# Ingress Requirements

<figure><img src="https://2503956294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MB_i6vKdtG6Z2n6zWgJ%2Fuploads%2FkQXMNTlQBqEsg04LKvn3%2FNetwork%20Config.jpg?alt=media&#x26;token=45a98766-f2ee-4449-bb78-4aa74d88c68c" alt=""><figcaption></figcaption></figure>

Keeper Automator can be deployed many different ways - on prem, cloud or serverless.

### Data Flow Diagram

<figure><img src="https://2503956294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MB_i6vKdtG6Z2n6zWgJ%2Fuploads%2FD73ri8Fwl4IZocxTALs3%2FAutomator%20Data%20Flow.jpg?alt=media&#x26;token=389edbb1-e7af-4e8c-ab14-622cfb1b7dd8" alt=""><figcaption><p>Data Flow Diagram</p></figcaption></figure>

### Network Firewall Setup

In your firewall inbound traffic rules, set one of following rulesets:

**For US Data Center Customers:**

* Inbound TCP port 443 from **`54.208.20.102/32`**
* Inbound TCP port 443 from **`34.203.159.189/32`**

**US / GovCloud Data Center Customers:**

* Inbound TCP port 443 from **`18.252.135.74/32`**
* Inbound TCP port 443 from **`18.253.212.59/32`**

**For EU / Dublin Data Center Customers:**

* Inbound TCP port 443 from **`52.210.163.45/32`**
* Inbound TCP port 443 from **`54.246.185.95/32`**

**For AU / Sydney Data Center Customers:**

* Inbound TCP port 443 from **`3.106.40.41/32`**
* Inbound TCP port 443 from **`54.206.208.132/32`**

**For CA / Canada Data Center Customers:**

* Inbound TCP port 443 from **`35.182.216.11/32`**
* Inbound TCP port 443 from **`15.223.136.134/32`**

**For JP / Tokyo Data Center Customers:**

* Inbound TCP port 443 from **`54.150.11.204/32`**
* Inbound TCP port 443 from **`52.68.53.105/32`**

{% hint style="info" %}
In addition, you may want to allow traffic from your office network (for the purpose of testing and health checks).
{% endhint %}

Make sure to create a rule for each IP address listed based on your Keeper geographic data center region.
