Systam Visit works reliably once a few things are allowed on your network — whether you're using self-service kiosks, Rooms displays, or just signing in to Systam Studio. This is the full list for your IT team.
Systam Studio
Studio runs in your browser at app.systam.io — there's nothing to install, but your network still needs to allow HTTPS access to the domain below. If this is blocked, Studio may load the page but fail to show your data properly.
| Destination | Port / protocol | Direction |
|---|---|---|
| *.systam.io | TCP 443 (HTTPS) | Outbound |
Self-service kiosks
The kiosk talks to a few separate services: Systam's own cloud, EloView (which manages the device remotely and pushes software updates), our remote support tool, and Systam Pass if your visitors complete inductions on the kiosk.
| Destination | Port / protocol | Purpose |
|---|---|---|
| *.systam.io | TCP 443 (HTTPS) | All communication with Systam Visit |
| secure-api.eloview.com, secure-provisioning.eloview.com, secure-auth.eloview.com, secure-broker.eloview.com, secure-logs.eloview.com, secure-content.eloview.com | TCP 443 (HTTPS), TCP 8883 (MQTT over TLS) | EloView device management — provisioning, login, updates, logs |
| secure.eloview.com, polaris-prod-public-ota.s3.us-west-2.amazonaws.com | TCP 443 (HTTPS) | System and app updates via EloView |
| 2.android.pool.ntp.org | UDP 123 (NTP) | Keeps the device clock in sync — required just to connect |
| *.teamviewer.com | TCP/UDP 5938 (preferred) or TCP 443 | Remote support from our team |
| pass.fi | TCP 443 (HTTPS) | Only if visitors complete Systam Pass inductions on the kiosk |
EloView's own list of addresses is longer and updated more often than we can keep track of here — for the complete, current list, check EloView's network requirements article. Whitelist by domain name rather than IP address — these services run behind a CDN, so IP addresses change without notice.
Rooms displays
Rooms displays need the same Systam domain, plus two more connections of their own.
| Destination | Port / protocol | Purpose |
|---|---|---|
| *.systam.io | TCP 443 (HTTPS) | Device connectivity, configuration, and updates |
| time.android.com | UDP 123 (NTP) | Keeps the display's clock in sync |
| ws-eu.pusher.com | — | Real-time device status and update notifications |
No personal or customer data is transmitted through the time sync or Pusher connections. For more detail, see Required network access for Systam Rooms device.
Proxy or SSL inspection?
If your network runs traffic through a proxy or does SSL inspection, exclude the domains above from inspection. Inspection can block the connection even when the address itself is allowed through the firewall.
A quick way to check for a firewall block
If a kiosk, a Rooms display, or Studio suddenly stops working properly, one way to check whether your network is blocking Systam is to open https://api.systam.io directly on a computer on the same network. You should get some kind of response back from our server — even an error page is fine, that just means the connection reaches us. If your browser can't connect at all, times out, or shows a message from your own firewall or antivirus software instead, that's a sign the connection is being blocked on your end.
Some firewalls categorize websites automatically, and api.systam.io has occasionally been miscategorized as suspicious by mistake. If the check above suggests a block, ask your IT team to check with your firewall vendor how api.systam.io is currently categorized.
Related articles
- Setting up a new visitor kiosk
- The kiosk has no network connection
- Required network access for Systam Rooms device
- Troubleshooting Systam Rooms displays
That's the full list — once your firewall allows it, Systam Visit should stay connected without any surprises.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article