IT administrator guide

Network and device requirements

Everything your district needs to allow so students and teachers can use Active Learning Labs on a filtered school network, including Chromebooks managed through Google Admin.

Last updated: October 1, 2026Applies to: app.activelearninglabs.comPlatform: browser based, nothing to install
Go to the allowlist

Overview

Active Learning Labs is a web application for career and technical education. Students and teachers use it in a browser on Chromebooks, Windows, macOS or iPad. Nothing is installed on the device, and all traffic uses HTTPS or secure WebSockets on TCP port 443.

Our domain
*.activelearninglabs.com
One wildcard covers the app, content delivery and live class events
Plus
Google and one CDN
Sign-in, saved progress, reCAPTCHA and the slide viewer engine
Ports
TCP 443 only
HTTPS and WSS. No UDP, no custom ports
Video
YouTube
Some lessons embed YouTube videos

Most districts need to do two things: allow the domains in the list below, and exclude the hosts marked for SSL inspection bypass from decryption. If your network already permits Google Workspace services (Google sign-in, Firebase, reCAPTCHA), you are most of the way there.

We cannot publish fixed IP addresses. The application and its content are served through Amazon CloudFront and Google Cloud, whose IP ranges change without notice. Please allowlist by hostname.

Allowlist

Paste this into your content filter or firewall. Securly, GoGuardian, Lightspeed, Linewize, iboss, Palo Alto and similar products all accept hostnames and wildcards. Apply it to both student and staff policies.

# Active Learning Labs (app, content, live class events)
*.activelearninglabs.com

# Sign-in, saved progress and live sync (Google / Firebase)
accounts.google.com
apis.google.com
identitytoolkit.googleapis.com
securetoken.googleapis.com
firestore.googleapis.com
*.firebaseio.com

# Login protection (Google reCAPTCHA)
www.google.com
www.gstatic.com

# Slide viewer engine
cdn.jsdelivr.net

# Embedded lesson videos (YouTube)
www.youtube.com
www.youtube-nocookie.com
*.ytimg.com
*.googlevideo.com

# Optional: web fonts, teacher support chat, usage analytics
fonts.googleapis.com
fonts.gstatic.com
*.tawk.to
www.googletagmanager.com
*.google-analytics.com

Wildcards are preferred where your filter supports them. If it does not, the table below lists the exact hosts observed.

Domain details

Hosts marked Required are needed for lessons to work. Optional hosts improve the experience but students can work without them. Bypass SSL marks hosts that should be excluded from HTTPS decryption. From vendor docs marks hosts taken from the provider's own documentation rather than observed in our network audit.

HostUsed forStatusNotes
Active Learning Labs
app.activelearninglabs.comThe application: pages, scripts, API, and all lesson content (PDF slides, images and uploaded media under /static-content/, delivered by Amazon CloudFront)RequiredBypass SSLServes PDFs and images. Opening a lesson link directly may return the app with an HTTP 404 status; the lesson still loads, so do not block on status code.
ws.activelearninglabs.comLive class events over a long-lived WebSocket (teacher controls, pacing, team activity)RequiredBypass SSLWebSocket (wss). Do not close idle connections during a class period.
www.activelearninglabs.comPublic website. Users land here after logging outOptionalNot needed during lessons.
Sign-in, saved progress and live sync (Google / Firebase)
accounts.google.comapis.google.comGoogle Identity Services and the Google API client, loaded on every page. Also handles Sign in with GoogleRequired
identitytoolkit.googleapis.comsecuretoken.googleapis.comFirebase Authentication: session token exchange after any login, and the hourly token refreshRequiredWithout the token refresh host, sessions drop after about an hour.
firestore.googleapis.comFirebase Firestore: saves student progress and streams updates over a long-lived channelRequiredBypass SSLLong-polling connections stay open for the whole lesson.
*.firebaseio.comFirebase Realtime Database over WebSocketRequiredBypass SSLConnects to rotating shard hostnames such as s-gke-usc1-nssi4-29.firebaseio.com. Use the wildcard.
Login protection
www.google.comwww.gstatic.comGoogle reCAPTCHA on the login page. Some sign-ins show an image challengeRequiredBlocking these blocks email and password sign-in.
Slide viewer
cdn.jsdelivr.netRendering engine for PDF slides (pdf.js worker script)RequiredWithout it, slides do not render.
Embedded lesson videos
www.youtube.comwww.youtube-nocookie.com*.ytimg.com*.googlevideo.comSome lessons embed YouTube videos. The player loads from youtube.com, thumbnails from ytimg.com and the video stream from googlevideo.comRequiredFrom vendor docsOnly needed for lessons that contain video. Districts that use YouTube Restricted Mode can keep it on; our videos are not age-restricted.
Optional services
fonts.googleapis.comfonts.gstatic.comWeb fontsOptionalPages fall back to system fonts if blocked.
*.tawk.toIn-app support chat for teachers to reach us. Not loaded for student accountsOptionalUses WebSocket to rotating vsbNN.tawk.to servers. Recommended for staff policies.
www.googletagmanager.com*.google-analytics.comstats.g.doubleclick.netAnonymous usage analyticsOptionalNo effect on students if blocked.
Hosts you may see in logs that need no action

Requests to csp.withgoogle.com are security-policy reports sent by Google's own sign-in frames. Chrome rejects them itself and they have no effect on the application. A country-specific Google domain such as www.google.com or www.google.co.uk may appear once at logout from the analytics library.

SSL inspection and decryption

Filters that decrypt HTTPS traffic (Securly, Lightspeed Filter, GoGuardian, Zscaler, Palo Alto and others) can alter binary responses and interrupt long-lived connections even when a host is allowed. Exclude these from decryption:

  • app.activelearninglabs.com (PDF slides, images, fonts)
  • ws.activelearninglabs.com (WebSocket)
  • firestore.googleapis.com and *.firebaseio.com (long-lived sync)
  • *.googlevideo.com (video streams, for lessons with video)

WebSocket upgrade: if your firewall or filter performs SSL inspection, it must also pass the WebSocket upgrade handshake (Connection: Upgrade, Upgrade: websocket) to ws.activelearninglabs.com and *.firebaseio.com. Some products decrypt the connection but then drop the upgrade. When that happens the lesson still loads and looks normal, but live class sync (teacher pacing, team activity) silently stops working. Most filters have a separate "allow WebSocket" or "bypass" setting for this.

Symptom to watch for: slides stuck on "Loading the document, please wait", or slides that load once after clearing the browser cache and then stop loading. In the cases we have investigated, the cause was a decrypting proxy or a cached response on a managed Chromebook, not the school's internet connection.

Ports, protocols and TLS

ProtocolPortUsed by
HTTPSTCP 443All application, API, content and video traffic
Secure WebSocket (wss)TCP 443
  • ws.activelearninglabs.com
  • *.firebaseio.com
  • *.tawk.to (optional, teachers only)
UDPNoneNot used
  • TLS 1.2 or later is required on every host. Proxies that negotiate TLS 1.0 or 1.1 will fail to connect, and the WebSocket in particular fails without an error message.
  • WebSocket upgrade on port 443 must be permitted, including through any SSL-inspecting proxy (see the note above).
  • Idle timeout of at least 60 minutes on WebSocket connections, so a connection opened at the start of a class period survives to the end.

Quick connectivity test

From a student device on the school network, open these in a browser tab. Each one should load without a warning or block page.

Open this URLWhat a pass looks like
https://app.activelearninglabs.com/The Active Learning Labs login page, including the reCAPTCHA badge in the lower right corner. No badge means www.google.com or www.gstatic.com is blocked.
https://app.activelearninglabs.com/static-content/network-check/sample-slide.pdfA one-page PDF opens in the browser. A download prompt means the Chrome PDF viewer is disabled by policy; a block page means content delivery is filtered.

To confirm the WebSocket, sign in with a test account on a device where DevTools is allowed, press F12, open the Network tab, choose the WS filter and reload. You should see a connection to ws.activelearninglabs.com with status 101 that stays open. If it shows a different status, or closes within a few seconds, the upgrade is being blocked.

Managed Chromebook policies

For devices managed in the Google Admin console (Devices, then Chrome, then Settings), apply these to the student and staff organizational units.

SettingChrome policyValue
Site allowed if you run a URL blocklistURLAllowlistIf student Chrome policy blocks all sites by default (URLBlocklist contains *), add activelearninglabs.com, ws.activelearninglabs.com, google.com, googleapis.com, gstatic.com, firebaseio.com, cdn.jsdelivr.net and the YouTube hosts above. This policy is separate from your content filter.
Built-in PDF viewer stays enabledAlwaysOpenPdfExternallyDisabled (false). Slides are PDFs rendered in the page.
Pop-ups allowed for the appPopupsAllowedForUrlshttps://app.activelearninglabs.com
Cookies allowed for the appCookiesAllowedForUrlshttps://app.activelearninglabs.com. If third-party cookies are blocked, also allow https://[*.]google.com so Google sign-in works.
JavaScript enabledJavaScriptAllowedForUrlshttps://app.activelearninglabs.com
PDF downloads not forcedDownloadRestrictionsDo not block or force-download PDF files.
Developer tools for troubleshootingDeveloperToolsAvailabilityAllowed on at least one admin or test device, so you can send us a Network panel screenshot. It can stay blocked for students.

Chromebooks that use a Chrome extension filter (Securly, GoGuardian, Lightspeed) take the same host list from the Allowlist section through the extension's policy.

Email senders to allow

Teacher invitations, password resets, class codes and support replies come from our domain. Add it as a trusted sender in your mail filter so messages are not quarantined.

  • *@activelearninglabs.com

Transactional email is delivered through SendGrid and is SPF and DKIM aligned with activelearninglabs.com. If your mail gateway filters by sending infrastructure rather than the From address, also allow sendgrid.net.

Sign-in

Email and password

The login form is protected by Google reCAPTCHA. The hosts www.google.com and www.gstatic.com must be reachable, or sign-in fails without a clear error.

Sign in with Google

Uses Google Identity Services (accounts.google.com). If your Google Workspace restricts which third-party apps may use Google sign-in, add Active Learning Labs to the trusted apps list. Contact support@activelearninglabs.com for the OAuth client ID.

Rostering

Teachers create classes and invite students with a class code or by email. No roster sync or LMS integration is required.

Supported browsers and devices

  • Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari: current version and one version back
  • Chromebooks on a supported ChromeOS release
  • iPad with Safari, landscape orientation recommended for worksheets
  • A screen width of 1024 px or more is recommended for labs with spreadsheet worksheets
  • No audio hardware required. Lessons with video include captions where available.

Troubleshooting: slides, images or video do not load

  1. Check the allowlistConfirm every Required host above is allowed for the student's policy, especially app.activelearninglabs.com and cdn.jsdelivr.net.
  2. Check SSL inspectionMake sure the hosts under SSL inspection are excluded from decryption. A slide that loads once after a cache clear and then stops is the classic sign of a decrypting proxy or a poisoned cached response.
  3. Test on a non-managed deviceTry the same lesson on a non-managed device on the school network, then on a managed device off the network. This separates filter problems from Chrome policy problems.
  4. Send us a Network panel screenshotOn a device where DevTools is allowed, press F12, open the Network tab, reload the activity, type pdf in the filter box and screenshot the result. The status code tells us exactly where the request is being stopped.
  5. Check video separatelyIf only videos fail, open youtube.com directly on a student device. If it is blocked there, the lesson video will be blocked too.
  6. Lesson loads but live sync does notIf students can open lessons but do not receive teacher pacing or team updates, the WebSocket is being blocked. Check the WS filter in DevTools as described in the connectivity test, and confirm your SSL inspection product passes the WebSocket upgrade to ws.activelearninglabs.com.

Support: support@activelearninglabs.com. Include your district, the lab and activity name, the filtering product you use and the screenshot. We usually reply within one business day.

Privacy and security

Student data is stored in the United States on Amazon Web Services and Google Cloud. We collect only the data needed to run the classroom experience and never sell it or use it for advertising. Full details are in our Privacy Policy and our Data Security and Privacy Plan. A signed data privacy agreement for your district or state is available on request.

Change log

  • 2026-10-01Page published. Every host was verified against a recorded student session through a complete lab. Lesson content moved behind app.activelearninglabs.com and live class events moved to ws.activelearninglabs.com, so no Amazon hostnames are required.

We give at least 30 days notice on this page before adding a new required host.

Questions about this page: support@activelearninglabs.com. Permanent link: www.activelearninglabs.com/it-admins