Schaeffler OPTIME
FAQ
We start by spelling out the abbreviations used on this site, then answer the most common questions.
Glossary
Abbreviations first - plain-language explanations follow.
- FAQ
- Frequently Asked QuestionsCommon questions about this service.
- IoT
- Internet of ThingsConnected devices and services.
- SIM
- Subscriber Identity ModuleThe mobile identity stored on the SIM.
- ICCID
- Integrated Circuit Card IdentifierThe unique number of a SIM card.
- CMDB
- Configuration Management DatabaseThe asset and configuration data store.
- API
- Application Programming InterfaceThe interface used by software clients.
Network connectivity
Which FQDNs must the gateway be allowed to reach?
Use the explicit FQDNs below where firewall policy permits. The Azure wildcards are relevant only when an explicit allowlist cannot be maintained. Jump to the IP reference.
Open the current Schaeffler OPTIME connectivity settings. Detailed network settings are available only after authenticating as a Schaeffler OPTIME User.
OPTIME update package transmission (OTA)
OTA means over-the-air update package transmission. The device-ota-update page is the primary update entry point. The lookup hosts and firmware service support the package delivery path; allow all applicable endpoints for reliable updates.
- schaeffler-optime.io/device-ota-update Primary OTA/update package entry point.
- schaeffler-optime.com
- lookup.schaeffler-optime.com Public update package downloads without mTLS.
- lookup-mtls.schaeffler-optime.com mTLS-protected update package lookup/download path.
- gateway-firmware.api.sls-sms-d.de Firmware service; redirects to Azure Blob Storage
- gateway-firmware.api.sls-sms-p.de Firmware service; redirects to Azure Blob Storage and participates in OTA package delivery.
- status.schaeffler-lifetime-solutions.eu Disaster-recovery fallback, independent of Azure
Azure IoT and Blob Storage
sls-iothub-prod-westeurope-i2b6j-orj.azure-devices.nettempartifactstgfirmware.blob.core.windows.netslswestindiastg.blob.core.windows.netIndia-located update files to reduce latencyi40gw2fwcstgd.blob.core.windows.net
Protocols and ports
These are the outbound gateway transport requirements. The protocol is direct gateway traffic, not a value derived from CMDB, LocalDB, or IoT Hub lookup data.
- Azure Blob Storage
- HTTPS over TCP port 443
- Azure IoT Hub
- HTTPS over TCP port 443 and MQTT/S over TCP port 8883
- Recommended future-proof transport
- HTTP/3 over UDP port 443, where the gateway and firewall support it. This improves reliability compared with HTTP/1.1 or HTTP/2 over TCP.
Required gateway connectivity
The gateway uses these services for address assignment, name resolution, connectivity checks, time synchronisation, updates, provisioning, application traffic, and maintenance. Static addresses and selected servers can be configured in the gateway configuration UI where noted.
- ICMP
- General network traffic for ping and traceroute. Used for connectivity checks and the gateway LED; default targets are google.com and baidu.cn, and targets can be configured.
- DHCP client
- Outbound UDP 67 and inbound UDP 68 for dynamic addressing. Static addressing can be configured instead.
- DNS
- Outbound UDP 53 and TCP 53. DNS servers can be configured in the gateway configuration UI.
- HTTP
- Outbound TCP 80 for connectivity checks: ipv4.connman.net on OPTIME gateway (2019) and network-test.debian.org/nm on OPTIME gateway 2.
- HTTPS
- Outbound TCP 443 for updates, provisioning, and firmware downloads. Gateway-specific targets are listed below.
- NTP
- Outbound UDP 123 for time synchronisation. Custom NTP servers can be configured; pool.ntp.org is the documented default.
- MQTT/S
- Outbound TCP 8883 for application communication with Azure services.
- Maintenance channel
- Outbound TCP 10011 for gateway maintenance. Additional gateway-generation targets and ports are listed below.
Provisioning, update, and maintenance targets
OPTIME gateway (2019, Gen1/GW1)
global.azure-devices-provisioning.nettempartifactstgfirmware.blob.core.windows.netschaeffler-optime.ioTCP 10011i40-optime-gw1-eu-p.schaeffler-iot.comTCP 10024i40-optime-gw1-cn-p.schaeffler-iot.com
OPTIME gateway 2 (Gen2/GW2)
global.azure-devices-provisioning.neti40gw2fwcstgd.blob.core.windows.nettempartifactstgfirmware.blob.core.windows.netschaeffler-optime.iosls-gw-gen2-rssh.schaeffler-iot.com
After provisioning, a gateway may connect to different IoT Hub FQDNs depending on latency or manual configuration. See the regional IoT Hub list below.
DPS (Device Provisioning Service) uses global.azure-devices-provisioning.net over HTTPS/TLS on TCP 443 and MQTT/S over TCP 8883. This note is included for completeness; both transports must be permitted where the gateway uses them.
Outgoing ports and targets
TCP 10011toi40-optime-gw1-eu-p.schaeffler-iot.comTCP 10024toi40-optime-gw1-cn-p.schaeffler-iot.comTCP 10030toi40-rssh-vm-v4.westeurope.cloudapp.azure.com
Relevant wildcards
Use these only as a broader alternative to explicit endpoint allowlisting.
*.azure-devices.net*.blob.core.windows.net*.azure-devices.cn*.blob.core.chinacloudapi.cn
Legacy endpoint
schaeffler-prod-iothub.azure-devices.net is a legacy endpoint. Its replacement is planned by 2028.
cm20storageaccount01.blob.core.windows.net is a legacy and deprecated Blob Storage endpoint. Its replacement is planned by 2028.
IP allowlist reference
Use the current IPv4 addresses below when an IP-based whitelist is required. Hostnames remain preferred where possible. These values reflect DNS resolution checked on 2026-07-30 and may change.
schaeffler-iot.comno IPv4 A record returned from current DNSschaeffler-optime.com150.171.109.100schaeffler-optime.io150.171.109.101lookup.schaeffler-optime.com20.71.186.35; downloads without mTLSlookup-mtls.schaeffler-optime.com20.71.186.35gateway-firmware.api.sls-sms-d.de98.64.165.27gateway-firmware.api.sls-sms-p.deno IPv4 A record returned from current DNSstatus.schaeffler-lifetime-solutions.eu202.61.206.122
Additional IoT Hub endpoints
sls-iothub-prod-westeurope-i2b6j-5i3.azure-devices.netsls-iothub-prod-westeurope-i2b6j-znp.azure-devices.netsls-iothub-prod-westeurope-i2b6j-mc5.azure-devices.netsls-iothub-prod-westeurope-i2b6j-orj.azure-devices.netsls-iothub-prod-eastus-i2b6j-a3d.azure-devices.netsls-iothub-prod-australiaeast-i2b6j-20f.azure-devices.netsls-iothub-prod-brazilsouth-i2b6j-7uw.azure-devices.netsls-iothub-prod-japaneast-i2b6j-b4l.azure-devices.netsls-iothub-prod-westus-i2b6j-z5j.azure-devices.netsls-iothub-prod-southeastasia-i2b6j-cw4.azure-devices.net
Schaeffler may change port numbers and add or remove addresses through standard service change notifications. This page is updated accordingly; the authenticated connectivity documentation remains the authoritative reference.