All Products
Search
Document Center

Elastic Compute Service:Configure network permissions for Cloud Assistant Agent

Last Updated:Mar 31, 2026

Cloud Assistant Agent connects to several Alibaba Cloud endpoints to receive commands, access instance metadata, and download agent updates. In advanced security groups—where all outbound traffic is denied by default—you must add outbound rules to allow these connections. Basic security groups allow all outbound traffic by default and require no additional rules.

Connectivity principles

All required connections follow these rules:

  • All connections are outbound. Cloud Assistant Agent initiates connections to the cloud; no inbound rules are needed.

  • Cloud Assistant server and OSS connections use TCP/port 443.

  • Domain name resolution requires UDP/port 53.

Required endpoints

Cloud Assistant Agent requires access to the following endpoints:

EndpointPortPurposeWhen required
https://{region-id}.axt.aliyun.com443Cloud Assistant server — receives and dispatches commandsAlways
http://100.100.100.20080MetaServer — provides instance metadataAlways
https://aliyun-client-assist-{region-id}.oss-{region-id}-internal.aliyuncs.com443Object Storage Service (OSS) — stores the Cloud Assistant Agent installation packageInstallation and updates only

Replace {region-id} with the region ID of your ECS instance. For example, use cn-hangzhou for the China (Hangzhou) region.

Choose a configuration approach

ApproachHow it worksUse when
GeneralAllow outbound access to CIDR blocks that cover all Cloud Assistant endpointsYou want a simple, low-maintenance configuration
Fine-grainedAllow outbound access to specific IP addresses per regionYou need strict, per-region network controls

General configuration

Allow outbound access to the following URLs and ports. This covers Cloud Assistant endpoints across all regions.

URL or portPurpose
DNS/UDP port 53Domain name resolution
https://100.100.0.0/16 port 443Cloud Assistant server (CIDR block: 100.100.0.0/16)
https://100.0.0.0/8 port 443Cloud Assistant Agent installation package server (CIDR block: 100.0.0.0/8)

For steps to add a rule, see Add a security group rule.

添加安全组规则

Fine-grained configuration

Allow outbound access to the specific IP addresses for each region where your instances run.

Example: China (Hangzhou)

URL or portPurpose
DNS/UDP port 53Domain name resolution
https://100.100.45.106 port 443Cloud Assistant server in China (Hangzhou)
https://100.118.28.50 port 443Cloud Assistant Agent installation package server in China (Hangzhou)

For steps to add a rule, see Add a security group rule.

添加安全组规则1

Cloud Assistant server endpoints by region

Use the following table to find the endpoint and IP address for each region.

For installation package server endpoints and IP address ranges, refer to the Internal endpoint for access over VPCs and VIP range columns in Access OSS using bucket domain names.

RegionRegion IDEndpointIP address
China (Qingdao)cn-qingdaocn-qingdao.axt.aliyun.com100.100.15.4, 100.100.183.1
China (Beijing)cn-beijingcn-beijing.axt.aliyun.com100.100.18.120
China (Zhangjiakou)cn-zhangjiakoucn-zhangjiakou.axt.aliyun.com100.100.99.23, 100.100.202.194
China (Hohhot)cn-huhehaotecn-huhehaote.axt.aliyun.com100.100.126.8, 100.100.59.86
China (Ulanqab)cn-wulanchabucn-wulanchabu.axt.aliyun.com100.100.0.3
China (Hangzhou)cn-hangzhoucn-hangzhou.axt.aliyun.com100.100.45.106
China (Shanghai)cn-shanghaicn-shanghai.axt.aliyun.com100.100.36.108, 100.100.159.7
China (Nanjing - Local Region)cn-nanjingcn-nanjing.axt.aliyun.com100.100.0.1
China (Fuzhou - Local Region)cn-fuzhoucn-fuzhou.axt.aliyun.com100.100.0.26
China (Wuhan - Local Region)cn-wuhan-lrcn-wuhan-lr.axt.aliyun.com100.100.0.8
China (Shenzhen)cn-shenzhencn-shenzhen.axt.aliyun.com100.100.0.70
China (Heyuan)cn-heyuancn-heyuan.axt.aliyun.com100.100.0.5
China (Guangzhou)cn-guangzhoucn-guangzhou.axt.aliyun.com100.100.0.4
China (Chengdu)cn-chengducn-chengdu.axt.aliyun.com100.100.0.42
China (Hong Kong)cn-hongkongcn-hongkong.axt.aliyun.com100.100.35.30, 100.100.98.28
Singaporeap-southeast-1ap-southeast-1.axt.aliyun.com100.100.30.60, 100.100.169.197
Malaysia (Kuala Lumpur)ap-southeast-3ap-southeast-3.axt.aliyun.com100.100.127.16, 100.100.62.2
Indonesia (Jakarta)ap-southeast-5ap-southeast-5.axt.aliyun.com100.100.80.165, 100.100.132.30
Philippines (Manila)ap-southeast-6ap-southeast-6.axt.aliyun.com100.100.0.15
Thailand (Bangkok)ap-southeast-7ap-southeast-7.axt.aliyun.com100.100.0.30
Japan (Tokyo)ap-northeast-1ap-northeast-1.axt.aliyun.com100.100.0.76
South Korea (Seoul)ap-northeast-2ap-northeast-2.axt.aliyun.com100.100.0.23
US (Silicon Valley)us-west-1us-west-1.axt.aliyun.com100.100.29.34, 100.100.1.3
US (Virginia)us-east-1us-east-1.axt.aliyun.com100.100.152.140, 100.100.147.87
Germany (Frankfurt)eu-central-1eu-central-1.axt.aliyun.com100.100.46.12, 100.100.53.26
UK (London)eu-west-1eu-west-1.axt.aliyun.com100.100.0.20
UAE (Dubai)me-east-1me-east-1.axt.aliyun.com100.100.43.7
SAU (Riyadh - Partner Region) — operated by a partnerme-central-1me-central-1.axt.aliyun.com100.100.0.15
China East 2 Financecn-shanghai-finance-1cn-shanghai-finance-1.axt.aliyun.com100.100.0.46
China North 2 Finance (Preview)cn-beijing-finance-1cn-beijing-finance-1.axt.aliyun.com100.100.0.165
China South 1 Financecn-shenzhen-finance-1cn-shenzhen-finance-1.axt.aliyun.com100.103.0.140
China North 2 Ali Gov 1cn-north-2-gov-1cn-north-2-gov-1.axt.aliyun.com100.100.0.67