Networking & Firewall Considerations
Different parts of the GovWorx application suite require special network configuration. Use the sections below to identify what firewall rules apply to your deployment.
On-Prem Data Agent — CAD / VLR / Telephony
The following hosts, protocols, and ports are required for the on-prem Data Agent to communicate with GovWorx's secure AWS GovCloud environment for CAD and VLR data.
This is also outlined in the Data Agent Installation Checklist.
Host | Port | Purpose |
app.govworx.net | 443 | Main application |
govworx-cad-incidents.s3-fips.us-gov-west-1.amazonaws.com | 443 | CAD Uploads |
gw-coach-temp-upload-storage.s3-fips.us-gov-west-1.amazonaws.com | 443 | Audio Uploads |
gw-data-agent.s3.us-gov-west-1.amazonaws.com | 443 | Data Agent Installer |
otlp.us5.datadoghq.com | 443 | Agent Logs |
ocsp.r2m01.amazontrust.com (OCSP) crl.r2m01.amazontrust.com (CRL) crt.r2m01.amazontrust.com (CA Issuers)
Alternatively, a wildcard rule for *.r2m01.amazontrust.com covers all three hosts. | 80 | SSL Certificate Check |
On-Prem Data Agent — Telephony / ANI-ALI
⚠️ This section is only required if your agency is implementing a Telephony and ANI/ALI connection.
The following hosts must be allowlisted on end user workstations for telephony connectivity. These entries are also required if your agency has purchased CommsCoach Assist. See the Assist section below for details.
Host | Port | Purpose |
rum.govworx.net | 443 | CommsCoach Assist |
realtime.govworx.net | 443 | CommsCoach Assist |
pubsub.govworx.net | 443 | CommsCoach Assist |
End User & Application Access
The following firewall rules apply to workstations and devices used by end users to access GovWorx web applications.
Web Applications — QA / Training / Hire
Required for all agencies using the core GovWorx platform.
Host | Port | Purpose |
app.govworx.net | 443 | Main application |
portal.govworx.net | 443 | End user portal |
simulate.govworx.net | 443 | Simulator |
livekit.govworx.net | 443 | Simulator |
turn.govworx.net | 3478, 60001–65001 | Simulator |
speech.microsoft.com | 443 | Scripted caller accessibility |
api.openai.com | 443 | Smart Caller backend (API calls) |
realtime.api.openai.com | 443 | Smart Caller primary WebRTC audio transport |
Web Applications — CommsCoach Assist
⚠️ This section is only required if your agency has purchased CommsCoach Assist.
The following hosts must be allowlisted on end user workstations for Assist functionality.
Host | Port | Purpose |
realtime.govworx.net | 443 | CommsCoach Assist |
rum.govworx.net | 443 | CommsCoach Assist |
pubsub.govworx.net | 443 | CommsCoach Assist |
pubsub-a.govworx.net | 443 | CommsCoach Assist |
pubsub-b.govworx.net | 443 | CommsCoach Assist |
pubsub-c.govworx.net | 443 | CommsCoach Assist |
pubsub-d.govworx.net | 443 | CommsCoach Assist |
pubsub-e.govworx.net | 443 | CommsCoach Assist |
