Sunlogin needs no inbound port mapping, but the client must reach the internet. Corporate networks, proxies and firewall policy can all block it; this page explains what to allow.
What to allow
The client mainly uses standard HTTPS outbound ports and service domains. Allowing outbound 443 is enough in most environments.
- Allow outbound TCP 443
- Allow the client program through the firewall
- Allow resolution of the service domains
- No router port forwarding needed
Proxy environments
Where a proxy is required, configure it in the client or system. If the proxy needs authentication or uses an allowlist, add the relevant domains.
- Configure system or client proxy
- Proxy must allow the service domains
- Fill in credentials for authenticating proxies
- Allow the client separately if possible
How to verify
Compare with another network, such as a phone hotspot, on the same machine. If it works elsewhere, the original network has a policy restriction.
- Switch networks to isolate the cause
- Use a phone hotspot to confirm network blocking
- Read connection errors in the client log
- Ask the network administrator to review policy
FAQ
Do I need port forwarding?
No. The client communicates outbound and negotiates through the service; only unusual networks need extra configuration.
Why did a direct link fall back to relay?
When peer-to-peer cannot be established (symmetric NAT, strict firewall) traffic relays automatically. Everything still works, with slightly higher latency.