Manage
Security and Compliance
Edited
Network and firewall requirements for Pleneo
This article describes the network, firewall, and security requirements for deploying Pleneo rooms in an enterprise environment.
Network architecture
Pleneo hubs has two separate, isolated Ethernet ports, with no bridging between them:
LAN 1 (control network): management, configuration, integration and control.
LAN 2 (audio and video network): real-time media and traffic to and from audio and video devices on segmented networks
Device control can run on LAN 1 or LAN 2, depending on how the devices are connected.
DHCP
Pleneo devices get their IP address and network settings automatically over DHCP.
With a DHCP server (recommended): everything gets an IP address automatically
Static IP: you can also set a static IP address in the settings
Pleneo devices works on most network setups. If your network doesn't use DHCP, contact Pleneo Support for the best way to set it up.
Device discovery
Pleneo finds devices automatically on the local network, so you can add them to the room during setup. Multicast needs to be allowed on the audio and video network for real-time audio.
Management access on DeviceHubs (LAN 1)
You reach the Pleneo hub's web interface over HTTPS:
Service | Protocol | Port | Direction | Encryption |
|---|---|---|---|---|
Web interface | TCP | 443 | Inbound | TLS 1.2+ |
Pleneo uses a self-signed certificate by default, so your browser shows a warning the first time you connect. Accept it to continue.
Device communication
Pleneo uses a mix of outbound connections and a few inbound UDP ports for discovery and control. Unencrypted control traffic stays on the local network.
Purpose | Protocol | Port(s) | Direction | Encryption |
|---|---|---|---|---|
Device control and monitoring | TCP | 19150–19152 | Outbound | None (local) |
Device heartbeat / discovery | UDP | 19153 | Inbound | None |
Secure device control | TCP | 443 | Outbound | TLS 1.2+ |
Legacy device control | TCP | 45 | Outbound | None |
Vendor-specific control | TCP | 2202 | Outbound | None |
Camera control (VISCA over IP) | UDP | 52381 | Outbound | None |
Camera discovery / session init | UDP | 45 | Inbound | None |
Real-time audio (multicast) | UDP | Dynamic | Bidirectional | None |
Pleneo Cloud (outbound)
Pleneo Cloud is used for remote management, monitoring, and firmware updates. All of this traffic is outbound over HTTPS (TCP 443). Local DeviceHubs never need any inbound connection from the internet.
To allow this on your firewall, we recommend allowing by domain rather than by IP address, so nothing breaks if an IP address changes later. For the current list of Pleneo Cloud domains, contact Pleneo Support.
Internet access is only needed for Pleneo Cloud features.
Microsoft Teams / Zoom requirements
A Pleneo room runs your meeting platform (for example, Microsoft Teams Rooms or Zoom Rooms) on the room computer. Make sure that platform's own network requirements are open on your firewall, as set out by the vendor:
These are on top of the Pleneo requirements above.
Firewall configuration
Open these firewall rules:
Source | Destination | Port(s) | Protocol | Direction | Purpose |
|---|---|---|---|---|---|
Admin computer | RoomHub (LAN 1) | 443 | TCP | Inbound | Secure management access |
Devices | RoomHub | 19153 | UDP | Inbound | Device heartbeat / discovery |
PTZ cameras | RoomHub | 45 | UDP | Inbound | Camera session start |
RoomHub | Devices | See device communication | TCP/UDP | Outbound | Device communication |
RoomHub | Pleneo Cloud | 443 | TCP | Outbound | Cloud management |
Summary
Protocol | Ports | Direction | Firewall rules | Description |
|---|---|---|---|---|
DHCP | UDP 67, 68 | — | None needed | Get IP, gateway, DNS |
Multicast | Dynamic | Bidirectional | None (stays on the local subnet) | Real-time audio |
HTTPS (management) | TCP 443 | Inbound | Admin computer → RoomHub | Web interface |
Device control | See device communication | Mixed | Local network only | RoomHub ↔ devices |
HTTPS (Cloud) | TCP 443 | Outbound | RoomHub → Pleneo Cloud (domains on request) | Remote management, monitoring, firmware |
Microsoft / Zoom | Various | Various | Follow the vendor's firewall docs | Meeting platform |
If you still have problems after opening these ports, contact Pleneo Support.