Headset Security and Network Requirements

For IT: how headsets are locked down, the network access they need, options for isolating VR traffic, and MAC addresses.

For: IT staff

Transfr headsets are locked to Transfr content and need only a small amount of network access to work. This article explains the security layers Transfr puts in place, what your network needs to allow, and the options your IT team has for isolating VR traffic.

Security here is deliberately layered: if one layer is bypassed, the others still hold. Each section below covers one of those layers.

If headsets join your Wi-Fi but sims will not load, a blocked endpoint is a common cause. Start with the connectivity test.

How Transfr locks down the headset

Every headset Transfr provides is configured with ManageXR, a mobile device management (MDM) platform. This is the first line of defense, and it lets Transfr manage headset configuration remotely.

Through ManageXR, Transfr sets up the Transfr home screen — a kiosk mode that limits the headset to Transfr applications only. Learners are blocked from:

  • Internet browsers
  • Games and game demos
  • Media and streaming platforms
  • Chat features
  • Any other app that shipped with the headset from the manufacturer

Transfr also uses ManageXR to hold the headset operating system on a tested, known-good version rather than letting firmware update automatically. When a manufacturer releases new software or firmware, Transfr and ManageXR test it before it reaches your headsets, so an update can’t quietly break the locked-down environment.

What network access headsets need (ports and URLs)

Headsets need Wi-Fi to authenticate learners and upload training data. Transfr uses very few ports and URLs to do this:

  • Ports: 80 and 443
  • URLs: a short list of Transfr and ManageXR addresses

Your network should be set up to allow those addresses and prohibit access to anything else. The full list is in its own article, linked below. It is the same for the Quest 2, Quest 3S, and Pico Neo 3. If you run an older legacy headset, check with Transfr Technical Support before you build the rule.

The full list of ports, URLs, and protocols lives in one place so it stays current: What ports and URLs does Transfr need allowlisted?. That page prints as a clean handout for a network team — Ctrl+P, or the print link at the top of it.

Options for isolating VR traffic on your network

How you separate VR traffic from the rest of your network is up to you. It depends on your setup and your budget. These are the options customers most often choose:

  • Network segmentation. If you’d rather headsets weren’t on a network shared with other resources, separate them using VLANs or subnetting. You can add time-based controls on top of that, so the VR network is only available during class periods.
  • A separate network. If you don’t want VR equipment on your network at all — or you have Wi-Fi coverage problems — a cellular hotspot is an option. Security features vary by hotspot provider, and some have limited controls, which can make it harder to apply other measures.
  • Firewalling. To limit what the headsets can reach, allowlist the Transfr and ManageXR endpoints and allow outbound communication only to those. This is the most common approach.

What casting needs on your network

Transfr uses a casting method built by ManageXR that shows what the learner sees in the headset, in a browser on a computer. Casting options vary by headset model.

Because the video travels across your Wi-Fi from the headset to the computer, casting usually needs a conversation with whoever administers your Wi-Fi — the security settings have to allow that traffic through rather than blocking it. What casting needs depends on which method you use, and the methods differ by headset model. On the Quest 2, wired casting over a USB cable does not travel over your network at all, so it works even where Wi-Fi is locked down. The Pico Neo 3 has no wired equivalent.

For setup steps, see Casting and Screen Sharing Guide.

MAC addresses

Every Transfr headset has a unique Media Access Control (MAC) address, and Transfr can provide them on request. If your network team prefers to grant access by device rather than by rule, MAC addresses are how they allow Transfr headsets onto the network.

Bandwidth, ports, and the full endpoint list are in What ports and URLs does Transfr need allowlisted?.

How learner usernames and passwords work

Each learner needs their own username and password to open Transfr applications on the headset. Those credentials are created by your organization’s Transfr administrator in the Transfr Dashboard, which is a separate web-based tool.

Learners cannot view or change passwords from inside the headset. Account management happens only in the Dashboard.

Wi-Fi passwords are not visible in the headset

The headset has a Wi-Fi settings section, but it shows the connected network by name only. Neither the learner nor Transfr can see or retrieve the network password from the headset.

If your team needs a formal spec sheet

The endpoints above are the list Transfr maintains for the Quest 2, Quest 3S, and Pico Neo 3. If your IT or security team needs it as a document — for a security review, a change request, or a procurement questionnaire — open What ports and URLs does Transfr need allowlisted? and print it — Ctrl+P, or Save as PDF from your browser’s print dialog. If you need it on letterhead or with anything else attached, contact Transfr Technical Support and name your headset model.

Still need help?

Contact our support team — Monday–Friday, 8am–8pm ET, 646-466-2600, technicalsupport@transfrvr.com.

Last updated: August 6, 2026

Search icon

Looking for something else?

Email icon

Still need help?

Contact support