Configure communications with the Insight Platform

Still need to opt-in to the cloud?

See Activating your console on the Insight Platform for instructions.

Data upload

You may need to configure your firewall rules to allow outbound connectivity to the following hostnames according to your selected region in order to successfully upload data to the Insight Platform:

Is your Rapid7 product subscription provisioned for the United States? Check your region code first!

As of April 12th, 2021, all new customers subscribing to Rapid7 Insight products that elect to store their data in the United States will be provisioned for one of three data centers. Since these data centers have unique endpoints, any firewall rules you configure must correspond to the data center your organization is assigned to. Follow these steps to determine which United States data center your organization is part of:

  1. Go to insight.rapid7.com and sign in with your Insight account email address and password.
  2. Navigate to the Platform Home page.
    • If you are not taken to this page by default, expand the product dropdown in the upper left and click My Account.
  3. Look for the Data Storage Region tag in the upper right corner of the page below your account name. Your United States region tag will show one of the following data centers:
    • United States - 1
    • United States - 2
    • United States - 3

All hostnames listed below are reached via TCP port 443.

RegionWebDataS3
United States - 1exposure-analytics.insight.rapid7.comus.deployment.endpoint.ingress.rapid7.com
https://us.api.endpoint.ingress.rapid7.com:443
s3.amazonaws.com
United States - 2us2.exposure-analytics.insight.rapid7.comus2.deployment.endpoint.ingress.rapid7.com
https://us2.api.endpoint.ingress.rapid7.com:443
s3.us-east-2.amazonaws.com
United States - 3us3.exposure-analytics.insight.rapid7.comus3.deployment.endpoint.ingress.rapid7.com
https://us3.api.endpoint.ingress.rapid7.com:443
s3.us-west-2.amazonaws.com
Canadaca.exposure-analytics.insight.rapid7.comca.deployment.endpoint.ingress.rapid7.com
https://ca.api.endpoint.ingress.rapid7.com:443
s3.ca-central-1.amazonaws.com
Europeeu.exposure-analytics.insight.rapid7.comeu.deployment.endpoint.ingress.rapid7.com
https://eu.api.endpoint.ingress.rapid7.com:443
s3.eu-central-1.amazonaws.com
Japanap.exposure-analytics.insight.rapid7.comap.deployment.endpoint.ingress.rapid7.com
https://ap.api.endpoint.ingress.rapid7.com:443
s3-ap-northeast-1.amazonaws.com
s3.ap-northeast-1.amazonaws.com
Australiaau.exposure-analytics.insight.rapid7.comau.deployment.endpoint.ingress.rapid7.com
https://au.api.endpoint.ingress.rapid7.com:443
s3-ap-southeast-2.amazonaws.com
s3.ap-southeast-2.amazonaws.com

Test This!

You can test your connection to the Insight Platform with the Security Console's Cloud Diagnostics tool. To do so, click the Administration tab, in Console > Troubleshooting section, click Troubleshoot issues.
Uncheck all boxes except for Cloud Diagnostics and click Perform Diagnostics.
After a few seconds, you'll see if you can communicate with the Insight Platform!

Ticketing and Container Registry connections

Rapid7 provides the following list of static IP addresses that you may use to allow traffic originating from the Insight Platform to your on-premises JIRA or container registries:

NOTE

This does not address agent proxying use cases or scenarios relating to communication originating from customer environments to the Insight Platform.

All IP addresses listed below are reached via TCP port 443.

United States - 1United States - 2United States - 3CanadaEuropeJapanAustralia
52.87.0.923.132.61.19244.235.43.23735.182.161.11152.28.227.7213.113.44.1513.55.206.11
34.203.6.733.137.118.10252.10.164.19752.60.69.6052.58.219.3252.69.171.12713.54.208.29
34.202.19.1383.14.210.19652.88.123.23752.63.226.244
52.2.37.56

Data Transmitted to the Insight Platform

The following types of information are transmitted to the Insight Platform:

  • Asset information
  • Asset groups
  • Asset owners
  • Vulnerabilities
  • Vulnerability exceptions
  • Tags
  • Scan Engine information
  • InsightVM Console information
  • User information

InsightVM does not transmit service or user credentials of any kind to the Insight Platform.

Looking for Security Console port information?

See Requirements for console-specific port needs.