, and proxy servers:
| # | Endpoint / FQDN / URL | Purpose & Description |
|---|---|---|
| 1 | https://secure-api.eloview.com/prod | Token API, Over-The-Air (OTA) OS updates, and EloCare™ OS 360 warranty entitlement validation (outbound). |
| 2 | https://secure-provisioning.eloview.com/prod | Device onboarding and initial zero-touch provisioning base URL (outbound). |
| 3 | https://secure-broker.eloview.com:8883 | MQTT Broker endpoint for bi-directional live command routing, device status, and telemetry (Port 8883). |
| 4 | https://secure-logs.eloview.com | Diagnostic log bundle uploads, firmware build distribution, and private content transfers (bidirectional). |
| 5 | https://secure-content.eloview.com | Delivers application icons, media thumbnails, and assets rendered within the device user interface. |
| 6 | https://secure-auth.eloview.com | OAuth 2.0 device authentication, identity token generation, and secure session management. |
| 7 | https://secure.eloview.com/systemUpdate/ | Core EloView system software and web runtime updates. |
| 8 | https://polaris-prod-public-ota.s3.us-west-2.amazonaws.com/systemUpdate/ | AWS S3 public distribution bucket hosting standard and custom Android OS firmware OTA packages and SDKs. |
| 9 | https://polaris-promote-prod.s3.us-west-2.amazonaws.com | AWS S3 storage repository for approved applications, media assets, Attract Loops, and deployment configuration files. |
| 10 | https://polaris-scan-prod.s3.us-west-2.amazonaws.com | AWS S3 secure staging bucket where uploaded APKs and media undergo Trend Micro antivirus scanning prior to deployment. |
| 11 | https://cognito-identity.us-west-2.amazonaws.com | AWS Cognito Identity Pool: Delivers temporary scoped AWS credentials for devices and users to establish live IoT channels. |
| 12 | https://cognito-idp.us-west-2.amazonaws.com | AWS Cognito User Pool: Manages user authentication, SAML SSO/MFA workflows, password resets, and token refreshes. |
| 13 | *.us-west-2.compute.amazonaws.com | AWS IoT Core, API Gateway, and serverless Lambda compute backends. |
| 14 | eloprod.blob.core.windows.net | Microsoft Azure Blob Storage for global content asset hosting, media caching, and auxiliary deployment packages. |
| 15 | *.1e100.nethttp://nuq04s43-in-f4.1e100.net | Google-owned domain network utilized by core Android OS frameworks, Play Protect, and cloud connection checks. |
| 16 | *.google.com:443clients3.google.comwww.google.com | Android OS captive portal detection, network connectivity validation, and certificate revocation checks. |
Time Synchronization (NTP) Requirements
Accurate system time is critical for SSL/TLS handshakes and token validation. EloView 4 devices utilize Network Time Protocol (NTP) over UDP port 123:
2.android.pool.ntp.org(Primary NTP server used by EloView)time.android.comtime.google.com*.pool.ntp.org
2.android.pool.ntp.org) during initial boot to synchronize time before establishing secure SSL connections to EloView. Once enrolled, devices can be configured to point to your corporate intranet NTP server.Cloudflare Global Content Delivery Network (CDN)
EloView 4 leverages Cloudflare’s global Content Delivery Network (CDN) to accelerate package distribution and defend against DDoS threats.
- Domain Whitelisting Recommendation: Always whitelist traffic by Domain Name / FQDN rather than IP addresses.
- Why Static IP Whitelisting is Not Recommended: Cloudflare IP ranges are dynamic and change without prior notice. Filtering by IP will cause unexpected service disruptions during edge routing changes.
Sample Cloudflare IP Ranges (Reference Only):
104.16.60.227, 104.16.61.227, 104.16.62.227, 104.16.63.227, 104.16.64.227IPv6:
2606:4700::6810:3ce3, 2606:4700::6810:3de3, 2606:4700::6810:3ee3, 2606:4700::6810:3fe3, 2606:4700::6810:40e3Optional Remote Services
If your organization utilizes integrated remote desktop access and device diagnostics via TeamViewer:
- TeamViewer Integration: Allow
*.teamviewer.comacross Port 443 (HTTPS).
✔ Enterprise Firewall Configuration Best Practice:
For enterprise network firewalls and proxy filters supporting wildcard allowlisting, adding the following rules provides complete coverage and ensures future EloView 4 cloud feature additions operate without administrative overhead:
*.eloview.com(Ports 443 TCP, 8883 TCP)*.amazonaws.com(Port 443 TCP)*.blob.core.windows.net(Port 443 TCP)*.1e100.net&*.google.com(Port 443 TCP)*.pool.ntp.org&time.android.com(Port 123 UDP)*.teamviewer.com(Optional - Port 443 TCP)
Please report any broken links by emailing elo.support@zebra.com and include a link to the knowledge article