Configuring firewall rules for Bob
Bob cannot connect due to network firewall restrictions blocking outbound traffic.
Error messages
Connection errors or timeouts when attempting to use Bob.
Common causes
Your organization's firewall is blocking outbound network traffic to Bob's servers. This prevents Bob from connecting to required services.
Solution
Configure your firewall to allow Bob domain
You can configure your organization's firewall to connect to Bob's servers in multiple regions such as the United States (US) East, Europe, and Japan.
Work with your network administrator or IT team to configure your firewall with the following domain-based rule:
Identify which region your organization uses and request that your network administrator or IT support team add the corresponding domains to your firewall's allowlist.
All regions require the following shared domains:
bob.ibm.com
iam.cloud.ibm.com
console-ibm-prod.verify.ibm.com
idaas.ice.ibmcloud.com
www.ibm.com
login.ibm.com
myibm.ibm.comIn addition, include the domains for your applicable region:
*.us-east.bob.ibm.com
api.us-east.bob.ibm.com*.eu-de.bob.ibm.com
api.eu-de.bob.ibm.com*.jp-tok.bob.ibm.com
api.jp-tok.bob.ibm.comAll domains use HTTPS on TCP port 443.
| Domain | Purpose |
|---|---|
*.{region}.bob.ibm.com, api.{region}.bob.ibm.com | Bob service endpoints for the selected region |
iam.cloud.ibm.com | IBM Cloud Identity and Access Management (IAM) for authentication and authorization |
console-ibm-prod.verify.ibm.com | IBM identity verification services |
*.ice.ibmcloud.com | IBM Cloud identity and access services, including regional IBM Verify endpoints such as idaas.ice.ibmcloud.com and idaas-eu01b.ice.ibmcloud.com |
www.ibm.com | IBM corporate domain for product information and resources |
login.ibm.com | IBMid authentication |
myibm.ibm.com | MyIBM portal for managing IBM SaaS subscriptions |
Wait for the firewall configuration to be applied.
Restart IBM Bob.
Test Bob's connectivity.