A Rise Up Administrator account is recommended to follow the platform-side changes, but implementing this article mainly depends on your IT / network team.
Required permissions and access:
- Access to your company's firewall, proxy, or whitelist management tool configuration
- Rights to add domains and allow outbound protocols (HTTPS and WebSocket)
- Rise Up administrator access to test the relevant features once the configuration is applied
Contact your IT team if your role does not allow you to modify the network configuration, or your Rise Up Customer Success Manager for any question about which domains to use.
A whitelist is a network security protocol that only allows pre-approved sites, domains, and protocols to communicate with your organisation's devices. For Rise Up to work correctly in a secure enterprise environment, several domains and a specific protocol (WebSocket) must be explicitly allowed by your firewall or proxy.
Getting your network ready follows these main stages:
- 1Identify the domains and protocols used by Rise Up and its third-party services
- 2Whitelist the content-hosting domains (images, videos, documents, reporting)
- 3Whitelist the WebSocket (WSS) protocol for real-time features
- 4Test access, then monitor and maintain the whitelist over time
An incomplete configuration generally doesn't block overall access to the platform, but it can silently disable specific features (document previews, videos, real-time notifications, and so on).
- Whitelist: a firewall or proxy rule that only allows explicitly approved domains and protocols.
- Content domains: the third-party domains (Filestack, JW Player, Box.com, H5P, Data Lab, Unsplash) used to host and display your training content.
- WebSocket protocol (WSS): a persistent-connection protocol, distinct from standard HTTPS, used for real-time features.
- Socket domains: the three domains dedicated to WebSocket, each tied to a different cloud provider (AWS, Azure, Scaleway).
- Real-time features: instant notifications and live sessions / webinars.
I — Identify the required domains and protocols
Goal: build the complete list of domains and the protocol your firewall or proxy needs to allow before rolling out Rise Up to your users.
Rise Up communicates through two main categories of network elements:
- Content domains — used to host and display images, videos, documents, and reports (see Section II).
- Real-time domains and protocol — used for notifications, and live sessions via WebSocket (see Section III).
Result: pass the consolidated list from Sections II and III to your IT team so it can be added to the firewall or proxy configuration before rollout.
II — Whitelist the content-hosting domains
These domains correspond to the third-party services Rise Up uses to store and display your training content. Share them with your IT team for whitelisting.
| Service | Used for | Domain(s) to whitelist |
|---|---|---|
| Filestack | Images and documents | .filestack.io |
| JW Player | Video content |
.jwpcdn.com, .jwplayer.com, .jwplatform.com
|
| Box.com | Document previews |
.box.com, .box.net, .boxcdn.net, .boxcloud.com, .boxrelay.com, .api.box.com, .cdn01.boxcdn.net, .public.boxcloud.com
|
| H5P | Authoring tool content |
riseup.h5p.com, eu-west-1.cdn.h5p.com, h5p.org
|
| Data Lab | Online reporting | eu-west-1.quicksight.aws.amazon.com |
| Unsplash | Image bank | .unsplash.com |
Result: once these domains are whitelisted, images, videos, documents, and reports display correctly for all users.
III — Whitelist the WebSocket (WSS) protocol for real-time features
In addition to the content domains, Rise Up uses the WebSocket protocol
(wss://) for all real-time communication between the browser and
Rise Up's servers:
- Instant notifications
- Live sessions and webinars
Unlike content, which is delivered through standard HTTPS requests, these features rely on a persistent WebSocket connection. This is a distinct protocol that must be explicitly allowed, in addition to the domains in Section II.
| Domain | Cloud provider | Protocol / Port |
|---|---|---|
socket.riseup.ai |
AWS | WSS (443) |
socket.riseup.fr |
Azure | WSS (443) |
fr-par-socket.riseup.fr |
Scaleway | WSS (443) |
Result: once the WSS protocol and the matching domain are whitelisted, real-time features update instantly for all users.
IV — Test, monitor, and maintain access
- Once the domains (Section II) and the WSS protocol (Section III) are whitelisted, have one or more users log in to Rise Up.
- Check that content displays correctly (images, videos, documents, reports) and that real-time features behave as expected (notifications and live sessions).
- If something is blocked, compare the domains actually contacted by the browser (developer tools / proxy logs) against the list in Sections II and III.
- Document the applied configuration and train your IT team to maintain it.
Best practices for ongoing maintenance:
- Regular audits: periodically check that every whitelisted domain is still necessary and up to date.
- Track user feedback: encourage users to report any access issues so the configuration can be adjusted quickly.
- Watch for product changes: Rise Up may add a new domain or third-party service over time; review this article periodically.
Result: all users access Rise Up without restriction, including content and real-time features, on an ongoing basis.
FAQ & Troubleshooting
-
Issue: Content (images, videos, documents) does not display correctly.
Solution: Check that the domains listed in Section II are correctly whitelisted. If the issue persists, check the file format and its compatibility with the platform.
Issue: Notifications or live sessions don't work, even though the rest of the platform works normally.
Solution: The WebSocket protocol (wss) or the socket domain matching your environment (socket.riseup.ai,socket.riseup.fr, orfr-par-socket.riseup.fr) is most likely not whitelisted. Add it to the whitelist (Section III) and test again.
Issue: Slow loading times for content.
Solution: Make sure content files are optimised for web use. Large files may need to be compressed or reformatted.
-
Why are there three different WebSocket domains?
— Rise Up distributes its real-time communication infrastructure across several cloud providers (AWS, Azure, Scaleway) depending on the customer account. Only the domain matching your environment is actually used; the other two can safely be added as a precaution.
Do I need to whitelist a specific port for WebSocket?
— No. The WSS protocol uses port 443, the same as standard HTTPS traffic.
Does an incomplete configuration block all access to Rise Up?
— Generally not. Overall access remains possible, but specific features (previews, videos, real-time) may be silently disabled.
Who should I contact if I don't know my hosting environment (AWS/Azure/Scaleway)?
— Your Customer Success Manager or Rise Up support can confirm it for you. -
Configuring a Firewall for Box Applications
Contact Rise Up Support