Overview
The Virtru AD Domain Sync tool communicates with an AWS S3 bucket in the us-east-2 region to retrieve domain map configurations. Organizations operating in environments with strict egress filtering — such as next-gen firewalls, proxies, or on-premises network controls — may need to explicitly allowlist the IP ranges used by this endpoint.
Because AWS S3 uses dynamic IP assignment with no guaranteed static addresses, we do not recommend allowlisting specific IPs. Instead, customers should allowlist the full set of AWS-published S3 CIDR ranges for us-east-2 and subscribe to AWS change notifications to keep those rules current.
Endpoint Details
| Property | Value |
|---|---|
| Hostname | virtru-com-<aws-region>-domain-maps-production.s3.us-east-2.amazonaws.com |
| Service | AWS S3 |
| AWS Region | example: us-east-2 |
| Protocol | HTTPS (TCP/443) |
Recognizing This Error
If egress to the S3 endpoint is blocked by a firewall or proxy, the AD Domain Sync tool will log the following errors:
ERROR Sync - Unable to upload sync data.: System.Net.WebException: The underlying connection was closed: An unexpected error occurred on a send. ERROR DomainSyncServiceImplementation.sync Top Level Exception: System.Net.WebException: The underlying connection was closed: An unexpected error occurred on a send.
What This Error Means
The AD Sync tool successfully ran its sync logic and attempted to upload domain map data to the S3 endpoint, but the outbound connection was reset before the upload could complete. The root cause in both cases is:
System.Net.Sockets.SocketException: An existing connection was forcibly closed by the remote host
This exception surfaces during the TLS handshake phase (System.Net.Security.SslState.ForceAuthentication / System.Net.TlsStream.ProcessAuthentication), which means:
- The TCP connection to the S3 endpoint was initially established
- But the TLS layer was reset before the handshake could complete
- The remote host closing the connection in this context is most commonly the customer's firewall or proxy — not AWS
This is the classic behavior of an egress firewall that allows the initial TCP connection but blocks or resets traffic once it identifies the destination IP is not on the allowlist.
The failure occurs at: Virtru.DomainMapGenerator.SyncAgent.UploadDMData (SyncAgent.cs, line 148), which is the final step where domain map data is written to S3.
us-east-2.Allowlist AWS S3 CIDRs for us-east-2
Rather than allowlisting specific IPs, configure your firewall or proxy to permit outbound HTTPS traffic to the full set of AWS S3 IP ranges for the <aws-region>. AWS publishes and maintains an authoritative, machine-readable list of all IP ranges in use across their services at:
https://ip-ranges.amazonaws.com/ip-ranges.json
Retrieve S3 IP Ranges for us-east-2
Use the following command to extract only the S3 CIDRs for <aws-region>:
curl -s https://ip-ranges.amazonaws.com/ip-ranges.json \ | jq -r '.prefixes[] | select(.service=="S3" and .region=="us-east-2") | .ip_prefix'
Staying Current with AWS IP Range Changes
AWS updates the ip-ranges.json file whenever IP ranges are added, removed, or modified. To avoid service disruptions:
-
Subscribe to AWS IP Range Update Notifications via Amazon SNS. AWS publishes a notification to the topic
arn:aws:sns:us-east-1:806199016981:AmazonIpSpaceChangedwhenever the file changes. - Automate allowlist updates by building a pipeline that queries the JSON feed on a scheduled basis and syncs the results to your firewall policy.
-
Use FQDN-based firewall rules if your firewall supports DNS-based or application-layer filtering. Allowlisting
*.s3.us-east-2.amazonaws.comat the FQDN level is often more resilient than CIDR-based rules.