Users can sign in to Box and still be unable to upload or download a file. In a Box Zone, that usually means the firewall or proxy allowlist is missing that Zone’s hostnames.
Box Zones uses a dedicated set of hostnames for each Zone, in addition to the standard Box domains. If your organization restricts outbound traffic, your network or security team has to allowlist the hostnames for every Zone your people are assigned to.
That list changes. When Box launches a Zone, or turns on a capability inside a Zone that needs its own network path, new hostnames are added to Configuring Firewall Access for Box Zones on docs.box.com. An allowlist that was correct last quarter can be incomplete after the next release. Check that page whenever Box ships a Zones capability, and again before you assign people to a Zone you have not used before.
Two changes already on that page are easy to miss if the allowlist was built earlier.
What You Need to Know
- Allowlist the hostnames for the Zones your people are actually assigned to. A person in a Zone whose hostnames are missing may be unable to upload or download, even though sign-in still works.
- Each Zone has the same four endpoint types today: upload, upload for Box Verified Enterprise, download, and SFTP. Add the Box Verified Enterprise hostname only if your organization is a Box Verified Enterprise. Add the SFTP hostname only if you use Box SFTP.
- A future capability can add another endpoint type. When it does, docs.box.com is where the new hostname shows up, Zone by Zone, as that capability becomes available.
- Allowlist the hostnames themselves. Do not pin the rule to an IP address. Addresses can change.
- The docs page is the list to implement against. This post covers what has already changed. The page is what to re-check next time.
What changed
July 2026 — three new Zones. Switzerland, Singapore, and Israel joined Box Zones. Box Zones now covers ten regions. Each new Zone has its own hostnames. If you assign people to one of these Zones, those hostnames have to be on the allowlist before they upload or download.
September 16, 2026 — in-region compute for France and Canada. France and Canada were already available for content storage. Until this change, uploads, downloads, encryption, and previews for people in those Zones ran outside the Zone. On September 16 that processing moved inside the Zone, onto the Zone-specific endpoints below.
The allowlist that worked before September 16 is not enough. If people in the France or Canada Zone lost the ability to upload, download, or otherwise work with files on or after September 16, start with the allowlist.
The same pattern will repeat. A capability that needs hostnames the table does not already list is added on the docs page. Check that page when you hear about a new Zone or a new in-Zone capability, instead of waiting until a user reports that upload or download has stopped.
Hostnames to add
Add every hostname for a Zone you use or might use in the future. Skip the Box Verified Enterprise or SFTP row only when that case does not apply to you.
France
fupload-euw9.app.box.comfupload-euw9.ent.box.com(Box Verified Enterprise only)euw9.boxcloud.comsftp-euw9.services.box.com(SFTP only)
Canada
fupload-nan2.app.box.comfupload-nan2.ent.box.com(Box Verified Enterprise only)nan2.boxcloud.comsftp-nan2.services.box.com(SFTP only)
Switzerland (if you assign users to this Zone)
fupload-euw6.app.box.comfupload-euw6.ent.box.com(Box Verified Enterprise only)euw6.boxcloud.comsftp-euw6.services.box.com(SFTP only)
Singapore (if you assign users to this Zone)
fupload-ase1.app.box.comfupload-ase1.ent.box.com(Box Verified Enterprise only)ase1.boxcloud.comsftp-ase1.services.box.com(SFTP only)
Israel (if you assign users to this Zone)
fupload-asw1.app.box.comfupload-asw1.ent.box.com(Box Verified Enterprise only)asw1.boxcloud.comsftp-asw1.services.box.com(SFTP only)
Hostnames for the other Zones (US, Japan, Australia, EU, UK), and any endpoint added after this post, are on the docs page. Open it and compare it with your allowlist. That comparison is the check worth repeating.
What to do
- Open Configuring Firewall Access for Box Zones and note every Zone your users are assigned to.
- Send your network or security team the hostnames for those Zones, including any row or column that was not on the allowlist the last time you looked.
- Add the hostnames to the outbound firewall or proxy allowlist.
- Ask affected users to upload and download a file in Box.
- Come back to the same docs page the next time Box adds a Zone or an in-Zone capability. New endpoints are published there as those capabilities ship.
This covers Box Zones only. Your allowlist still needs the standard Box domains for every other Box application and service.
Resources
- The page to check, and to check again: Configuring Firewall Access for Box Zones
- Standard Box domains, all products: Configuring a Firewall for Box Applications and Services
- Product announcement: New Box Zones in Switzerland, Singapore, and Israel, with expanded in-region processing for France and Canada
We want to hear from you
If people in a Zone still cannot upload or download after the allowlist matches the docs page, reply with the Zone and what fails (upload, download, preview, or SFTP). Other admins hit the same gap, and the reply helps the next person who finds this thread.
