Executive Summary
The Nectar Endpoint Client (EPC) is a lightweight endpoint component used to collect endpoint telemetry and perform network and application performance testing. The EPC is designed with a minimal footprint and communicates with designated Nectar infrastructure over defined network ports.
This guide provides a general overview of the network and security requirements needed before installing the EPC. Completing these requirements in advance helps ensure a smooth installation and allows EPC connectivity and peer-to-peer (P2P) testing to function correctly.
1. Approve the EPC Installer
Before installing the EPC, download the current EPC installer from here.
Because the EPC installer introduces software to managed endpoints, your organization's security team may need to approve or allow the installer before deployment.
After approval, download the EPC installer to the endpoint or to the software-distribution platform used by your organization.
2. Allow Connectivity to the Nectar Controller
EPC endpoints must be able to communicate with the Nectar Controller.
Controller hostname:
neccontroller.us.nectar.services
The hostname currently resolves to the following addresses:
| IP Address |
|---|
| 52.204.230.133 |
| 34.231.219.110 |
| 50.17.99.212 |
Allow the required outbound EPC traffic to the controller through the organization's firewall and network security controls.
Controller Ports
Allow traffic to the controller using protocol TCP port 443.
3. Enable P2P Testing
EPC uses peer-to-peer (P2P) testing to measure network performance between endpoints and Nectar test hubs.
Allow UDP port 29999 from EPC endpoints to the designated Nectar Hubs.
Begin with the following U.S. Hubs:
| Hub | IP Address |
|---|---|
| AWS-US-Hub-East | 34.234.81.122 |
| AWS-US-Hub-West | 54.203.76.27 |
P2P Firewall Requirement
| Source | Destination | Protocol | Port | Direction | Purpose |
|---|---|---|---|---|---|
| EPC endpoints | AWS-US-Hub-East | UDP | 29999 | Outbound | P2P testing |
| EPC endpoints | AWS-US-Hub-West | UDP | 29999 | Outbound | P2P testing |
These rules enable EPC endpoints to perform P2P network tests against the Nectar Hubs.
4. Install the EPC
Once the installer has been approved and the required firewall rules are in place:
Run the approved EPC installer on the target endpoint.
Complete the installation using the deployment parameters provided.
Confirm that the EPC service is installed, running, and can communicate with the Nectar Controller.
To verify, right click on the EPC system-tray icon, and confirm Status shows all green bars


Confirm that P2P testing can reach the designated Nectar Hubs.
For managed environments, the EPC installer may also be deployed through the organization's endpoint-management platform.
5. Post-Installation Validation
After installation, verify the following:
EPC is installed successfully on the endpoint.
The EPC service is running.
The endpoint can resolve to the controller:
neccontroller.us.nectar.services.UDP 29999 connectivity to the designated Nectar Hubs is permitted.
The endpoint appears in the Nectar EPC Reporter.
P2P tests can execute successfully.
If the EPC installs successfully but does not appear or communicate correctly, first verify the endpoint's firewall, EDR, proxy, DNS, and network-security policies.
Network Requirements Summary
| Destination | Protocol / Port | Purpose |
|---|---|---|
neccontroller.us.nectar.services | TCP 443 | Secure controller communication |
AWS-US-Hub-East (34.234.81.122) | UDP 29999 | P2P testing |
AWS-US-Hub-West (54.203.76.27) | UDP 29999 | P2P testing |