Network Requirements
The kiosk requires only internet connectivity for its operations and does not need access to internal network resources. Given the physical accessibility of the ethernet connection through the maintenance panel, we recommend deploying the device on an isolated network segment.
Recommended Network Architecture
IoT Network Segment:
Dedicated VLAN with internet-only access
Firewall rules blocking lateral movement to internal networks
Standard egress filtering for required protocols (HTTPS, NTP, etc.)
Technical Specifications
Required Outbound Access:
*.tjekvik.com via port 443 and 8883 / HTTPS and MQTT over TLS (Tjekvik main website)
*.tjekvikapp.com via port 443 / HTTPS (Tjekvik backend services)
*.tjekvik.app via port 443 / HTTPS (Tjekvik authentication service)
*.amazonaws.com via port 443 and 8883 / HTTPS and MQTT over TLS (Images)
TeamViewer remote machine control
Full information about TeamViewer : LINK
www.recaptcha.net, www.gstatic.com and cdn.cookielaw.org via port 443.
Port 22 (SSH reverse proxy remote access)
ntp.ubuntu.com via port 123 UDP / NTP
*.archive.ubuntu.com via port 443 / HTTPS
Network Requirements:
DHCP or static IP assignment
Standard ethernet connectivity
No inbound port requirements
Implementation Benefits
Eliminates internal network exposure risk
Maintains full device functionality
Scalable for additional IoT devices
Aligns with zero-trust principles