Product guide, Part 5 / Sovereign GaiXer

What if your network blocks internet access?
Enable updates and web search on a LAN with restricted outbound access

After required initial OS setup and updates, Sovereign GaiXer works without internet access. However, admin-console updates and web search require outbound traffic from the unit. Many companies restrict this through firewalls or proxies. This article explains how to move from blocked access to an approved configuration, including the change request to submit to IT.

Published: Updated: Estimated reading time: 7 minutes

In a sentence

Outbound communication means the unit contacting the internet for updates or web search; core local AI still works without it after required initial setup. There are three approaches: allowlist destinations on the firewall (A), use a corporate proxy (B), or stay offline and update through USB (C). Choose according to company security policy and submit a change request with a communication-requirements table. The seven steps are diagnosis, approach selection, request, implementation, unit configuration, connection testing and recording the change.

  • What you will learn, 1: what “no internet access” means, and how to identify what is being blocked and where.
  • What you will learn, 2: choosing and implementing allowlisting, proxy access or offline USB operation.
  • What you will learn, 3: the seven change-request items, requirements table and post-change connectivity tests.
WHY BLOCKED

Why access is blocked: often the company gateway, not the unit

A website that opens at home may fail on corporate Wi-Fi. The phone is not necessarily broken: the company firewall or proxy may be blocking access. Sovereign GaiXer can similarly work normally on the LAN while outbound internet traffic is blocked.

First, understand this

The product works without outbound access

AI processing and internal data stay on the unit. After required initial OS setup and updates, internet access is optional for core local AI use, and core functions work on isolated networks. Outbound access is needed for admin-console updates and web search.

Possible block 1

Firewall port restrictions

Outbound traffic may be restricted by port number or destination. Organizations that block server outbound traffic by default may therefore block the unit’s update check.

Possible block 2

A mandatory proxy

Company PCs may need a proxy server to reach the internet. A device that does not know the proxy settings cannot use that route. Configure the unit accordingly.

Possible block 3

URL filters and HTTPS inspection

A URL filter may block destination categories, or SSL inspection may decrypt and inspect HTTPS. The update server may be blocked as an uncategorized destination.

An analogy

Think of the LAN as an office floor and the internet as outside the building. Sovereign GaiXer can work on the floor, but leaving requires going through reception—the firewall—and sometimes a designated exit—the proxy. Blocked internet access means it has been stopped at reception. The procedure is to declare which device needs to visit which destination, and why.

THREE WAYS

Three approaches: allowlist, proxy or no outbound access

All three approaches can be appropriate. Organizations with strict isolation policies may choose method C and apply updates through USB on a scheduled basis, such as monthly.

Diagram: three outbound-access approaches
A. AllowlistAllow approved destinationsUpdate serverFirewallGaiXer unitNo unit-side proxy setupB. Corporate proxyUse the company gatewayUpdate serverFirewallProxy serverGaiXer unitConfigure the proxyC. Stay offlineUpdate through USBUpdate serverAnother PCUSBGaiXer unitNo outbound traffic

With each approach, core AI processing and internal documents remain inside the unit. Methods A and B allow update downloads and web-search queries. A search query is external traffic and must follow your information-handling policy.

A / Like approved sites on corporate Wi-Fi

Allowlist destinations on the firewall

Allow outbound HTTPS on TCP 443 only, with the unit’s IP as source and the update server or other required destinations as targets. No proxy change is needed on the unit. Restricting destinations makes the scope easier for IT to assess. See the requirements table.

B / Like a designated company exit

Use a corporate proxy

Configure the same proxy used by company PCs. In NVIDIA DGX OS, based on Ubuntu, open Settings → Network → Network Proxy → Manual and enter HTTP/HTTPS proxy addresses and ports. Allow the unit and destinations on the proxy.

C / Like keeping a phone in airplane mode

Stay offline and update through USB

Obtain updates using another internet-connected computer and transfer them by USB or similar media. The unit has no outbound traffic. This suits isolated-network operation: web search is unavailable, but the other core functions remain usable.

AspectA: AllowlistB: ProxyC: Offline
IT-side workAdd destination rules to firewallAuthorize unit and destinations on proxyNone for outbound access
Unit-side workNone for proxy settingsConfigure network proxyTransfer each update by USB
Admin-console online updatesAvailableAvailableUnavailable; apply via USB
Web searchAvailableAvailableUnavailable
Outbound trafficLimited to approved destinationsLimited to approved destinationsNone
Best suited toDestination-based server access policiesMandatory-proxy environmentsIsolated-network policies

A: Allowlist

IT-side work
Add destination rules to firewall
Unit-side work
None for proxy settings
Admin-console online updates
Available
Web search
Available
Outbound traffic
Limited to approved destinations
Best suited to
Destination-based server access policies

B: Proxy

IT-side work
Authorize unit and destinations on proxy
Unit-side work
Configure network proxy
Admin-console online updates
Available
Web search
Available
Outbound traffic
Limited to approved destinations
Best suited to
Mandatory-proxy environments

C: Offline

IT-side work
None for outbound access
Unit-side work
Transfer each update by USB
Admin-console online updates
Unavailable; apply via USB
Web search
Unavailable
Outbound traffic
None
Best suited to
Isolated-network policies

Comparison as of September 2026, assuming a typical corporate network. Your configuration may differ.

After completing required initial OS setup and updates, you can start with offline method C. You can begin on an isolated network and later switch to A or B if update handling becomes burdensome, with limited unit-side changes. Contact sales to discuss the choice.
STEPS

Seven network-change steps: from diagnosis to documentation

The process is similar to approving communication for another company device. Only the two unit-specific configuration points differ; otherwise follow IT’s normal change-management process.

STEP 1 / Business team + IT

Diagnose what is blocked

Run an update check and distinguish name-resolution failure, connection failure and proxy authentication. IT should inspect firewall and proxy logs to find where traffic from the unit’s IP is rejected. See troubleshooting.

STEP 2 / IT

Choose A, B or C

Follow company policy: destination-based outbound rules suggest A; a mandatory corporate proxy suggests B; required isolation suggests C. If choosing C, no outbound-enablement steps are needed—agree who will transfer updates by USB and when.

STEP 3 / Business team

Submit the request with a requirements table

Use the IT change-request form and include the seven items in section 4 and the requirements table. If device-connection approval is still pending, attach the security questionnaire responses (PDF, Japanese).

STEP 4 / IT

Implement the allowlist or proxy authorization

For A, add rules specifying source: unit IP; destination: approved endpoints; port: TCP 443; direction: outbound. For B, authorize the unit’s IP and destinations on the proxy. Add an approved URL-filter exception where required.

STEP 5 / Business team with IT

Configure the unit only for proxy method B

On the attached monitor, choose Settings → Network → Network Proxy → Manual, then enter HTTP and HTTPS proxy addresses and ports. Add internal destinations or address ranges to Ignored Hosts so internal traffic bypasses the proxy. Method A does not require this step.

STEP 6 / Business team + IT

Test whether the update check succeeds

Run an update check in the admin console. An “up to date” message or an update list confirms success. If web search is enabled, test it in chat. IT should check logs to confirm that traffic reaches only approved destinations.

STEP 7 / IT

Record the change and rollback procedure. Document added rules, proxy authorizations and unit settings, including which rules to remove to restore the previous state. This record can support the next request when adding or replacing a unit.

Fix the unit’s IP before writing rules. If an automatic address changes, an IP-based allow rule may stop working. See Part 4: assigning a static IP.
REQUEST

Writing the IT request: seven items to avoid missing information

Requests are often returned because information is missing. Providing the seven items IT needs to assess the change helps reduce unnecessary back-and-forth.

  • 1. Target device: Sovereign GaiXer, based on Lenovo ThinkStation PGX with NVIDIA DGX OS/Ubuntu; include location, fixed IP, MAC address and serial number.
  • 2. Purpose: downloading AI-OS/LLM updates and, if required, web search. Explain that the purpose is not transmitting internal documents, and core AI processing stays on the unit. Identify web-search queries separately as outbound traffic.
  • 3. Communication requirements: outbound only, HTTPS/TCP 443, and the destination domains in the requirements table. State that internet-initiated access to the unit is not required.
  • 4. Preferred method: A (allowlist) or B (proxy). Say that the company standard will be followed and leave the final network decision to IT.
  • 5. Frequency and timing: administrators choose when to check for updates, for example monthly outside business hours. Explain that update retrieval is not continuous communication.
  • 6. Security evidence: links to the security questionnaire responses (Japanese) and security page, covering data location, encryption and vulnerability handling.
  • 7. Rollback and contacts: describe how removing added rules restores the prior state, identify the internal owner and provide FIXER’s support contact.
Example request

Please allow outbound HTTPS (TCP 443) from the Sovereign GaiXer AI device at fixed IP 192.168.10.50 to the destinations in the attached requirements table for software updates. Internal data is not transmitted for these updates, and AI processing stays on the unit. An administrator will update monthly outside business hours. No internet-initiated inbound access is needed. The security questionnaire responses (Japanese) are attached. Rollback consists of removing the added rules, which apply only to this device. The IP address is an example.

REQUIREMENTS

Communication requirements: purpose, destination and port

Attach this table to the change request. Outbound communication generally uses HTTPS/TCP 443 for the functions described, rather than a continuous connection. Internal access is from users’ PCs to the unit.

PurposeDirectionDestinationProtocol / portNotes
Sovereign GaiXer AI-OS / LLM updatesOutboundFIXER update server (confirm current endpoint with support)HTTPS/443/TCPAdministrator initiated; unnecessary for C
Web search, if enabledOutboundSearch endpoint (confirm with support)HTTPS/443/TCPOnly when used; unavailable in C
NVIDIA DGX OS / Ubuntu security updatesOutboundports.ubuntu.com/developer.download.nvidia.com/repo.download.nvidia.comHTTP/80、HTTPS/443/TCPARM64 repositories in NVIDIA documentation; confirm which updates are included in FIXER packages
DNS name resolutionInternalCorporate DNS serverDNS / UDP and TCP 53Required for A/B; internal DNS must resolve external names
NTP time synchronizationInternal or outboundInternal NTP server (recommended)NTP/123/UDPIncorrect time may cause certificate validation failure
User PC → unitInternalUnit IP addressHTTP / HTTPS (confirm ports with support)Browser access; independent of internet exposure
Internet → unitInbound─Not requiredThe unit need not be exposed to the internet

Sovereign GaiXer AI-OS / LLM updates

Direction
Outbound
Destination
FIXER update server (confirm current endpoint with support)
Protocol / port
HTTPS/443/TCP
Notes
Administrator initiated; unnecessary for C

Web search, if enabled

Direction
Outbound
Destination
Search endpoint (confirm with support)
Protocol / port
HTTPS/443/TCP
Notes
Only when used; unavailable in C

NVIDIA DGX OS / Ubuntu security updates

Direction
Outbound
Destination
ports.ubuntu.com/developer.download.nvidia.com/repo.download.nvidia.com
Protocol / port
HTTP/80、HTTPS/443/TCP
Notes
ARM64 repositories in NVIDIA documentation; confirm which updates are included in FIXER packages

DNS name resolution

Direction
Internal
Destination
Corporate DNS server
Protocol / port
DNS / UDP and TCP 53
Notes
Required for A/B; internal DNS must resolve external names

NTP time synchronization

Direction
Internal or outbound
Destination
Internal NTP server (recommended)
Protocol / port
NTP/123/UDP
Notes
Incorrect time may cause certificate validation failure

User PC → unit

Direction
Internal
Destination
Unit IP address
Protocol / port
HTTP / HTTPS (confirm ports with support)
Notes
Browser access; independent of internet exposure

Internet → unit

Direction
Inbound
Destination
─
Protocol / port
Not required
Notes
The unit need not be exposed to the internet

Sovereign GaiXer communication requirements as of September 2026. OS update destinations refer to the ARM64 repositories in the NVIDIA DGX OS 7 User Guide. Confirm all marked or pending endpoint and port details with support before implementation.

Where SSL inspection decrypts HTTPS traffic, an approved inspection exception or corporate CA certificate installation may be needed. Follow IT policy and confirm supported methods with support.
TROUBLESHOOT

Troubleshooting: use symptoms to narrow the cause

“No internet access” has several stages. Check name resolution, reaching the destination, and intermediate filtering, in that order, to narrow the cause.

SymptomPossible causeCheck and response
Update check cannot find the serverDNS resolution failureCheck the unit’s DNS settings and whether corporate DNS resolves the external destination
Name resolves but connection fails or times outFirewall blocks TCP 443Check rejection logs for the unit IP; implement approved A rules
Company PCs connect but the unit cannotA mandatory proxy is not configuredUse B; configure Network Proxy and authorize the unit on the proxy
Authentication required or HTTP 407Authenticated proxyConfirm compatibility with support; IT may provide supported credentials or an approved IP-based authentication exception
Invalid certificate errorSSL inspection or incorrect clockCheck approved inspection exceptions and confirm time synchronization
Only one destination is blockedURL-filter category blockRequest an approved allowlist entry for required destinations

Update check cannot find the server

Possible cause
DNS resolution failure
Check and response
Check the unit’s DNS settings and whether corporate DNS resolves the external destination

Name resolves but connection fails or times out

Possible cause
Firewall blocks TCP 443
Check and response
Check rejection logs for the unit IP; implement approved A rules

Company PCs connect but the unit cannot

Possible cause
A mandatory proxy is not configured
Check and response
Use B; configure Network Proxy and authorize the unit on the proxy

Authentication required or HTTP 407

Possible cause
Authenticated proxy
Check and response
Confirm compatibility with support; IT may provide supported credentials or an approved IP-based authentication exception

Invalid certificate error

Possible cause
SSL inspection or incorrect clock
Check and response
Check approved inspection exceptions and confirm time synchronization

Only one destination is blocked

Possible cause
URL-filter category block
Check and response
Request an approved allowlist entry for required destinations

Illustrative troubleshooting for corporate networks, as of September 2026

What this means

Diagnose three stages: can we find the address (DNS), is the route open (TCP 443), and is a checkpoint blocking it (proxy, URL filter or SSL inspection)? Once the blocking point is known, the request to IT can be precise.

MISCONCEPTIONS

Common misconceptions and the actual arrangement

MisconceptionActual arrangement
Allowing outbound access sends internal documents outsideDocumented outbound functions are updates and web-search queries; core AI processing and internal documents stay local. Apply data-handling rules to external queries
The product cannot run unless ports are openedAfter initial setup, core local AI works offline, and updates can be transferred by USB
The entire firewall must be openedAllow only required destinations and ports from the unit’s IP
Internet-initiated inbound connections are also neededInbound exposure is not required
The unit must be continuously online to workThe described external functions communicate during update retrieval and web searches
Proxy environments are unsupportedConfigure the proxy in OS settings; confirm authenticated-proxy compatibility with support

Actual arrangement

Allowing outbound access sends internal documents outside
Documented outbound functions are updates and web-search queries; core AI processing and internal documents stay local. Apply data-handling rules to external queries
The product cannot run unless ports are opened
After initial setup, core local AI works offline, and updates can be transferred by USB
The entire firewall must be opened
Allow only required destinations and ports from the unit’s IP
Internet-initiated inbound connections are also needed
Inbound exposure is not required
The unit must be continuously online to work
The described external functions communicate during update retrieval and web searches
Proxy environments are unsupported
Configure the proxy in OS settings; confirm authenticated-proxy compatibility with support

Common questions about outbound access, based on published information as of September 2026

GLOSSARY

Mini glossary: terms you may hear from IT

Term 01

Sovereign GaiXer outbound communication

Traffic from the unit to the internet for updates or web search. The product can run without allowing it.

Term 02

Firewall

A system deciding which traffic can cross the network boundary, using rules combining source, destination and port.

Term 03

Port 443

A numbered network endpoint. HTTPS encrypted web traffic generally uses TCP 443, as do the outbound functions described here.

Term 04

Proxy server

A system that accesses the internet on behalf of internal devices. Configure the unit to use it where corporate policy requires a proxy.

Term 05

Allowlist

An explicit list of permitted destinations or applications. Method A adds required update destinations to approved firewall rules.

Term 06

URL filter

A mechanism that blocks destinations by category, such as non-business or uncategorized sites. An update server may need review if classified as unknown.

Term 07

SSL inspection

Inspection that decrypts encrypted traffic. Supported approaches may require an approved destination exception or corporate certificate installation.

Term 08

DNS (name resolution)

The system translating a server name into an IP address. Without resolution, a name-based connection cannot begin.

Term 09

Offline update

Downloading an update on another internet-connected computer and transferring it to the unit through USB or similar media.

Term 10

Communication-requirements table

A table listing purpose, direction, destination, protocol/port and notes. Attaching it helps IT turn requirements into approved rules.

FAQ

Outbound access: frequently asked questions

What is Sovereign GaiXer outbound communication?

It is traffic from the unit to the internet for downloading updates or performing web searches. The product works without it. Core AI processing and internal documents remain inside the unit; web search involves sending a search query externally.

Our firewall blocks outbound ports. Can we still use it?

Yes. After required initial OS setup and updates, internet access is optional for core local AI use, and core features work on isolated networks. Obtain update files on a connected computer, transfer them by USB or similar media, and apply them to the unit.

What should we allow for admin-console updates?

Allow outbound HTTPS (TCP 443) from the unit’s IP address to FIXER’s update server. Also confirm that internal DNS can resolve external names for the unit and that its time is synchronized through NTP. Obtain current destination details from support.

Our company only allows internet access through a proxy. Is that supported?

In NVIDIA DGX OS, based on Ubuntu, go to Settings → Network → Network Proxy → Manual and configure the HTTP/HTTPS proxy addresses and ports. The proxy must allow the unit and update-server destinations. Confirm authenticated-proxy compatibility with support.

Does allowing outbound traffic send internal data to the internet?

Core AI processing remains local. The documented outbound functions are update downloads and web-search queries; internal documents and ordinary AI inputs are processed inside the unit. Search queries are external traffic, so apply your information-handling rules when enabling web search. See the security page and security questionnaire responses (Japanese) for supporting information.

Do we need to allow incoming connections from the internet?

No. The unit does not need to be exposed to the internet. The relevant communication is outbound HTTPS initiated by the unit. Users access it from PCs on the internal LAN.

What should the IT change request contain?

Seven items: target device (IP, MAC and serial number), purpose (updates and web search), communication requirements (outbound HTTPS 443 and destinations), preferred approach (allowlist or proxy), frequency and timing, security evidence, and rollback procedure plus contacts. Attach the requirements table to reduce follow-up questions.

The update check says the server cannot be found. Where should we start?

Start with DNS. Check that the unit uses internal DNS and that this DNS service resolves the external destination. If resolution works but connection fails, investigate the firewall. If company PCs can connect but the unit cannot, check whether a required proxy is missing.

Can updates work with SSL inspection?

Possible approaches include an inspection exception for the update server or installing the corporate CA certificate on the unit. Follow IT policy and confirm supported procedures with support.

After initial setup, can we start offline and allow outbound traffic later?

Yes, after required initial OS setup and updates. Start with isolated operation (method C), then switch to a firewall allowlist (A) or corporate proxy (B) when needed. Method B requires proxy configuration on the unit; method A does not require that unit-side change.

SUMMARY

Three answers to “the network is blocked”

  • After required initial setup, core local AI works without outbound access. Admin-console online updates and web search need external communication; isolated operation with USB updates (C) remains a valid choice.
  • If allowing access, restrict it to required destinations and ports from the unit IP. Use firewall allowlisting (A) or a corporate proxy (B). Inbound internet exposure is unnecessary. Core internal-data processing stays local; web-search queries are external traffic.
  • Provide seven request items plus the requirements table. Diagnose, select, request, implement, configure, test and record, using the normal IT change-management process.

This article reflects the Japanese source as of September 2026. Update methods, offline operation and vulnerability handling summarize the published FAQ and security information. The three approaches, seven steps, request items and troubleshooting table describe general corporate-network scenarios; actual requirements depend on your configuration, security policies and procedures. Confirm pending destinations and ports with support. OS update destinations reference the ARM64 repositories in the NVIDIA DGX OS 7 User Guide: Air-Gapped Installations. Proxy labels follow the standard Ubuntu-based interface and may change with updates. Always follow IT instructions for settings and allow rules. IP addresses are examples. ThinkStation is a Lenovo trademark. “AI-OS” describes the software foundation for secure business AI. Smartphone and office analogies explain structure without implying compatibility or equivalence with specific products.
Company, product, and service names mentioned are trademarks or registered trademarks of their respective owners.