> For the complete documentation index, see [llms.txt](https://docs.enginsight.com/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.enginsight.com/docs/knowledge-base/english/managed-service-providers/how-do-i-ensure-a-working-connection-to-the-enginsight-license-server.md).

# How do I ensure a working connection to the Enginsight License Server?

To participate in the Managed Services Provider (MSP) program and use the contractually agreed services without interruption, your systems require a working connection to the centrally hosted License Server of Enginsight GmbH.

To ensure this, communication between your IT infrastructure and the domain `*.enginsight.com` must be possible without restrictions. If traffic is blocked, filtered, or modified by security systems such as firewalls, proxy systems, or upstream web application firewalls (WAFs), this can affect license validation and cause the contractually agreed services to fail.

{% hint style="danger" %}
**Please note**: The technical requirements are only considered properly implemented once you have **verified their effectiveness**. This applies in particular to all systems on which the Enginsight platform is running.
{% endhint %}

***

## Technical Requirements

Below you will find all technical requirements for ensuring uninterrupted connectivity to the Enginsight License Server.

{% hint style="danger" %}
**Please note**: All allowlist entries and other requirements must be implemented and observed both centrally and on **every individual virtual machine (VM)** on which the Enginsight platform is running.
{% endhint %}

### Network Allowlist Entries

The following parameters must be allowed in your firewall, your proxy, and any upstream WAF:

<table><thead><tr><th width="200.4921875">Parameter</th><th>Value</th></tr></thead><tbody><tr><td>Target domain</td><td>*.enginsight.com</td></tr><tr><td>Port</td><td>443 (HTTPS)</td></tr><tr><td>Protocol</td><td>TCP</td></tr></tbody></table>

### SSL/TLS Inspection

Traffic to the domain \*.enginsight.com must be explicitly excluded from SSL/TLS inspection (deep packet inspection).

{% hint style="danger" %}
**Please note**: This requirement applies not only to firewalls and proxy systems, but **explicitly** also to any upstream WAF.
{% endhint %}

### Additional Requirements

The central License Server validates your instance's license tokens. To ensure uninterrupted license validation, the following must also be ensured:

* The domain of the Enginsight API must be reachable from your infrastructure.
* DNS queries must resolve correctly.
* Response times (latencies) must be within the usual range.

***
