使用Ably实现WebSockets Pub/Sub:防火墙白名单配置咨询
Hey there! As an Ably Developer Evangelist, I’ve walked through this setup with tons of users—so let’s break down exactly what you need to add to your firewall whitelist, whether you’re using general Ably services or specifically WebSocket-based Pub/Sub.
Recommended: Use Domains (Avoid IPs When Possible)
IP ranges can shift as we scale our global infrastructure, so domain whitelisting is always the most reliable approach. Add these wildcard domains to cover all Ably service endpoints:
*.ably.io*.ably-realtime.com
If You Must Use IP Ranges
If your network requires IP-based whitelisting, here are Ably’s current public IP ranges (note: these may be updated periodically, so keep an eye on our internal docs if you run into connectivity issues):
IPv4 Ranges
34.197.220.0/2234.201.32.0/1952.71.208.0/2054.160.0.0/14
IPv6 Range
2600:1f18::/32
Required Ports
For all Ably traffic—including WebSocket Pub/Sub (which uses secure WebSockets, wss://)—you’ll need to open these ports:
443(Standard TLS/HTTPS/WSS port: this is the primary port you should use, as all modern Ably connections default to this)80(Fallback port: connections here will automatically redirect to 443, but it’s good to have it open for edge cases)- Optional:
8080and8443(Alternative non-standard ports if your network blocks 443/80; these work for both HTTPS and WebSocket traffic)
Quick Note for WebSocket Pub/Sub
Since Ably’s WebSocket connections are always secured with TLS (using wss://), they rely on the same ports and endpoints as our regular HTTPS traffic. The whitelist rules above apply directly—no extra configuration is needed beyond what’s listed!
内容的提问来源于stack exchange,提问作者Srushtika Neelakantam

