Fowlguard

Home  /  Resources  /  Network Requirements

Network Requirements

The page to give your network team before a rollout. Allow outbound 443 to *.fowlguard.com, and exempt that name from TLS inspection.

Inspection is the one that breaks things

Fowlguard pins its own certificates. An inspection appliance substitutes its own, the pin does not match, and the connection is refused, so decrypting our traffic does not weaken the tunnel, it stops the client connecting at all. The failure is immediate and total, and it looks like the product is broken rather than like a policy is working.

That is deliberate. These connections carry your devices’ policy, their identity and their updates; a product that let an unknown intermediary sit inside them would have nothing left to promise. There is no setting that makes an inspected connection work, and there should not be.

What to exempt

Exempt from decryptionWhat it carries
*.fowlguard.comControl plane, relay, tunnel, sign-in, downloads
*.fgdns.netYour mesh’s own DNS names

Most products call this a TLS decryption exclusion, an SSL bypass or a do-not-decrypt list, and accept a domain suffix. One entry each is enough, because both cover every subdomain. Do not substitute an IP range: the addresses change, and an exemption keyed on one stops matching without telling you.

What to allow

All outbound. No inbound rules, no port forwarding and no static addresses are needed for a client.

ProtocolPortDestinationWhat it is
TCP443*.fowlguard.comControl plane, relay, tunnel, sign-in
UDP443*.fowlguard.comThe QUIC tunnel
UDP3478dp01.fowlguard.comSTUN, to learn the public address

UDP 443 matters more than it looks

The tunnel prefers QUIC. Blocking UDP 443 does not break anything, because it falls back to TCP but it gives up the transport that performs best on a lossy or mobile network, and the fallback costs a round trip on every connection. A network that allows TCP 443 and blocks UDP 443 works, and feels slower, with nothing on screen to say why.

Direct connections need more, and degrade safely without it

Two devices can connect directly rather than through a relay, using NAT traversal that sends UDP to high-numbered ports most enterprise egress policies forbid. That is expected to fail on a locked-down network, and it is not a fault: the connection falls back to the relay on 443 and works. Nothing needs opening, and we do not suggest opening anything.

One thing worth telling your SOC in advance: on some networks traversal probes many ports in a short window and can look like a port scan to an IDS. It is one host, outbound, to one destination.

Recognising your own policy

What people seeCause
Sign-in works, the client never connects443 to *.fowlguard.com is being decrypted, or is blocked
Connects, then drops repeatedlyInspection on some paths only, often an exception on one hostname instead of the suffix
Works, but slow on poor networksUDP 443 blocked, TCP fallback in use
Always relayed, never directHigh-port UDP blocked. Expected, and harmless
© 2026 Fowlguard Platform Pricing Resources Company hello@fowlguard.com