Firewall Configuration

If you are using a firewall and not using a reverse proxy, you may have to allow traffic to port 3000:

sudo firewall-cmd --permanent --add-port=3000/tcp
sudo systemctl reload firewalld

To communicate with Rocket.Chat cloud services, and depending on the services you want to use, you need to whitelist the following URLs in your firewall configuration:

cloud.rocket.chat

This URL is required for workspace registration, workspace client authentication, and sync license and communications.

marketplace.rocket.chat

List and install marketplace apps.

releases.rocket.chat

Check for new versions.

billing.rocket.chat

Checkout and tier subscription management.

gateway.rocket.chat

Gateway for Rocket.Chat mobile app push notifications.

omni-gateway.rocket.chat

Gateway for communications for omnichannel apps (such as WhatsApp, Facebook, Instagram, and Telegram).

collector.rocket.chat

This URL is used to collect usage statistics. Community workspaces must whitelist this URL, or the workspaces will enter read-only mode.

Note that running Rocket.Chat in air-gapped mode requires a premium license.

nps.rocket.chat

NPS collector.