Configure security group rules to allow ECS instances running Cloud Assistant Agent to access the required endpoints and ports.
Background
ECS instances must access specific endpoints and IP addresses to run Cloud Assistant commands. Configure security group rules to allow outbound access to the following endpoints and IP addresses.
|
Endpoint or IP address |
Purpose |
|
https://{region-id}.axt.aliyun.com:443/ |
Access the Cloud Assistant server. |
|
http://100.100.100.200:80/ |
Access MetaServer. |
|
https://aliyun-client-assist-{region-id}.oss-{region-id}-internal.aliyuncs.com:443/ |
Access the server that stores the Cloud Assistant Agent installation package for installing or updating Cloud Assistant Agent. |
{region-id} is the region ID of the ECS instance. For example, for the China (Hangzhou) region, use cn-hangzhou.
Choose one of the following methods to configure security group rules for an instance with Cloud Assistant Agent installed:
-
General configurations: Allow access to the CIDR blocks and ports of the Cloud Assistant server and the Cloud Assistant Agent package server. Suitable for most cases.
-
Fine-grained configurations: Allow access to specific ports and IP addresses based on the region of the instance with Cloud Assistant Agent installed.
General configurations
Configure security group rules to allow access to the CIDR blocks and ports of the Cloud Assistant server and the Cloud Assistant Agent package server.
The Cloud Assistant server CIDR block is 100.100.0.0/16. The Cloud Assistant Agent package server CIDR block is 100.0.0.0/8.
Basic security groups allow all outbound traffic by default. Advanced security groups deny all outbound traffic by default. For advanced security groups, add outbound rules to allow access to the URLs, CIDR blocks, or ports listed in the following table. See Add a security group rule.
|
URL, IP address, or port |
Purpose |
|
DNS/UDP port 53 |
Resolve domain names. |
|
https://100.100.0.0/16:443/ |
Access the Cloud Assistant server. |
|
https://100.0.0.0/8:443/ |
Access the Cloud Assistant Agent package server to install or update Cloud Assistant Agent. |

Fine-grained configurations
Allow access to region-specific IP addresses of the Cloud Assistant server and the Cloud Assistant Agent package server for fine-grained network control.
For example, if your instance is in the China (Hangzhou) region, add outbound rules in the advanced security group to allow access to the following URLs, IP addresses, and ports. See Add a security group rule.
|
URL, IP address, or port |
Purpose |
|
DNS/UDP port 53 |
Resolve domain names. |
|
https://100.100.45.106:443/ |
Access the Cloud Assistant server in the China (Hangzhou) region. |
|
https://100.118.28.50:443/ |
Access the Cloud Assistant Agent package server in the China (Hangzhou) region to install or update Cloud Assistant Agent. |

The following table lists the Cloud Assistant server endpoints and IP addresses for each region.
For Cloud Assistant Agent package server endpoints and IP addresses, see the Internal endpoint for access over VPCs and VIP range columns in Access OSS over bucket domain names.
|
Region |
Region ID |
Endpoint |
IP address |
|
China (Qingdao) |
cn-qingdao |
cn-qingdao.axt.aliyun.com |
|
|
China (Beijing) |
cn-beijing |
cn-beijing.axt.aliyun.com |
100.100.18.120 |
|
China (Zhangjiakou) |
cn-zhangjiakou |
cn-zhangjiakou.axt.aliyun.com |
|
|
China (Hohhot) |
cn-huhehaote |
cn-huhehaote.axt.aliyun.com |
|
|
China (Ulanqab) |
cn-wulanchabu |
cn-wulanchabu.axt.aliyun.com |
100.100.0.3 |
|
China (Hangzhou) |
cn-hangzhou |
cn-hangzhou.axt.aliyun.com |
100.100.45.106 |
|
China (Shanghai) |
cn-shanghai |
cn-shanghai.axt.aliyun.com |
|
|
China (Nanjing - Local Region) |
cn-nanjing |
cn-nanjing.axt.aliyun.com |
100.100.0.1 |
|
China (Fuzhou - Local Region) |
cn-fuzhou |
cn-fuzhou.axt.aliyun.com |
100.100.0.26 |
|
China (Wuhan - Local Region) |
cn-wuhan-lr |
cn-wuhan-lr.axt.aliyun.com |
100.100.0.8 |
|
China (Shenzhen) |
cn-shenzhen |
cn-shenzhen.axt.aliyun.com |
100.100.0.70 |
|
China (Heyuan) |
cn-heyuan |
cn-heyuan.axt.aliyun.com |
100.100.0.5 |
|
China (Guangzhou) |
cn-guangzhou |
cn-guangzhou.axt.aliyun.com |
100.100.0.4 |
|
China (Chengdu) |
cn-chengdu |
cn-chengdu.axt.aliyun.com |
100.100.0.42 |
|
China (Hong Kong) |
cn-hongkong |
cn-hongkong.axt.aliyun.com |
|
|
Singapore |
ap-southeast-1 |
ap-southeast-1.axt.aliyun.com |
|
|
Malaysia (Kuala Lumpur) |
ap-southeast-3 |
ap-southeast-3.axt.aliyun.com |
|
|
Indonesia (Jakarta) |
ap-southeast-5 |
ap-southeast-5.axt.aliyun.com |
100.100.80.165 100.100.132.30 |
|
Philippines (Manila) |
ap-southeast-6 |
ap-southeast-6.axt.aliyun.com |
100.100.0.15 |
|
Thailand (Bangkok) |
ap-southeast-7 |
ap-southeast-7.axt.aliyun.com |
100.100.0.30 |
|
Japan (Tokyo) |
ap-northeast-1 |
ap-northeast-1.axt.aliyun.com |
100.100.0.76 |
|
South Korea (Seoul) |
ap-northeast-2 |
ap-northeast-2.axt.aliyun.com |
100.100.0.23 |
|
US (Silicon Valley) |
us-west-1 |
us-west-1.axt.aliyun.com |
100.100.29.34 100.100.1.3 |
|
US (Virginia) |
us-east-1 |
us-east-1.axt.aliyun.com |
100.100.152.140 100.100.147.87 |
|
Germany (Frankfurt) |
eu-central-1 |
eu-central-1.axt.aliyun.com |
|
|
UK (London) |
eu-west-1 |
eu-west-1.axt.aliyun.com |
100.100.0.20 |
|
UAE (Dubai) |
me-east-1 |
me-east-1.axt.aliyun.com |
100.100.43.7 |
|
SAU (Riyadh - Partner Region), operated by a partner. |
me-central-1 |
me-central-1.axt.aliyun.com |
100.100.0.15 |
|
China East 2 Finance |
cn-shanghai-finance-1 |
cn-shanghai-finance-1.axt.aliyun.com |
100.100.0.46 |
|
China North 2 Finance (Preview) |
cn-beijing-finance-1 |
cn-beijing-finance-1.axt.aliyun.com |
100.100.0.165 |
|
China South 1 Finance |
cn-shenzhen-finance-1 |
cn-shenzhen-finance-1.axt.aliyun.com |
100.103.0.140 |
|
China North 2 Ali Gov 1 |
cn-north-2-gov-1 |
cn-north-2-gov-1.axt.aliyun.com |
100.100.0.67 |