This page applies to Pangolin Cloud only. If you self-host Pangolin, see DNS & Networking for the hostnames and ports on your own deployment.
Control Plane
The control plane is the central Pangolin service that runs the dashboard, REST API, authentication, and configuration orchestration.
Sites and clients use this hostname as their endpoint. For example, Sites connect here to register, receive policy, and maintain their control channel.
Points of Presence
Points of presence (PoPs), also called relays, are the networking edge where sites and clients connect for data traffic.What PoPs Do
- Public resources send all traffic through a PoP.
- Private resources use PoPs to coordinate NAT traversal between a client and a site. If hole punching fails, traffic relays through the PoP instead.
Remote Nodes
If you use remote nodes, the point of presence (relay) for your traffic is your self-hosted node, not the cloud PoPs listed above. The control plane endpoint for dashboard access, API calls, and authentication remainsapp.pangolin.net.
Whitelisting Checklist
To allow Pangolin Cloud on an outbound firewall or proxy, permit traffic to:app.pangolin.netfor the control plane- All
*.pop.pangolin.nethostnames listed above for site and client data traffic

