Allowlisting requirements for Acunetix Online agents
To ensure the proper functioning of cloud agents and integrations, configure inbound and outbound traffic rules to allow access to the URLs in this document. Correctly configuring network access is a prerequisite for successful and accurate scans of your targets.
These are the allowlisting configuration steps to consider:
- Outbound connections
- Your browser outbound connections
- Acunetix Online internal scanning agent outbound connections
- AcuSensor outbound connections
- Inbound connections
Outbound connections
Your browser outbound connections
Your browser might be behind an outbound firewall or web proxy, especially when connected to a corporate LAN or VPN. Ensure that your firewall, proxy, or VPN allows outbound connections to the Acunetix Online URL for your location.
US-based customers | EU-based customers |
https://app.invicti.com | https://app-eu.invicti.com |
Acunetix Online internal scanning agent outbound connections
If you have deployed an internal scanning agent, ensure your network infrastructure permits it to establish outbound connections to the following destinations:
Scope | US-based customers | EU-based customers |
API calls to Acunetix Online | https://app.invicti.com | https://app-eu.invicti.com |
API calls to the AcuMonitor service for out-of-band vulnerability checking | https://bxss.me | https://bxss.me |
API calls to the safe browsing service | https://sb.bxss.me | https://sb.bxss.me |
API calls to the software composition analysis service | https://sca.acunetix.com | https://sca.acunetix.com |
AcuMonitor S3 bucket for out-of-band vulnerability checking | https://bxss.s3.dualstack.us-west-2.amazonaws.com | https://bxss.s3.dualstack.us-west-2.amazonaws.com |
Downloading of update packages for the internal scanning agent & used by cloud and internal agents to send scan data into private S3 buckets | https://*.amazonaws.com | https://*.amazonaws.com |
API calls to the AcuSensor Bridge | https://acusensor.acunetix.com | https://acusensor.acunetix.com |
Scanning requests to your target | IP Address/URL for your target, including destination port | IP Address/URL for your target, including destination port |
AcuSensor outbound connections
If you have deployed an AcuSensor agent in your target web application, ensure your network infrastructure permits it to establish outbound connections for API calls to the AcuSensor Bridge URL for your location.
US-based customers | EU-based customers |
https://acusensor.acunetix.com | https://acusensor.acunetix.com |
Inbound connections
Your target accepting inbound connections
Ensure your target’s network infrastructure allows incoming scanning requests from:
US-based customers | EU-based customers |
scanners.acunetix.com / 54.208.242.36 | scanners-eu.invicti.com / 3.75.126.236 |
IP Address / URL of your Internal Scanning Agent(s) | IP Address / URL of your Internal Scanning Agent(s) |
Your integration server accepting inbound connections
Ensure your integration server's network infrastructure allows incoming connections for integration API calls.
US-based customers | EU-based customers |
scanners.acunetix.com / 54.208.242.36 | scanners-eu.invicti.com / 3.75.126.236 |
IMPORTANT: If you have a dedicated environment, ensure access to the environment accordingly. |