Configure firewall rules for CLEAR Engine

2025/6/1 |

This article describes how to configure firewall rules for CLEAR Engine and the Web UI.

In this article, you will learn how to:

  • Configure required firewall rules for CLEAR Engine and the Web UI.
  • Configure optional firewall rules for CLEAR Engine.

At the end, you will be able to configure firewall rules for CLEAR Engine and the Web UI.

Configure firewall rules for CLEAR Engine and the Web UI

CLEAR Engine

CLEAR Engine requires outbound connection on the following protocols, ports, and destinations:

  • TCP/443: api.lucentskyavm.com

To enable remote access to CLEAR Engine, it also requires inbound connectivity on the following protocols and ports:

  • TCP/5759

To deploy Lucent Sky AVM in environments without Internet access, contact Lucent Sky support.

Web UI

To enable remote access to the Web UI, it requires inbound connectivity on the following protocols and ports:

  • TCP/80
  • TCP/443

Configure optional firewall rules for CLEAR Engine

Some features, such as real-time intelligence, requires additional connectivity.

Real-time intelligence

Real-time intelligence requires outbound connectivity on the following additional protocols, ports, and destinations:

  • TCP/443: api.lucentskyavm.com
  • TCP/443: update.lucentskyavm.com
  • TCP/443: www.cisa.gov
  • TCP/443: search.maven.org
  • TCP/443: status.maven.org
  • TCP/443: nvd.nist.gov
  • TCP/443: services.nvd.nist.gov
  • TCP/443: static.nvd.nist.gov
  • TCP/443: registry.npmjs.org
  • TCP/443: ossindex.sonatype.org

Machine learning services

Machine learning services, such as ML-augmented analysis and remediation, requires outbound connectivity on the following protocols, ports, and destinations:

  • TCP/443: api.lucentskyavm.com
  • TCP/443: update.lucentskyavm.com