What if your network blocks internet access?
Enable updates and web search on a LAN with restricted outbound access
After required initial OS setup and updates, Sovereign GaiXer works without internet access. However, admin-console updates and web search require outbound traffic from the unit. Many companies restrict this through firewalls or proxies. This article explains how to move from blocked access to an approved configuration, including the change request to submit to IT.
In a sentence
Outbound communication means the unit contacting the internet for updates or web search; core local AI still works without it after required initial setup. There are three approaches: allowlist destinations on the firewall (A), use a corporate proxy (B), or stay offline and update through USB (C). Choose according to company security policy and submit a change request with a communication-requirements table. The seven steps are diagnosis, approach selection, request, implementation, unit configuration, connection testing and recording the change.
- What you will learn, 1: what “no internet access” means, and how to identify what is being blocked and where.
- What you will learn, 2: choosing and implementing allowlisting, proxy access or offline USB operation.
- What you will learn, 3: the seven change-request items, requirements table and post-change connectivity tests.
Why access is blocked: often the company gateway, not the unit
A website that opens at home may fail on corporate Wi-Fi. The phone is not necessarily broken: the company firewall or proxy may be blocking access. Sovereign GaiXer can similarly work normally on the LAN while outbound internet traffic is blocked.
The product works without outbound access
AI processing and internal data stay on the unit. After required initial OS setup and updates, internet access is optional for core local AI use, and core functions work on isolated networks. Outbound access is needed for admin-console updates and web search.
Firewall port restrictions
Outbound traffic may be restricted by port number or destination. Organizations that block server outbound traffic by default may therefore block the unit’s update check.
A mandatory proxy
Company PCs may need a proxy server to reach the internet. A device that does not know the proxy settings cannot use that route. Configure the unit accordingly.
URL filters and HTTPS inspection
A URL filter may block destination categories, or SSL inspection may decrypt and inspect HTTPS. The update server may be blocked as an uncategorized destination.
Think of the LAN as an office floor and the internet as outside the building. Sovereign GaiXer can work on the floor, but leaving requires going through reception—the firewall—and sometimes a designated exit—the proxy. Blocked internet access means it has been stopped at reception. The procedure is to declare which device needs to visit which destination, and why.
Three approaches: allowlist, proxy or no outbound access
All three approaches can be appropriate. Organizations with strict isolation policies may choose method C and apply updates through USB on a scheduled basis, such as monthly.
With each approach, core AI processing and internal documents remain inside the unit. Methods A and B allow update downloads and web-search queries. A search query is external traffic and must follow your information-handling policy.
Allowlist destinations on the firewall
Allow outbound HTTPS on TCP 443 only, with the unit’s IP as source and the update server or other required destinations as targets. No proxy change is needed on the unit. Restricting destinations makes the scope easier for IT to assess. See the requirements table.
Use a corporate proxy
Configure the same proxy used by company PCs. In NVIDIA DGX OS, based on Ubuntu, open Settings → Network → Network Proxy → Manual and enter HTTP/HTTPS proxy addresses and ports. Allow the unit and destinations on the proxy.
Stay offline and update through USB
Obtain updates using another internet-connected computer and transfer them by USB or similar media. The unit has no outbound traffic. This suits isolated-network operation: web search is unavailable, but the other core functions remain usable.
| Aspect | A: Allowlist | B: Proxy | C: Offline |
|---|---|---|---|
| IT-side work | Add destination rules to firewall | Authorize unit and destinations on proxy | None for outbound access |
| Unit-side work | None for proxy settings | Configure network proxy | Transfer each update by USB |
| Admin-console online updates | Available | Available | Unavailable; apply via USB |
| Web search | Available | Available | Unavailable |
| Outbound traffic | Limited to approved destinations | Limited to approved destinations | None |
| Best suited to | Destination-based server access policies | Mandatory-proxy environments | Isolated-network policies |
A: Allowlist
- IT-side work
- Add destination rules to firewall
- Unit-side work
- None for proxy settings
- Admin-console online updates
- Available
- Web search
- Available
- Outbound traffic
- Limited to approved destinations
- Best suited to
- Destination-based server access policies
B: Proxy
- IT-side work
- Authorize unit and destinations on proxy
- Unit-side work
- Configure network proxy
- Admin-console online updates
- Available
- Web search
- Available
- Outbound traffic
- Limited to approved destinations
- Best suited to
- Mandatory-proxy environments
C: Offline
- IT-side work
- None for outbound access
- Unit-side work
- Transfer each update by USB
- Admin-console online updates
- Unavailable; apply via USB
- Web search
- Unavailable
- Outbound traffic
- None
- Best suited to
- Isolated-network policies
Comparison as of September 2026, assuming a typical corporate network. Your configuration may differ.
Seven network-change steps: from diagnosis to documentation
The process is similar to approving communication for another company device. Only the two unit-specific configuration points differ; otherwise follow IT’s normal change-management process.
Diagnose what is blocked
Run an update check and distinguish name-resolution failure, connection failure and proxy authentication. IT should inspect firewall and proxy logs to find where traffic from the unit’s IP is rejected. See troubleshooting.
Choose A, B or C
Follow company policy: destination-based outbound rules suggest A; a mandatory corporate proxy suggests B; required isolation suggests C. If choosing C, no outbound-enablement steps are needed—agree who will transfer updates by USB and when.
Submit the request with a requirements table
Use the IT change-request form and include the seven items in section 4 and the requirements table. If device-connection approval is still pending, attach the security questionnaire responses (PDF, Japanese).
Implement the allowlist or proxy authorization
For A, add rules specifying source: unit IP; destination: approved endpoints; port: TCP 443; direction: outbound. For B, authorize the unit’s IP and destinations on the proxy. Add an approved URL-filter exception where required.
Configure the unit only for proxy method B
On the attached monitor, choose Settings → Network → Network Proxy → Manual, then enter HTTP and HTTPS proxy addresses and ports. Add internal destinations or address ranges to Ignored Hosts so internal traffic bypasses the proxy. Method A does not require this step.
Test whether the update check succeeds
Run an update check in the admin console. An “up to date” message or an update list confirms success. If web search is enabled, test it in chat. IT should check logs to confirm that traffic reaches only approved destinations.
Record the change and rollback procedure. Document added rules, proxy authorizations and unit settings, including which rules to remove to restore the previous state. This record can support the next request when adding or replacing a unit.
Writing the IT request: seven items to avoid missing information
Requests are often returned because information is missing. Providing the seven items IT needs to assess the change helps reduce unnecessary back-and-forth.
- 1. Target device: Sovereign GaiXer, based on Lenovo ThinkStation PGX with NVIDIA DGX OS/Ubuntu; include location, fixed IP, MAC address and serial number.
- 2. Purpose: downloading AI-OS/LLM updates and, if required, web search. Explain that the purpose is not transmitting internal documents, and core AI processing stays on the unit. Identify web-search queries separately as outbound traffic.
- 3. Communication requirements: outbound only, HTTPS/TCP 443, and the destination domains in the requirements table. State that internet-initiated access to the unit is not required.
- 4. Preferred method: A (allowlist) or B (proxy). Say that the company standard will be followed and leave the final network decision to IT.
- 5. Frequency and timing: administrators choose when to check for updates, for example monthly outside business hours. Explain that update retrieval is not continuous communication.
- 6. Security evidence: links to the security questionnaire responses (Japanese) and security page, covering data location, encryption and vulnerability handling.
- 7. Rollback and contacts: describe how removing added rules restores the prior state, identify the internal owner and provide FIXER’s support contact.
Please allow outbound HTTPS (TCP 443) from the Sovereign GaiXer AI device at fixed IP 192.168.10.50 to the destinations in the attached requirements table for software updates. Internal data is not transmitted for these updates, and AI processing stays on the unit. An administrator will update monthly outside business hours. No internet-initiated inbound access is needed. The security questionnaire responses (Japanese) are attached. Rollback consists of removing the added rules, which apply only to this device. The IP address is an example.
Communication requirements: purpose, destination and port
Attach this table to the change request. Outbound communication generally uses HTTPS/TCP 443 for the functions described, rather than a continuous connection. Internal access is from users’ PCs to the unit.
| Purpose | Direction | Destination | Protocol / port | Notes |
|---|---|---|---|---|
| Sovereign GaiXer AI-OS / LLM updates | Outbound | FIXER update server (confirm current endpoint with support) | HTTPS/443/TCP | Administrator initiated; unnecessary for C |
| Web search, if enabled | Outbound | Search endpoint (confirm with support) | HTTPS/443/TCP | Only when used; unavailable in C |
| NVIDIA DGX OS / Ubuntu security updates | Outbound | ports.ubuntu.com/developer.download.nvidia.com/repo.download.nvidia.com | HTTP/80、HTTPS/443/TCP | ARM64 repositories in NVIDIA documentation; confirm which updates are included in FIXER packages |
| DNS name resolution | Internal | Corporate DNS server | DNS / UDP and TCP 53 | Required for A/B; internal DNS must resolve external names |
| NTP time synchronization | Internal or outbound | Internal NTP server (recommended) | NTP/123/UDP | Incorrect time may cause certificate validation failure |
| User PC → unit | Internal | Unit IP address | HTTP / HTTPS (confirm ports with support) | Browser access; independent of internet exposure |
| Internet → unit | Inbound | ─ | Not required | The unit need not be exposed to the internet |
Sovereign GaiXer AI-OS / LLM updates
- Direction
- Outbound
- Destination
- FIXER update server (confirm current endpoint with support)
- Protocol / port
- HTTPS/443/TCP
- Notes
- Administrator initiated; unnecessary for C
Web search, if enabled
- Direction
- Outbound
- Destination
- Search endpoint (confirm with support)
- Protocol / port
- HTTPS/443/TCP
- Notes
- Only when used; unavailable in C
NVIDIA DGX OS / Ubuntu security updates
- Direction
- Outbound
- Destination
- ports.ubuntu.com/developer.download.nvidia.com/repo.download.nvidia.com
- Protocol / port
- HTTP/80、HTTPS/443/TCP
- Notes
- ARM64 repositories in NVIDIA documentation; confirm which updates are included in FIXER packages
DNS name resolution
- Direction
- Internal
- Destination
- Corporate DNS server
- Protocol / port
- DNS / UDP and TCP 53
- Notes
- Required for A/B; internal DNS must resolve external names
NTP time synchronization
- Direction
- Internal or outbound
- Destination
- Internal NTP server (recommended)
- Protocol / port
- NTP/123/UDP
- Notes
- Incorrect time may cause certificate validation failure
User PC → unit
- Direction
- Internal
- Destination
- Unit IP address
- Protocol / port
- HTTP / HTTPS (confirm ports with support)
- Notes
- Browser access; independent of internet exposure
Internet → unit
- Direction
- Inbound
- Destination
- ─
- Protocol / port
- Not required
- Notes
- The unit need not be exposed to the internet
Sovereign GaiXer communication requirements as of September 2026. OS update destinations refer to the ARM64 repositories in the NVIDIA DGX OS 7 User Guide. Confirm all marked or pending endpoint and port details with support before implementation.
Troubleshooting: use symptoms to narrow the cause
“No internet access” has several stages. Check name resolution, reaching the destination, and intermediate filtering, in that order, to narrow the cause.
| Symptom | Possible cause | Check and response |
|---|---|---|
| Update check cannot find the server | DNS resolution failure | Check the unit’s DNS settings and whether corporate DNS resolves the external destination |
| Name resolves but connection fails or times out | Firewall blocks TCP 443 | Check rejection logs for the unit IP; implement approved A rules |
| Company PCs connect but the unit cannot | A mandatory proxy is not configured | Use B; configure Network Proxy and authorize the unit on the proxy |
| Authentication required or HTTP 407 | Authenticated proxy | Confirm compatibility with support; IT may provide supported credentials or an approved IP-based authentication exception |
| Invalid certificate error | SSL inspection or incorrect clock | Check approved inspection exceptions and confirm time synchronization |
| Only one destination is blocked | URL-filter category block | Request an approved allowlist entry for required destinations |
Update check cannot find the server
- Possible cause
- DNS resolution failure
- Check and response
- Check the unit’s DNS settings and whether corporate DNS resolves the external destination
Name resolves but connection fails or times out
- Possible cause
- Firewall blocks TCP 443
- Check and response
- Check rejection logs for the unit IP; implement approved A rules
Company PCs connect but the unit cannot
- Possible cause
- A mandatory proxy is not configured
- Check and response
- Use B; configure Network Proxy and authorize the unit on the proxy
Authentication required or HTTP 407
- Possible cause
- Authenticated proxy
- Check and response
- Confirm compatibility with support; IT may provide supported credentials or an approved IP-based authentication exception
Invalid certificate error
- Possible cause
- SSL inspection or incorrect clock
- Check and response
- Check approved inspection exceptions and confirm time synchronization
Only one destination is blocked
- Possible cause
- URL-filter category block
- Check and response
- Request an approved allowlist entry for required destinations
Illustrative troubleshooting for corporate networks, as of September 2026
Diagnose three stages: can we find the address (DNS), is the route open (TCP 443), and is a checkpoint blocking it (proxy, URL filter or SSL inspection)? Once the blocking point is known, the request to IT can be precise.
Common misconceptions and the actual arrangement
| Misconception | Actual arrangement |
|---|---|
| Allowing outbound access sends internal documents outside | Documented outbound functions are updates and web-search queries; core AI processing and internal documents stay local. Apply data-handling rules to external queries |
| The product cannot run unless ports are opened | After initial setup, core local AI works offline, and updates can be transferred by USB |
| The entire firewall must be opened | Allow only required destinations and ports from the unit’s IP |
| Internet-initiated inbound connections are also needed | Inbound exposure is not required |
| The unit must be continuously online to work | The described external functions communicate during update retrieval and web searches |
| Proxy environments are unsupported | Configure the proxy in OS settings; confirm authenticated-proxy compatibility with support |
Actual arrangement
- Allowing outbound access sends internal documents outside
- Documented outbound functions are updates and web-search queries; core AI processing and internal documents stay local. Apply data-handling rules to external queries
- The product cannot run unless ports are opened
- After initial setup, core local AI works offline, and updates can be transferred by USB
- The entire firewall must be opened
- Allow only required destinations and ports from the unit’s IP
- Internet-initiated inbound connections are also needed
- Inbound exposure is not required
- The unit must be continuously online to work
- The described external functions communicate during update retrieval and web searches
- Proxy environments are unsupported
- Configure the proxy in OS settings; confirm authenticated-proxy compatibility with support
Common questions about outbound access, based on published information as of September 2026
Mini glossary: terms you may hear from IT
Sovereign GaiXer outbound communication
Traffic from the unit to the internet for updates or web search. The product can run without allowing it.
Firewall
A system deciding which traffic can cross the network boundary, using rules combining source, destination and port.
Port 443
A numbered network endpoint. HTTPS encrypted web traffic generally uses TCP 443, as do the outbound functions described here.
Proxy server
A system that accesses the internet on behalf of internal devices. Configure the unit to use it where corporate policy requires a proxy.
Allowlist
An explicit list of permitted destinations or applications. Method A adds required update destinations to approved firewall rules.
URL filter
A mechanism that blocks destinations by category, such as non-business or uncategorized sites. An update server may need review if classified as unknown.
SSL inspection
Inspection that decrypts encrypted traffic. Supported approaches may require an approved destination exception or corporate certificate installation.
DNS (name resolution)
The system translating a server name into an IP address. Without resolution, a name-based connection cannot begin.
Offline update
Downloading an update on another internet-connected computer and transferring it to the unit through USB or similar media.
Communication-requirements table
A table listing purpose, direction, destination, protocol/port and notes. Attaching it helps IT turn requirements into approved rules.
Outbound access: frequently asked questions
What is Sovereign GaiXer outbound communication?
It is traffic from the unit to the internet for downloading updates or performing web searches. The product works without it. Core AI processing and internal documents remain inside the unit; web search involves sending a search query externally.
Our firewall blocks outbound ports. Can we still use it?
Yes. After required initial OS setup and updates, internet access is optional for core local AI use, and core features work on isolated networks. Obtain update files on a connected computer, transfer them by USB or similar media, and apply them to the unit.
What should we allow for admin-console updates?
Allow outbound HTTPS (TCP 443) from the unit’s IP address to FIXER’s update server. Also confirm that internal DNS can resolve external names for the unit and that its time is synchronized through NTP. Obtain current destination details from support.
Our company only allows internet access through a proxy. Is that supported?
In NVIDIA DGX OS, based on Ubuntu, go to Settings → Network → Network Proxy → Manual and configure the HTTP/HTTPS proxy addresses and ports. The proxy must allow the unit and update-server destinations. Confirm authenticated-proxy compatibility with support.
Does allowing outbound traffic send internal data to the internet?
Core AI processing remains local. The documented outbound functions are update downloads and web-search queries; internal documents and ordinary AI inputs are processed inside the unit. Search queries are external traffic, so apply your information-handling rules when enabling web search. See the security page and security questionnaire responses (Japanese) for supporting information.
Do we need to allow incoming connections from the internet?
No. The unit does not need to be exposed to the internet. The relevant communication is outbound HTTPS initiated by the unit. Users access it from PCs on the internal LAN.
What should the IT change request contain?
Seven items: target device (IP, MAC and serial number), purpose (updates and web search), communication requirements (outbound HTTPS 443 and destinations), preferred approach (allowlist or proxy), frequency and timing, security evidence, and rollback procedure plus contacts. Attach the requirements table to reduce follow-up questions.
The update check says the server cannot be found. Where should we start?
Start with DNS. Check that the unit uses internal DNS and that this DNS service resolves the external destination. If resolution works but connection fails, investigate the firewall. If company PCs can connect but the unit cannot, check whether a required proxy is missing.
Can updates work with SSL inspection?
Possible approaches include an inspection exception for the update server or installing the corporate CA certificate on the unit. Follow IT policy and confirm supported procedures with support.
After initial setup, can we start offline and allow outbound traffic later?
Yes, after required initial OS setup and updates. Start with isolated operation (method C), then switch to a firewall allowlist (A) or corporate proxy (B) when needed. Method B requires proxy configuration on the unit; method A does not require that unit-side change.
Three answers to “the network is blocked”
- After required initial setup, core local AI works without outbound access. Admin-console online updates and web search need external communication; isolated operation with USB updates (C) remains a valid choice.
- If allowing access, restrict it to required destinations and ports from the unit IP. Use firewall allowlisting (A) or a corporate proxy (B). Inbound internet exposure is unnecessary. Core internal-data processing stays local; web-search queries are external traffic.
- Provide seven request items plus the requirements table. Diagnose, select, request, implement, configure, test and record, using the normal IT change-management process.
This article reflects the Japanese source as of September 2026. Update methods, offline operation and vulnerability handling summarize the published FAQ and security information. The three approaches, seven steps, request items and troubleshooting table describe general corporate-network scenarios; actual requirements depend on your configuration, security policies and procedures. Confirm pending destinations and ports with support. OS update destinations reference the ARM64 repositories in the NVIDIA DGX OS 7 User Guide: Air-Gapped Installations. Proxy labels follow the standard Ubuntu-based interface and may change with updates. Always follow IT instructions for settings and allow rules. IP addresses are examples. ThinkStation is a Lenovo trademark. “AI-OS” describes the software foundation for secure business AI. Smartphone and office analogies explain structure without implying compatibility or equivalence with specific products.
Company, product, and service names mentioned are trademarks or registered trademarks of their respective owners.