Getting started · 12 min read · networkfirewallvpn

Connect Zynty to your existing network

What to open, what to leave closed, and how the collector fits into a network that already has firewalls, VPNs and segmentation in place.

What you'll need

  • A Zynty account with Editor or Admin role
  • Access to your firewall or security group configuration
  • A defined management VLAN or subnet for the devices you'll monitor
1

Understand the traffic direction

The collector only makes outbound TLS connections to Zynty Cloud (port 443). You never need to open an inbound port on your perimeter firewall for Zynty itself.

2

Open collector-to-device paths

The collector needs to reach your devices on their monitoring ports: UDP/161 for SNMP, TCP/22 for SSH, UDP/514 or TCP/6514 for syslog, and the flow-export ports (UDP/2055 NetFlow, UDP/4739 IPFIX, UDP/6343 sFlow) if devices push flow data to the collector.

Zynty application screenshot
1
3

If your sites are on separate networks

Deploy one collector per site rather than tunneling monitoring traffic across a WAN or VPN link. Each collector registers independently but reports into the same Zynty workspace, so you still get one unified dashboard.

4

For split-tunnel or zero-trust networks

If your network uses a zero-trust access model, add app.zynty.net and your collector's outbound destination to the allowed egress list rather than trying to route it through a client VPN, the collector is a service, not a user endpoint.