Home/Resources/Network requirements

Network requirements for Polaris

Read network documentation ↗

Plan your Polaris deployment with the ports, protocols, and endpoints your network team needs to review. Start with the cloud connections, check the local sharing paths, and use the reference design to assess your VLAN rules.

Outbound · cloud services

Connect Pods and clients to cloud services

Allow outbound HTTPS on TCP 443 from both the Pod VLAN and the client VLAN to the endpoints below. These connections support signaling, licensing, and management. When the sharing device and Pod are on the same network, their shared content does not travel through these cloud endpoints.

PortProtocolEndpointPurpose
TCP 443HTTPS/TLSapp.mersive.comPortal / signaling server
TCP 443HTTPS/TLSdisplay.mersive.comMersive display app
TCP 443HTTPS/TLSmcsapi.mersive.comPolaris API service
TCP 443HTTPS/TLSwebrtc.mersive.comWebRTC signaling server
TCP 443HTTPS/TLShosted.mender.ioUpdate server
TCP 443HTTPS/TLShosted-mender-artifacts.s3.amazonaws.comUpdate artifacts (AWS S3)
TCP 443HTTPS/TLSc271964d41749feb10da762816c952ee.r2.cloudflarestorage.comUpdate artifacts (Cloudflare R2)
TCP 443HTTPS/TLSapp.launchdarkly.comFeature flags
TCP 443HTTPS/TLSclientstream.launchdarkly.comFeature flag streaming
TCP 443HTTPS/TLSevents.launchdarkly.comFeature flag events
TCP 443HTTPS/TLSfirestore.googleapis.comReal-time state sync
TCP 443HTTPS/TLSfirebasestorage.googleapis.comStorage & licensing info
TCP 443HTTPS/TLSidentitytoolkit.googleapis.comAuthentication (identity)
TCP 443HTTPS/TLSsecuretoken.googleapis.comAuthentication (token)
Outbound · UDP

Allow time sync and NAT traversal

Allow the outbound UDP traffic below through your firewall and NAT policies. Clock drift over two minutes breaks TLS certificate validation.

PortProtocolEndpointPurpose
UDP 123NTPntp.mersive.comTime sync (fallback: time.google.com)
UDP 19302STUNstun.l.google.comWebRTC NAT traversal
UDP 19302STUNstun1.l.google.comNAT traversal (backup)
Outbound · TURN relay

Allow the TURN relay for restrictive networks

The TURN relay is optional and enabled per organization. Media goes through it only when no direct or STUN-assisted path can form, or when an administrator forces relayed connections. Pods and sharing clients connect to it outbound only, so nothing needs to be opened inbound. The relay is IPv4 only.

PortProtocolEndpointPurpose
UDP 3478TURN / STUNMersive TURN relay (address in your organization's ICE settings in the Polaris portal)Relay allocation and NAT discovery
TCP 3478TURNMersive TURN relayRelay allocation where outbound UDP 3478 is blocked
UDP 49152–49751TURN relayMersive TURN relayRelayed media

The relay port range may change as capacity is adjusted. The Mersive relay has no TLS or port 443 path. Organizations that need one should use the Cloudflare relay below.

If your organization uses the Cloudflare relay, allow these instead:

PortProtocolEndpointPurpose
UDP 3478 (alt. UDP 443)TURNturn.cloudflare.comRelay over UDP
TCP 3478 (alt. TCP 80)TURNturn.cloudflare.comRelay over TCP
TCP 5349 (alt. TCP 443)TURN over TLSturn.cloudflare.comRelay over TLS
UDP 3478STUNstun.cloudflare.comNAT discovery

Cloudflare serves its relay from an anycast network and publishes no fixed relay port range.

Local · discovery

Allow multicast discovery on the Pod VLAN

AirPlay and Google Cast use local discovery to find the room. Allow the multicast traffic below on the Pod VLAN. Filtering this traffic prevents native casting discovery; joining through the browser is unaffected.

PortProtocolMulticast addressPurpose
UDP 5353mDNS224.0.0.251AirPlay + Mersive discovery (Bonjour)
UDP 1900SSDP239.255.255.250Google Cast / UPnP discovery
Inter-VLAN · Pod-side ports

Connect the client VLAN to the Pod VLAN

When Pods and client devices are on separate VLANs, allow traffic to the Pod-side ports below for casting and sharing. The WebRTC media path also requires bidirectional UDP traffic between the two VLANs.

PortProtocolPurpose
TCP 7000AirPlayAirPlay service
TCP 7001AirPlayAirPlay mirroring
TCP 7100AirPlayAirPlay control channel
TCP 7236MiracastMiracast RTSP / control
TCP 8008Google CastCast HTTP
TCP 8009Google CastCast TLS
TCP 8443MersiveMersive secure service
TCP 443HTTPSReachability (diagnostic validation)
Port rangeProtocolDirectionPurpose
UDP 40000–49999RTP/RTCPClient VLAN ⇄ Pod VLANWebRTC media stream (screen sharing), bidirectional

The required production range is UDP 40000–49999. The diagnostic tool samples that range and also spot-checks UDP 32768–39999 and UDP 50000–65535 to identify partial blocks. Those additional probes are diagnostic checks, not additional production port requirements.

Reference architecture

Review the VLAN reference design

This reference design separates client devices on VLAN 10 from Pods on VLAN 20, with a stateful firewall between them. Use the traffic flows below alongside the detailed tables above when reviewing your network rules.

Traffic flowPortsPurpose
VLAN 10 (client) → internetTCP 443 outboundThe 14 cloud endpoints above
VLAN 20 (pod) → internetTCP 443 outboundThe 14 cloud endpoints above
VLAN 10 → VLAN 20TCP 7000–7001, 7100, 7236, 8008–8009, 8443Casting and discovery
VLAN 10 ⇄ VLAN 20UDP 40000–49999WebRTC media (screen sharing)
Both VLANs → internetUDP 19302 outboundSTUN (NAT traversal)
Both VLANs → internetUDP/TCP 3478, UDP 49152–49751 outboundTURN relay (when enabled for your organization)
Both VLANs → internetUDP 123 outboundNTP time sync
VLAN 20 (local)UDP 5353, 1900 multicastmDNS / SSDP discovery
Mersive Pod connection diagram
Pod connection diagram from the hardware library. This image shows physical connections; use the tables above for network traffic requirements.
Validate the deployment

Check the network from each VLAN

Use mersive_network_diag.py to check connectivity from a machine on the target network. The tool requires Python 3.7 or later and uses the standard library, with no additional packages to install. Choose the checks below for the network path you are testing.

CommandWhat it does
python3 mersive_network_diag.pyOpens the diagnostic in your browser and runs the full check
python3 mersive_network_diag.py --quickFive-second smoke test: DNS, STUN, NAT, and NTP
python3 mersive_network_diag.py --cloud-onlyDNS and TLS checks against the 14 cloud endpoints
python3 mersive_network_diag.py --pod-ip 10.0.2.50Adds a cross-VLAN probe against a specific pod
python3 mersive_network_diag.py --jsonMachine-readable output
python3 mersive_network_diag.py --send-to-supportSaves the report and opens your email client, addressed to support

For a deployment with separate VLANs, run the tool once from the client VLAN and once from the Pod VLAN. To check the path between them, run it from the client VLAN and specify a Pod-VLAN address with --pod-ip. Replace 10.0.2.50 in the example with the Pod address you want to test.

NAT symmetry: symmetric NAT silently breaks WebRTC even when every port appears open, because each destination sees a different external port and no direct path can be formed. The tool validates NAT type against both STUN servers and reports symmetric NAT as a critical failure.

How cross-network sharing connects →

Get help with your network review

Bring your deployment questions to Mersive support, or review the security documentation with your IT team.

Get deployment support Review security documentation