1. Required openings
The ScorePilot device contacts our operations server for updates and support. All traffic is initiated by the device and goes outbound — no inbound ports need to be opened.
*.scorepilot.seon TCP 443, with no application-type filtering — see section 2- UDP 53 to the network's DNS resolver, with
*.scorepilot.seallowlisted if DNS filtering is in use - UDP 123 to a time server. The device needs a correct system clock to connect
The device contacts no other destinations in operation.
2. Traffic on port 443
Part of the traffic is an encrypted VPN tunnel that the device opens outbound and keeps alive. It uses port 443 but is not HTTPS, which has two consequences:
- Rules that match on SNI or URL do not see it. The connection carries no hostname in the handshake. Firewalls that build their rules from DNS answers — FQDN objects, wildcard ones included — handle this correctly. If yours filters on SNI or URL category instead, it needs the IP address of the tunnel endpoint: contact us and we will supply it.
- Application filtering blocks it. Firewalls that only permit HTTP/HTTPS on port 443 will stop the traffic even though the port is open. The rule must allow arbitrary TCP traffic to the domain.
3. What stops the connection
Check these four before deployment:
- SSL/TLS inspection. The device trusts public certificate authorities only and aborts if the issuer has been replaced. Exempt
*.scorepilot.se. The VPN tunnel cannot be inspected at all. - Application filtering on port 443 that only lets HTTP/HTTPS through.
- Captive portals. The device has no user who can accept terms on a portal page. Its MAC address needs to be exempted — we can supply it in advance.
- 802.1X. The device connects automatically at power-on and needs either an exemption or a certificate.
4. Checklist
*.scorepilot.seallowed on TCP 443, regardless of application type- UDP 53 and UDP 123 allowed
- The domain exempted from TLS inspection
- No captive portal or port authentication on the device's port
Contact
Questions, or a request for the MAC address and installation details: support@sportinthebox.com. Let us know when the rules are in place and we will confirm from our side that the device connects.
Add a comment
Please log in or register to submit a comment.