What to open, what to leave closed, and how the collector fits into a network that already has firewalls, VPNs and segmentation in place.
The collector only makes outbound TLS connections to Zynty Cloud (port 443). You never need to open an inbound port on your perimeter firewall for Zynty itself.
The collector needs to reach your devices on their monitoring ports: UDP/161 for SNMP, TCP/22 for SSH, UDP/514 or TCP/6514 for syslog, and the flow-export ports (UDP/2055 NetFlow, UDP/4739 IPFIX, UDP/6343 sFlow) if devices push flow data to the collector.
Deploy one collector per site rather than tunneling monitoring traffic across a WAN or VPN link. Each collector registers independently but reports into the same Zynty workspace, so you still get one unified dashboard.
If your network uses a zero-trust access model, add app.zynty.net and your collector's outbound destination to the allowed egress list rather than trying to route it through a client VPN, the collector is a service, not a user endpoint.