USM Content
Smartsheet Jira connector firewall settings (self-hosted server)
USM Content
If your organization runs a self-hosted Jira Server behind a firewall, configure your firewall before completing the Jira Connector connection setup.
Before you begin
Confirm the following before making any firewall changes:
- Your Jira version is between 7.2 and 10.X.
- Your Jira Server uses an HTTPS connection with a valid certificate.
- You know which port your Jira Server uses. By default, Jira runs on port 8080 or 443. Check with your Jira Administrator if the port has been changed.
Configure your firewall
Two options are available to expose your self-hosted Jira Server to the Jira Connector.
Option 1: Allow connections by path
The Jira REST API runs on a custom port of the Apache Tomcat host. Allow access to these paths on your Jira Server, and block access to all other paths:
- https://<yourJirahost.com>/<context>/rest/*
- https://<yourJirahost.com>/<context>/auth/*
- https://<yourJirahost.com>/<context>/plugins/*
You can restrict and prevent Internet connections to all other paths on your Jira Server.
Option 2: Use a reverse proxy
Configure Jira to recognize your reverse proxy so it handles URLs and addresses correctly. See Atlassian's documentation on integrating Jira with a reverse proxy for configuration steps.
If you receive an OAuth Signature Rejected error during setup, this proxy configuration is likely the cause. See Atlassian's OAuth troubleshooting guide for help resolving it.
Error: Connection refused by Jira host. Please verify that the Jira host URL is correct and accessible.
This error appears if the Connector can't reach your Jira Server or if you've entered the Public and Consumer Keys incorrectly. Ensure the Jira Server REST API is accessible from the internet and uses an HTTPS-enabled port like 8080 or 443. HTTP isn't supported.
Error: Unable to find a valid SSL certificate on the Jira host. Please have your Jira Administrator install a valid certificate (note that expired certificates are considered invalid).
This error occurs if your self-hosted Jira Server lacks a valid SSL certificate from a trusted authority. Common reasons for invalidity include:
- The certificate isn't installed correctly.
- The intermediate certificate chain is missing.
- The certificate is from a trusted authority but may be signed by an untrusted authority.
If your Jira Server is publicly accessible, you can use a third-party SSL test tool (for example, SSL/TLS server assessment service provided by Qualys SSL Labs) to verify the certificate's installation. Contact your certificate provider for help with any errors or missing components.
Are there IP addresses used with Jira I can add to the Allowlist in our firewall?
Adding specific IP addresses to the Allowlist of your firewall doesn't significantly improve security. Instead, add Smartsheet's DNS A record at:
aws.relay.smartsheet.com (for US)
or
- aws.relay.connectors.smartsheet.eu (for EU)
This record resolves to the Jira Connector's outgoing IP.
Smartsheet advises against resolving this DNS record to its underlying IPs for your Allowlist. IP changes can disrupt Smartsheet's ability to connect to your Jira Server. Using the DNS record ensures ongoing connectivity even if the IP addresses change.
However, if you want to use IP addresses, you can add the following:
| US Commercial | EU Commercial |
|---|---|
| 98.80.23.123 54.157.54.169 52.204.43.171 34.227.211.250 54.235.179.6 3.224.32.218 98.80.45.99 98.80.158.43 54.159.146.16 52.5.43.47 98.80.22.69 107.20.173.108 3.139.159.141 3.138.57.194 52.15.39.139 3.16.179.80 3.16.201.183 3.14.89.245 3.140.222.51 3.140.168.101 | 54.93.118.54 3.126.112.245 3.73.171.120 18.184.190.206 18.196.67.16 18.196.132.133 3.123.123.251 3.72.163.85 52.209.63.161 54.73.146.126 108.128.215.0 54.220.119.129 54.72.92.127 63.33.121.81 54.76.4.106 52.17.24.48 |