The Amazon Signage Stick needs outbound HTTPS (port 443) to two sets of addresses: Amazon's own, and your signage software's. No inbound port needs to open anywhere. It needs a Wi-Fi or wired network with a password. It cannot join a hidden network, and it cannot get past a Wi-Fi login page on its own.
What does the stick talk to?
Amazon, for setup, management and software updates. Amazon's FAQ lists the domains to allow, all outbound HTTPS:
api.signage.amazon.comdevice.signage.amazon.comapi.cm.ds.amazon.devapi.ota.ds.amazon.devapi.beta.ota.ds.amazon.devapi.dt.ds.amazon.dev
Your CMS (the signage software), for content, schedules and live updates. Each CMS uses its own domains: ask your vendor for the list, and check whether images and video come from a separate CDN domain.
Does it need an inbound port?
No. Signage players open the connection themselves. A player keeps one outbound connection open (usually a WebSocket over HTTPS, port 443). When someone changes a playlist, the CMS sends the update back down that open connection, the same way a chat app gets new messages. A firewall lets replies in on a connection the stick started, so no inbound rule and no port forward is needed. If a vendor asks you to open an inbound port, ask why.
Does a hidden Wi-Fi network work?
No. The stick's setup only finds networks that broadcast their name (the SSID). A network set not to broadcast will not appear to pair the stick. Brix does not support a hidden network after setup either. If the site normally hides its SSID, broadcast it for the few minutes setup takes, then hide it again. Or connect the stick over wired Ethernet instead (see below).
What Wi-Fi security types work?
The stick's setup supports a password-protected personal network: WPA2-Personal, WPA3-Personal, or WEP. Nobody should still run WEP, but the stick accepts it. The setup does not support WPA2-Enterprise or WPA3-Enterprise, the kind that checks a username, a password, or a certificate against a RADIUS server. The Enterprise gap trips up a larger organization most often. A larger organization usually runs Enterprise Wi-Fi inside the building. Its guest network usually stays the only personal network on site.
If Enterprise Wi-Fi is the only option, three paths work:
- Put signage screens on a separate SSID set to WPA2-Personal or WPA3-Personal. Scope it to the outbound access in the table above.
- Ask your network team if the switch or controller supports MAC Authentication Bypass. A screen then joins the network by its hardware address, not a username and password. Your network team makes this call, not Brix.
- Run the stick on wired Ethernet. Enterprise Wi-Fi rules do not apply there.
Will a guest Wi-Fi login page work?
No. A captive portal is a guest network that opens a browser page first. The page asks someone to accept terms, or type a room number, before it grants internet access. Nobody stands by an unattended screen to clear that page.
The stick is locked to the signage app, so site staff have no way to reach a browser and clear it. The stick joins the Wi-Fi radio, then goes nowhere. Use a network that grants full access as soon as it accepts the password, with no second step.
Will a content filter block it?
Some schools and workplaces run a filter that blocks by category or domain reputation, such as Linewize-style filters. A filter like this can block api.brixsignage.com if it miscategorizes the domain, the same as it would any new cloud service it has not seen. Ask your filter administrator to add the domain to an allow list. Do not rely on category matching alone.
A filter that inspects TLS decrypts HTTPS traffic with its own certificate, then re-encrypts it. The decrypt-and-resign step needs your IT team to install the filter's certificate as trusted on the connecting stick. The stick's lock to the signage app leaves no settings screen for that install. A TLS-inspecting filter has to exempt the stick's traffic, by domain or by hardware, instead of intercepting it. Otherwise the connection fails with a certificate error.
Can it skip Wi-Fi and use wired Ethernet?
Yes. The stick has no Ethernet port built in. Wired needs Amazon's micro-USB Ethernet Adapter, $14.99. Check the port on your stick before you order one: it takes micro-USB, not USB-C. Wired Ethernet also sidesteps every Wi-Fi security and captive-portal question above. Wired Ethernet is usually the simplest answer for a network with Enterprise Wi-Fi and no spare personal SSID.
Where Brix fits
With Brix, the stick talks to one host for everything: api.brixsignage.com, over HTTPS on port 443. The pairing step, the playlist and schedule, images and video, live updates and the player screen all come from that one host. There is no separate media or CDN domain to allow. A network scan finds no open port on the stick.
| Allow | Destination | Protocol | Why |
|---|---|---|---|
| Needed | api.brixsignage.com | HTTPS, outbound, port 443 | The pairing step, content, the player screen, live updates |
| Optional | browser.sentry-cdn.com | HTTPS, outbound | Loads a script that reports crashes. If a filter blocks it, the player sends crash reports through the connection above instead. Nothing else changes. |
A short checklist for your network team
- Allow outbound HTTPS on port 443 to Amazon's domains (above) and your CMS's domains (for Brix:
api.brixsignage.com). Add no inbound rule. - If you run a content filter, allow the domain by name. Do not rely on its category.
- If the filter inspects TLS, exempt the stick rather than intercept it.
- Give the stick a password-protected SSID (WPA2-Personal or WPA3-Personal), or wired Ethernet. The setup does not support Enterprise Wi-Fi.
- Do not hide the SSID. Keep any guest-network login page off the SSID the stick uses.
- Put the stick on its own VLAN or subnet, the same as any other fixed appliance on your network.
FAQ
Does the player open any inbound ports?
No. The player only makes outbound requests, plus one outbound connection that stays open for live updates. There is nothing to open from outside, and no reason to forward a port to it.
Does blocking crash-reporting traffic break the player?
No. If a filter blocks browser.sentry-cdn.com, the player keeps working. The player sends crash details through its normal connection to api.brixsignage.com instead.
Does the stick need a static IP address?
No. A normal DHCP-assigned address works, the same as any other screen on the network.
What happens if the firewall rule is wrong?
The stick shows the pairing screen but never finishes pairing. Or a paired screen goes offline in Brix without the TV going dark, since it keeps showing its last cached content. See troubleshoot a screen for what each state means.
Can I change the Wi-Fi network after the stick is already deployed?
Yes, from Brix, without a site visit in most cases. See change Wi-Fi on an Amazon Signage Stick remotely.
For what the stick is and what it costs, see the Amazon Signage Stick overview. For the full setup walkthrough, see Amazon Signage Stick setup. A formal security review covers more than the network: answering a digital signage security questionnaire covers the rest. Talk to us before a multi-site rollout, and we can walk your network team through it directly.