Recommended tunnel settings for high bandwidth services
Topic
This article discusses recommended tunnel settings for high bandwidth services.
Environment
- Datto Secure Edge
Description
Below are list of recommended excluded address ranges when excluding specific traffic from the VPN for a Full Tunnel configuration. This will avoid sending high bandwidth application traffic into the Secure Edge Cloud Gateway.
To view or update these values in the Network Manager:
- Navigate to the desired network .
- Select Secure Edge → Security Policies.
- Click the name of the policy you'd like to edit.
- Select Tunnel Settings.
Full list of recommended addresses and ranges
Addresses:
- aiv-cdn.net
- aiv-delivery.net
- amazonvideo.com
- atv-ext.amazon.com
- atv-ps.amazon.com
- d25xi40x97liuc.cloudfront.net
- dmqdd6hw24ucf.cloudfront.net
- media-amazon.com
- primevideo.com
- dattobackup.com
- fileprotection.datto.com
- mothership.dtc.datto.com
- agent-update.datto.com
- datto.io
- dattolocal.net
- valid-isrgrootx1.letsencrypt.org
- workplace.datto.com
- soonr.com
- disney-plus.net
- disneyplus.com
- disneyplus.com.ssl.sc.omtrdc.net
- dssott.com
- dssott.com.akamaized.net
- emby.media
- alt1-mtalk.google.com
- alt2-mtalk.google.com
- alt3-mtalk.google.com
- alt4-mtalk.google.com
- alt5-mtalk.google.com
- alt6-mtalk.google.com
- alt7-mtalk.google.com
- alt8-mtalk.google.com
- hangouts.clients6.google.com
- hangouts.google.com
- hangouts.googleapis.com
- meet.google.com
- meetings.googleapis.com
- mobile-gtalk.l.google.com
- mobile-gtalk4.l.google.com
- mtalk.google.com
- mtalk4.google.com
- talk.google.com
- talk.l.google.com
- talkx.l.google.com
- hbo.com
- hbogo.com
- hbonow.com
- hbomax.com
- maxgo.com
- hbomaxcdn.com
- hbo.map.fastly.net
- hbomaxcdn.com.c.footprint.net
- hbomaxdash.s.llnwi.net
- hbo.com.edgesuite.net
- hulu.com
- huluad.com
- huluim.com
- hulumail.com
- hulustream.com
- cs428.wpc.edgecastcdn.net
- cws-hulu.conviva.com
- hulu-ios.hb-api.omtrdc.net
- hulu.com.c.footprint.net
- hulu.map.fastly.net
- assetshuluimcom-a.akamaihd.net
- lync.com
- teams.microsoft.com
- fast.com
- nflxso.net
- nflxvideo.net
- nflximg.net
- netflix.ca
- nflxext.com
- netflixstudios.com
- netflix.net
- netflix.com
- pandora.com
- p-cdn.com
- p-cdn.us
- plex.tv
- plex.bz
- plex.tv.cdn.cloudflare.net
- plexapp.com
- plexapp.com.cdn.cloudflare.net
- sndcdn.com
- soundcloud.com
- pscdn.co
- scdn.co
- spoti.fi
- spotify.com
- spotifycdn.com
- spotifycdn.net
- spotifycharts.com
- spotifycodes.com
- spotifyjobs.com
- spotify.map.fastly.net
- spotifynewsroom.jp
- spotilocal.com
- tospotify.com
- s.team
- steam-chat.com
- steamchina.com
- steamcommunity.com
- steamcontent.com
- steamgames.com
- steampowered.com
- steampowered.com.8686c.com
- steamstatic.com
- steamstatic.com.8686c.com
- steamusercontent.com
- valve.net
- valvesoftware.com
- steambroadcast.akamaized.net
- vimeo.com
- vimeocdn.com
- vhx.tv
- vhx.com
- ciscospark.com
- ciscospark.statuspage.io
- ciscowebex.com
- wbx2.com
- webex.ca
- webex.co.in
- webex.co.it
- webex.co.jp
- webex.co.kr
- webex.co.nz
- webex.co.uk
- webex.com
- webex.com.au
- webex.com.br
- webex.com.cn
- webex.com.hk
- webex.com.mx
- webex.de
- webex.es
- webex.fr
- webexapis.com
- webexapps.com
- webexconnect.com
- webexcontent.com
- ciscospark.com.edgekey.net
- ciscowebex.demdex.net
- windowsupdate.microsoft.com
- update.microsoft.com
- windowsupdate.com
- download.microsoft.com
- wustat.windows.com
- ntservicepack.microsoft.com
- stats.microsoft.com
- prod.do.dsp.mp.microsoft.com
- dl.delivery.mp.microsoft.com
- delivery.mp.microsoft.com
- adl.windows.com
- tsfe.trafficshaping.dsp.mp.microsoft.com
- emdl.ws.microsoft.com
- definitionupdates.microsoft.com
- youtube.com
- youtubeeducation.com
- youtubekids.com
- yt.be
- ytimg.com
- yt3.ggpht.com
- googlevideo.com
- gvt1.com
- video.google.com
- youtu.be
- youtube-nocookie.com
- youtube-ui.l.google.com
- zoom.com
- zoom.us
Ranges:
- 206.201.136.0/23
- 185.217.57.0/24
- 103.109.129.0/24
- 203.22.186.0/24
- 27.111.249.0/24
- 162.244.85.60
- 162.244.87.0/24
- 198.49.95.0/24
- 13.107.64.0/18
- 52.112.0.0/14
- 52.122.0.0/15
- 52.112.0.0/14
- 52.122.0.0/15
- 52.238.119.141/32
- 52.244.160.207/32
Lists based on service used:
Amazon Video
- aiv-cdn.net
- aiv-delivery.net
- amazonvideo.com
- atv-ext.amazon.com
- atv-ps.amazon.com
- d25xi40x97liuc.cloudfront.net
- dmqdd6hw24ucf.cloudfront.net
- media-amazon.com
- primevideo.com
Datto File Protection
- fileprotection.datto.com
Datto & Unitrends – Endpoint Backup
- mothership.dtc.datto.com
- agent-update.datto.com
- dattolocal.net
- valid-isrgrootx1.letsencrypt.org
- datto.io
Datto & Unitrends – Endpoint Backup for PCs
- mothership.dtc.datto.com
- agent-update.datto.com
- dattolocal.net
- valid-isrgrootx1.letsencrypt.org
- datto.io
Datto & Unitrends – Endpoint Backup with Disaster Recovery
- mothership.dtc.datto.com
- agent-update.datto.com
- dattolocal.net
- valid-isrgrootx1.letsencrypt.org
- datto.io
Datto Workplace
- workplace.datto.com
- soonr.com
Disney+
- disney-plus.net
- disneyplus.com
- disneyplus.com.ssl.sc.omtrdc.net
- dssott.com
- dssott.com.akamaized.net
Emby
- emby.media
Google Meet / Hangouts
- alt1-mtalk.google.com
- alt2-mtalk.google.com
- alt3-mtalk.google.com
- alt4-mtalk.google.com
- alt5-mtalk.google.com
- alt6-mtalk.google.com
- alt7-mtalk.google.com
- alt8-mtalk.google.com
- hangouts.clients6.google.com
- hangouts.google.com
- hangouts.googleapis.com
- meet.google.com
- meetings.googleapis.com
- mobile-gtalk.l.google.com
- mobile-gtalk4.l.google.com
- mtalk.google.com
- mtalk4.google.com
- talk.google.com
- talk.l.google.com
- talkx.l.google.com
HBO
- hbo.com
- hbogo.com
- hbonow.com
- hbomax.com
- maxgo.com
- hbomaxcdn.com
- hbo.map.fastly.net
- hbomaxcdn.com.c.footprint.net
- hbomaxdash.s.llnwi.net
- hbo.com.edgesuite.net
Hulu
- hulu.com
- huluad.com
- huluim.com
- hulumail.com
- hulustream.com
- cs428.wpc.edgecastcdn.net
- cws-hulu.conviva.com
- hulu-ios.hb-api.omtrdc.net
- hulu.com.c.footprint.net
- hulu.map.fastly.net
- assetshuluimcom-a.akamaihd.net
MS Teams Audio/Video Calls
- lync.com
- teams.microsoft.com
- 13.107.64.0/18
- 52.112.0.0/14
- 52.122.0.0/15
- 52.112.0.0/14
- 52.122.0.0/15
- 52.238.119.141/32
- 52.244.160.207/32
Netflix
- fast.com
- nflxso.net
- nflxvideo.net
- nflximg.net
- netflix.ca
- nflxext.com
- netflixstudios.com
- netflix.net
- netflix.com
Pandora
- pandora.com
- p-cdn.com
- p-cdn.us
Plex
- plex.tv
- plex.bz
- plex.tv.cdn.cloudflare.net
- plexapp.com
- plexapp.com.cdn.cloudflare.net
Soundcloud
- sndcdn.com
- soundcloud.com
Spotify
- pscdn.co
- scdn.co
- spoti.fi
- spotify.com
- spotifycdn.com
- spotifycdn.net
- spotifycharts.com
- spotifycodes.com
- spotifyjobs.com
- spotify.map.fastly.net
- spotifynewsroom.jp
- spotilocal.com
- tospotify.com
Steam
- s.team
- steam-chat.com
- steamchina.com
- steamcommunity.com
- steamcontent.com
- steamgames.com
- steampowered.com
- steampowered.com.8686c.com
- steamstatic.com
- steamstatic.com.8686c.com
- steamusercontent.com
- valve.net
- valvesoftware.com
- steambroadcast.akamaized.net
Vimeo
- vimeo.com
- vimeocdn.com
- vhx.tv
- vhx.com
Webex
- ciscospark.com
- ciscospark.statuspage.io
- ciscowebex.com
- wbx2.com
- webex.ca
- webex.co.in
- webex.co.it
- webex.co.jp
- webex.co.kr
- webex.co.nz
- webex.co.uk
- webex.com
- webex.com.au
- webex.com.br
- webex.com.cn
- webex.com.hk
- webex.com.mx
- webex.de
- webex.es
- webex.fr
- webexapis.com
- webexapps.com
- webexconnect.com
- webexcontent.com
- ciscospark.com.edgekey.net
- ciscowebex.demdex.net
Windows Updates
- windowsupdate.microsoft.com
- update.microsoft.com
- windowsupdate.com
- download.microsoft.com
- wustat.windows.com
- ntservicepack.microsoft.com
- stats.microsoft.com
- prod.do.dsp.mp.microsoft.com
- dl.delivery.mp.microsoft.com
- delivery.mp.microsoft.com
- adl.windows.com
- tsfe.trafficshaping.dsp.mp.microsoft.com
- emdl.ws.microsoft.com
- definitionupdates.microsoft.com
Youtube
- youtube.com
- youtubeeducation.com
- youtubekids.com
- yt.be
- ytimg.com
- yt3.ggpht.com
- googlevideo.com
- gvt1.com
- video.google.com
- youtu.be
- youtube-nocookie.com
- youtube-ui.l.google.com
Zoom
- zoom.com
- zoom.us