Enterprise Networking Requirements
Available in sensor version 1.2.4+
Enterprise Networking is enabled by default in all Linux EDR instances and may be leveraged to connect to a limited range of addresses. This allows you to connect to a single Red Canary domain, https://cwp-ingest.redcanary.io, for delivery of all telemetry and health and error reporting. This is available in any paid Linux EDR account.
Add the following keys to /opt/redcanary/config.json. Both are required for enabling enterprise networking. These values are available in Red Canary under Endpoints > Deploy Sensors or at https://go.my.redcanary.co/endpoints/deploy_sensors.
Migrating from Standard to Enterprise Networking
If you are already using Red Canary Linux EDR without Enterprise Networking, you can migrate to it by adding the outpost_auth_token and offload_target to your config.json file, and restarting the service. You must be on sensor version 1.2.4 or above to use Enterprise Networking.
Once the new configuration is saved, restart the service for enterprise networking to take effect.
systemctl restart cfsvcd
Please allow-list https://cwp-ingest.redcanary.io.
If there are any issues, check the sensor log file for errors relating to
Outpost and reach out for support if needed. You can contact us in your dedicated Slack channel or at firstname.lastname@example.org.
Standard Networking Requirements
If you do not want to use Enterprise Networking for any reason or are on a sensor version older than 1.2.4, Red Canary also supports standard networking. The following will need to be allowed in your firewall.
- s3-us-east-2.amazonaws.com (tcp/443)
- 184.108.40.206 (tcp/443)
- 220.127.116.11 (tcp/443)
You will also need to remove the offload_target and outpost_auth_token from your config.json file:
Proxy SupportTo utilize a SOCKS proxy:
- Set the
- Or, add the following to config.json: