e-satisfaction

External connections & IP allowlist

Some e-satisfaction features reach out to your systems: a data bridge signs in to your SFTP or FTP server to read a file, and a webhook delivers each survey completion to your endpoint. If your firewall only lets in traffic from addresses it knows, those connections are turned away until you add ours.

This page lists the IP addresses each kind of connection comes from, so whoever runs your firewall can allow exactly those — and nothing more.

At a glance

ConnectionWhat connects to youIP addresses to allowPort
Data bridgese-satisfaction, signing in to your SFTP or FTP server to read a file207.154.250.203, 68.183.76.178The port your server listens on — any port except 22
Webhookse-satisfaction, sending each survey completion to your payload URL77.235.63.178443 (HTTPS)

Allow every address listed for a connection — a connection can come from any one of them, and one missing address is enough to make some connections fail while others succeed.

Only traffic coming from us

These addresses are for connections e-satisfaction opens towards your servers. You don't need them for anything your side sends to us — uploading files to the e-satisfaction SFTP server, calling our API, or showing surveys on your website. If a company network blocks surveys from loading, see Troubleshooting instead.

Data bridges

When a data bridge runs on your own server — on its schedule, when you click Process now, or when you use Test connection or Check file — it connects to your server from one of these addresses:

  • 207.154.250.203
  • 68.183.76.178

Allow both in your server's firewall, on the port your SFTP or FTP service listens on.

  • Port 22 is never used. We block outgoing connections on port 22, so your server needs to listen on another port too — for example 2222. See Port 22 isn't supported.
  • The e-satisfaction SFTP server needs nothing. A bridge that uses the e-satisfaction SFTP server never leaves our platform, so there's no firewall of yours to open.

Webhooks

Every webhook delivery — the HTTPS POST sent to your payload URL when a survey is completed — comes from:

  • 77.235.63.178

Allow it on the port of your payload URL — 443, unless the URL names another port.

An allowlist is not a password

Allowing our addresses keeps everyone else out of your firewall, but it doesn't prove a request came from your webhook. Add a secret of your own as a custom header on the webhook — an authentication token, for example — and have your endpoint check it on every delivery.

Adding the addresses to your firewall

Share this page with whoever runs your firewall

That's usually your IT, network or hosting team. Tell them which connection you're setting up — a data bridge, a webhook, or both — and the port your server or endpoint uses.

Allow the addresses

They add each IP address for that connection to the firewall's allowlist, for incoming connections on that port. Allow the addresses themselves — don't rely on a hostname or reverse lookup.

Check the connection

For a data bridge, open its Server settings and use Test connection, then Check file. For a webhook, complete one of its surveys and open the webhook's history to see the delivery arrive.

Keep your allowlist up to date

This page always lists the current addresses. When you set up a new connection, or one that used to work starts failing, check your firewall against the list here.

When a connection is blocked

A firewall that doesn't recognise our address usually drops the connection without answering, so the signs look like the server simply isn't there:

  • Data bridges — Test connection or Check file reports that the server couldn't be reached, or times out, and scheduled runs fail in the import history. If the host and port are right, check that both bridge addresses are allowed.
  • Webhooks — the webhook's history shows deliveries that timed out or were refused, with no response from your endpoint. Check that the webhook address is allowed, then complete another survey to try again.