<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP address ranges for smartreceiver.cisco.com in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266465#M344777</link>
    <description>&lt;P&gt;Hello Georg,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the iACL is used as a Control Plane Protection, it is not about blocking specific websites. It is just a whitelist to permit specific IPs TO the device (like NTP server, specific management subnets, specific BGP neighbors, ...) and drop everything else TO the device. And then permit all transit traffic afterwards.&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jan 2021 15:05:24 GMT</pubDate>
    <dc:creator>Daniel-nl</dc:creator>
    <dc:date>2021-01-04T15:05:24Z</dc:date>
    <item>
      <title>IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266294#M344760</link>
      <description>&lt;P&gt;Hi colleagues,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my IOS-XE Routing and Switching devices configured for "Smart Licensing Using policy" communicate directly with CSSM, which is smartreceiver.cisco.com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I'm securing my devices with an Infrastructure ACL, I'm wondering if there is any documentation which IP addresses and ports from CSSM have to communicate with my devices, as I was not able to find any.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From different ping checks and packet captures, I was able to see the following Cisco IPs with port 443 incoming:&lt;/P&gt;&lt;P&gt;72.163.10.105&lt;BR /&gt;173.37.149.105&lt;BR /&gt;64.101.38.11&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are these the only 3 IPs which have to communicate with my devices? Or are there others as well? Any public documentation about this?&lt;BR /&gt;&lt;BR /&gt;Thanks for your help in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 10:59:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266294#M344760</guid>
      <dc:creator>Daniel-nl</dc:creator>
      <dc:date>2021-01-04T10:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266304#M344761</link>
      <description>&lt;P&gt;CSSM&amp;nbsp; - is this onpremises VM&amp;nbsp; you have ? &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Smart License use like any other https services, the activation service will be contacting always their Loadbalance and redirecting to based on the location or region some time ( as per i know)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since this outgoing only to register with smartnet portal for License.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is the process :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/switches/catalyst-9500-series-switches/214484-cisco-smart-licensing-troubleshooting.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/switches/catalyst-9500-series-switches/214484-cisco-smart-licensing-troubleshooting.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 11:14:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266304#M344761</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-01-04T11:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266309#M344762</link>
      <description>&lt;P&gt;Hello Balaji,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no, as I mentioned my devices are connecting directly to the Cisco Cloud, which is &lt;A href="https://smartreceiver.cisco.com/licservice/license" target="_blank"&gt;https://smartreceiver.cisco.com/licservice/license&lt;/A&gt;. There is no on-premise VM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"SL Using Policy" needs to push license reports to the Cisco Cloud, and needs to receive push ACKs as well. The question is, which IPs do I have to permit in my iACL to receive this push ACKs and not discard them?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 11:22:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266309#M344762</guid>
      <dc:creator>Daniel-nl</dc:creator>
      <dc:date>2021-01-04T11:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266360#M344765</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in addition to the IP addresses you have already captured, according the Cisco Live presentation linked below (page 18), CSSM uses these DNS names and ports:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Authorized Backends&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco Smart Software Manager (CSSM) (cisco.com)&lt;BR /&gt;HTTPS: tools.cisco.com (Port 443)&lt;BR /&gt;HTTP: &lt;A href="http://www.cisco.com" target="_blank"&gt;www.cisco.com&lt;/A&gt; (Port 80) (Cert Downloads)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Satellite&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;User Interface: HTTPS (Port 8443)&lt;BR /&gt;Products: HTTPS (Port 443), HTTP (Port 80)&lt;BR /&gt;CSSM: HTTPS (tools.cisco.com, api.cisco.com, cloudsso.cisco.com)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These names resolve to the following IP addresses:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cloudsso.cisco.com 72.163.4.74&lt;BR /&gt;cloudsso2.cisco.com 173.37.144.211&lt;BR /&gt;cloudsso3.cisco.com 173.38.127.38&lt;BR /&gt;tools.cisco.com 72.163.4.38&lt;BR /&gt;api.cisco.com 173.37.145.221&lt;/P&gt;
&lt;P&gt;cisco.com 72.163.4.185 --&amp;gt; this might be different depending on which country you are in&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/latam/docs/2018/pdf/BRKARC-2034.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/latam/docs/2018/pdf/BRKARC-2034.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I guess if you keep the three ports (80,443,8443) open for these IP addresses, Smart Licensing should be able to communicate with the CSSM server(s).&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 13:08:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266360#M344765</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2021-01-04T13:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266369#M344767</link>
      <description>&lt;P&gt;Hello Georg,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;thanks for your reply. Unfortunately this is only applicable to legacy "Smart Licensing", not to "Smart Licensing Using Policy". "SLUP" uses&lt;BR /&gt;"smartreceiver.cisco.com" instead of "tools.cisco.com", and it seems that "Smart Licensing Using Policy" uses different IP addresses to communicate.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;It is a bit weird that there is (almost) no public documentation from Cisco regarding this, as so many devices need to communicate to the Cisco cloud. For now it seems fine if I permit the whole supernets from Cisco (72.163.0.0/16, 173.36.0.0/14, 64.101.0.0/17) Port 443 incoming. But there should be something official and public about this important topic (I hope that I'm not the only one with iACLs deployed).&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 13:26:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266369#M344767</guid>
      <dc:creator>Daniel-nl</dc:creator>
      <dc:date>2021-01-04T13:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266370#M344768</link>
      <description>&lt;P&gt;i done some random lookup they always resolve as per your results :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;72.163.10.105&lt;BR /&gt;173.37.149.105&lt;BR /&gt;64.101.38.11&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 13:27:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266370#M344768</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-01-04T13:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266378#M344769</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;odd indeed that there is hardly any public information to be found. I can imagine, though, that Cisco is reluctant to publish these IP addresses, as they can be used for DDOS attacks, or some other exploits.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cae-xprp-rcdn-vip.cisco.com [72.163.10.105]&lt;BR /&gt;cae-xprp-alln-vip.cisco.com [173.37.149.105]&lt;BR /&gt;cae-xprp-rtp-vip.cisco.com [64.101.38.11]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess if you allow the supernets, that is the most you can do.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 13:40:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266378#M344769</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2021-01-04T13:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266431#M344772</link>
      <description>&lt;P&gt;Thanks guys for your replies.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 14:28:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266431#M344772</guid>
      <dc:creator>Daniel-nl</dc:creator>
      <dc:date>2021-01-04T14:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266456#M344775</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;just out of curiosity, what sites/IP addresses do you want to allow/block ? The public Internet is huge, I haven't found a comprehensive ACL example yet that blocks proven malicious external sites.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 14:56:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266456#M344775</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2021-01-04T14:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266463#M344776</link>
      <description>&lt;P&gt;Until there is an inttellegent device grab the IP address from RBL or any other source of IP Block lists, its hard to get work to be done.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;that is the reason if the device behind proxy or any other content filter you can easy to allow or deny. (just thought)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 15:03:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266463#M344776</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-01-04T15:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266465#M344777</link>
      <description>&lt;P&gt;Hello Georg,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the iACL is used as a Control Plane Protection, it is not about blocking specific websites. It is just a whitelist to permit specific IPs TO the device (like NTP server, specific management subnets, specific BGP neighbors, ...) and drop everything else TO the device. And then permit all transit traffic afterwards.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 15:05:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4266465#M344777</guid>
      <dc:creator>Daniel-nl</dc:creator>
      <dc:date>2021-01-04T15:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4391582#M349904</link>
      <description>&lt;P&gt;Be aware for a new IP: 192.133.220.90&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I opened a case with Cisco to ask if any static IP is available, but the answer was no.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 14:30:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4391582#M349904</guid>
      <dc:creator>Cesare</dc:creator>
      <dc:date>2021-04-22T14:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4392805#M350002</link>
      <description>&lt;P&gt;Thank you for the hint. It is really unbelievable that Cisco is not providing any documentation for the used public IPs.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Apr 2021 13:18:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4392805#M350002</guid>
      <dc:creator>Daniel-nl</dc:creator>
      <dc:date>2021-04-25T13:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4858065#M385295</link>
      <description>&lt;P&gt;Sadly this issue is still relevant in 2023&lt;/P&gt;&lt;P&gt;However there is workaround if you are using a ios x.e device:&lt;/P&gt;&lt;P&gt;1 - create an object-group i.e&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; object-group network URL_DNS_HOSTS&lt;BR /&gt;2 - create an eem script to update the object group regularly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; event manager applet URL_DNS_UPDATE authorization bypass&lt;BR /&gt;&amp;nbsp;&amp;nbsp; event timer watchdog time 250&lt;BR /&gt;&amp;nbsp;&amp;nbsp; action 0.1 cli command "enable"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; action 0.2 cli command "conf t"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; action 2.1 cli command "object-group network URL_DNS_HOSTS"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; action 2.3 cli command "host smartreceiver.cisco.com"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; action 2.4 syslog priority informational msg "DNS object-group has been updated via EEM"&lt;/P&gt;&lt;P&gt;3 - Apply the object-group to an acl that is applied on the internet facing device interface&lt;/P&gt;&lt;P&gt;The object group will update the host ips of smartreciever since the object group is added to an ACL, the ACL will update regularly with any new ip&lt;/P&gt;&lt;P&gt;72.163.15.137&lt;BR /&gt;192.133.220.120&lt;BR /&gt;173.36.127.32&lt;/P&gt;&lt;P&gt;AFIK, there are only 3 valid ip's for the &lt;STRONG&gt;smartreceiver.cisco.com&lt;/STRONG&gt;, regardless this method will automatically update if any new one appears.&lt;/P&gt;&lt;P&gt;Its incredible that in 2023 the IOS X.E ACL still cannot handle dns names, and instead just resolves the url into&amp;nbsp; the 1st ip it resolves, this might have been acceptable 20years ago but now its just strange how this never got improved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 07:35:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/4858065#M385295</guid>
      <dc:creator>Nuno Melo</dc:creator>
      <dc:date>2023-06-20T07:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: IP address ranges for smartreceiver.cisco.com</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/5151096#M401805</link>
      <description>&lt;P&gt;From Cisco TAC:&lt;/P&gt;&lt;P&gt;For "call-home" transport method--&amp;gt;&lt;/P&gt;&lt;P&gt;Domain Name: tools.cisco.com&lt;BR /&gt;Address: 72.163.4.38&lt;/P&gt;&lt;P&gt;b. For "smart" transport method--&amp;gt;&lt;/P&gt;&lt;P&gt;Domain Name: smartreceiver.cisco.com&lt;BR /&gt;Address: 146.112.59.81&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 13:27:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/ip-address-ranges-for-smartreceiver-cisco-com/m-p/5151096#M401805</guid>
      <dc:creator>FlarkySmoo</dc:creator>
      <dc:date>2024-07-25T13:27:12Z</dc:date>
    </item>
  </channel>
</rss>

