# IP whitelisting

> Allow Testsigma's IPs and domains through your firewall so cloud executions reach a private-network application, and know when Tunnel is the right tool instead.

Testsigma's cloud runs tests from its own infrastructure, so an application behind a firewall rejects those requests unless the firewall knows to allow them. Whitelisting adds Testsigma's addresses to that allowed list.

Whitelisting reaches an application on a private network. It cannot reach one hosted on `localhost` or a developer's own machine. For that, use [Testsigma Tunnel](https://testsigma.com/docs/v2/get-started/installation/testsigma-tunnel/) or run on local devices.

## Find the addresses

Go to **Settings > Testsigma IP**. Two sets are listed, and both matter:

- **Testsigma Server IP**: the server where executions run on Testsigma's device cloud
- **Testsigma Lab IPs**: the labs holding your account's test assets and data

Give both to your network administrator or infosec team to add to the firewall's allowed list.

Whitelisting applies to ad-hoc runs and test plan executions alike, since both originate from those addresses.

## Domains to allow

An IP allowlist is not always enough. Where outbound traffic is filtered by domain, these have to be reachable as well.

| Purpose | Domain |
|---|---|
| Local agent and cloud services | `app.testsigma.com` |
| Testsigma Tunnels | `connect.testsigma.com` |
| Mobile Recorder | `mobilerecorder.testsigma.com` |
| Asset Proxy | `asset-proxy.testsigma.com` |
| Identity | `id.testsigma.com` and `static-id.testsigma.com` |

The agent also downloads browser drivers on demand, from `googlechromelabs.github.io`, `chromedriver.storage.googleapis.com`, `storage.googleapis.com`, `registry.npmmirror.com`, and `raw.githubusercontent.com` for Chrome and Firefox, and `msedgewebdriverstorage.blob.core.windows.net` for Edge and Internet Explorer.

## What does not need whitelisting

The Testsigma Agent needs no inbound rule at all. It queries Testsigma's servers and receives responses, and Testsigma never initiates a connection to it, so nothing has to be opened inward. Outgoing connections to `*.testsigma.com` on port 443 do have to be allowed.

Testsigma Tunnel works the same way. It opens an outbound connection and accepts none, which is why it reaches an application that whitelisting cannot.

## Choose the right option

| Your application is | Use |
|---|---|
| Reachable from the internet | Nothing. Cloud execution works as it is |
| On a private network, reachable by IP | IP whitelisting, then cloud execution |
| On `localhost` or a developer machine | Testsigma Tunnel, or the agent on local devices |
| Needing a specific physical device | The agent on local devices |

See [Run tests](https://testsigma.com/docs/v2/run-tests/test-runs/) and [Testsigma Tunnel](https://testsigma.com/docs/v2/get-started/installation/testsigma-tunnel/).
