---
name: satellite-reqs-host-lal-outbound-osa
title: RHCOS enabled locations with reduced firewall in Osaka
description: Review the following network requirements for outbound connectivity for hosts in a minimum internet access location in the Osaka (`jp-osa`) region. Because this type of location requires a single network destination instead of multiple destinations, it reduces the number of outbound IP addresses that you must allow from your firewall. For more information, see Creating Red Hat CoreOS enabled Locations with reduced firewall footprint.
last-updated: 2026-08-14
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/satellite?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# RHCOS enabled locations with reduced firewall in Osaka
{: #req-minimum-outbound-osa}
  
Review the following network requirements for outbound connectivity for hosts in a minimum internet access location in the Osaka (`jp-osa`) region. Because this type of location requires a single network destination instead of multiple destinations, it reduces the number of outbound IP addresses that you must allow from your firewall. For more information, see [Creating Red Hat CoreOS enabled Locations with reduced firewall footprint](https://cloud.ibm.com/docs/satellite?topic=satellite-coreos-reduced-firewall&format=markdown).
{: shortdesc}


You can verify your host setup with the `satellite-host-check` script. For more information, see [Checking your host setup](https://cloud.ibm.com/docs/satellite?topic=satellite-host-network-check&format=markdown).
{: tip}

  
The following outbound network requirements are specific for hosts in the Osaka (`jp-osa`) region.

     
Allow Link tunnel clients to connect to the Link tunnel server endpoint.
:    * Destination IP addresses: 163.68.78.234, 163.69.70.106, 163.73.70.50
     * Destination hostnames: `c-01-ws.jp-osa.link.satellite.cloud.ibm.com`
     * Protocol and ports: HTTPS 443
     
  
Allow access to Red Hat network time protocol (NTP) servers.
:    * Destination hostnames: `0.rhel.pool.ntp.org`, `1.rhel.pool.ntp.org`, `2.rhel.pool.ntp.org`, `3.rhel.pool.ntp.org`
     * Protocol and ports: Allow NTP protocol and provide UDP on port 123
     
:    If you don't want to use Red Hat network time protocol (NTP) servers, you can instead define a [custom NTP server for your RHCOS hosts](https://cloud.ibm.com/docs/satellite?topic=satellite-config-custom-ntp&format=markdown).

Optional:  Allow hosts to connect to HPCS for encrypting cluster secrets.
:    * Domain: `api.jp-osa.hs-crypto.cloud.ibm.com`
     * Port: 8000-19999 

:    If you have a preconfigured set of instances, you can find the assigned port to your instance in the overview page and allowlist just that port on the domain.
  
For access to services such as IBM Cloud Log Analysis or IBM Cloud Monitoring, you must add the outbound access for them. For more information, see [RHCOS enabled locations in Osaka](https://cloud.ibm.com/docs/satellite?topic=satellite-reqs-host-rhcos-outbound-osa&format=markdown).