Systam Visit network and firewall requirements

Modified on Mon, 7 Sep at 3:08 PM

Systam Visit works reliably once a few things are allowed on your network — whether you're using self-service kiosks, Rooms displays, or just signing in to Systam Studio. This is the full list for your IT team.

Systam Studio

Studio runs in your browser at app.systam.io — there's nothing to install, but your network still needs to allow HTTPS access to the domain below. If this is blocked, Studio may load the page but fail to show your data properly.

DestinationPort / protocolDirection
*.systam.ioTCP 443 (HTTPS)Outbound

Self-service kiosks

The kiosk talks to a few separate services: Systam's own cloud, EloView (which manages the device remotely and pushes software updates), our remote support tool, and Systam Pass if your visitors complete inductions on the kiosk.

DestinationPort / protocolPurpose
*.systam.ioTCP 443 (HTTPS)All communication with Systam Visit
secure-api.eloview.com, secure-provisioning.eloview.com, secure-auth.eloview.com, secure-broker.eloview.com, secure-logs.eloview.com, secure-content.eloview.comTCP 443 (HTTPS), TCP 8883 (MQTT over TLS)EloView device management — provisioning, login, updates, logs
secure.eloview.com, polaris-prod-public-ota.s3.us-west-2.amazonaws.comTCP 443 (HTTPS)System and app updates via EloView
2.android.pool.ntp.orgUDP 123 (NTP)Keeps the device clock in sync — required just to connect
*.teamviewer.comTCP/UDP 5938 (preferred) or TCP 443Remote support from our team
pass.fiTCP 443 (HTTPS)Only if visitors complete Systam Pass inductions on the kiosk

EloView's own list of addresses is longer and updated more often than we can keep track of here — for the complete, current list, check EloView's network requirements article. Whitelist by domain name rather than IP address — these services run behind a CDN, so IP addresses change without notice.

Rooms displays

Rooms displays need the same Systam domain, plus two more connections of their own.

DestinationPort / protocolPurpose
*.systam.ioTCP 443 (HTTPS)Device connectivity, configuration, and updates
time.android.comUDP 123 (NTP)Keeps the display's clock in sync
ws-eu.pusher.comReal-time device status and update notifications

No personal or customer data is transmitted through the time sync or Pusher connections. For more detail, see Required network access for Systam Rooms device.

Proxy or SSL inspection?

If your network runs traffic through a proxy or does SSL inspection, exclude the domains above from inspection. Inspection can block the connection even when the address itself is allowed through the firewall.

A quick way to check for a firewall block

If a kiosk, a Rooms display, or Studio suddenly stops working properly, one way to check whether your network is blocking Systam is to open https://api.systam.io directly on a computer on the same network. You should get some kind of response back from our server — even an error page is fine, that just means the connection reaches us. If your browser can't connect at all, times out, or shows a message from your own firewall or antivirus software instead, that's a sign the connection is being blocked on your end.

Some firewalls categorize websites automatically, and api.systam.io has occasionally been miscategorized as suspicious by mistake. If the check above suggests a block, ask your IT team to check with your firewall vendor how api.systam.io is currently categorized.

Related articles

That's the full list — once your firewall allows it, Systam Visit should stay connected without any surprises.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article