Skip to main content
Level 2
July 8, 2026
Question

Marketo Data Center Migration to AWS Public Cloud

  • July 8, 2026
  • 4 replies
  • 687 views

Hi all,

Based on the AWS Migration documentation, the IP addresses need to be added by Company IT department. I reached out to them, and they asked for the following additional information.

Source IP/ or usernames (which ever is applicable):

Destination urls:

Port numbers:

APP ID:

 

Can someone help me how to get these details?

 

Regards,

Gowtham 

4 replies

SanfordWhiteman
Level 10
July 8, 2026
  • New destination IPs are at the base of that doc.
  • Destination URLs aren’t relevant — you can’t inspect URLs unless you have a MITM proxy so it’s not practical to filter based on URL. There are far too many URLs to list, anyway.
  • The only outbound port afaik is 443 (i.e. HTTPS). Note websockets also run over that port for Dynamic Chat, it’s not just basic HTTP.
  • Not clear what they mean by “APP ID” unless they mean HTTP?

The doc also suggests these IPs will send email — thus only if you already whitelist Marketo IPs for inbound SMTP, these would need to be added. I’m not sure this is accurate. Either way, IMO, whitelisting is a bad idea as it obscures wider deliverability problems.

Level 2
October 6, 2026

Hello ​@GowthamNataraj1 

Has your AWS migration been completed? I wanted to check what information you provided to the IT team for the below details:

  • Source IPs/usernames (whichever is applicable)

  • Destination URLs

  • Port numbers

 

Thanks!!
 

Level 2
October 6, 2026

No action was taken by the IT team since Marketo is not sending requests to on-premises applications and sending requests to only public hosted applications. Initially, I created a Marketo support case to get the information requested by IT.

AmitVishwakarma
Community Advisor
Community Advisor
October 6, 2026

Hi ​@GowthamNataraj1 
No firewall change may be needed for your setup if the public CRM/webhook endpoints accept connections without restricting them by source IP, and your mail gateway does not have a Marketo IP allowlist. However, a cloud-hosted endpoint can still enforce an IP allowlist, so confirm that with the owner of each receiving service. Marketo recommends adding the migration IPs where allowlists are in use and retaining the existing entries.
https://experienceleague.adobe.com/en/docs/marketo/using/getting-started/things-to-know/aws-migration

 

To find the applicable migration IPs, check the data center and pod in Admin > My Account > Support Information, then use the matching entry in the migration guide. For an IP-based firewall rule, provide the source IPs—not usernames.https://experienceleague.adobe.com/en/docs/marketo/using/getting-started/things-to-know/system-status-notifications

 

There is no single migration-wide destination URL or App ID: Marketo UI access uses the domains in the protocol guide; CRM/webhook destinations are the customer's configured integration endpoints. Ask IT what it means by "App ID" rather than guessing. The migration guide doesn't specify a new port; for an HTTPS integration, TCP 443 is typical, but confirm the port for the actual endpoint and any custom configuration.https://experienceleague.adobe.com/en/docs/marketo/using/getting-started/initial-setup/configure-protocols-for-marketo

Amit Vishwakarma - Adobe Commerce Champion 2025 | 17x Adobe certified | 6x Adobe SME