Cloud Endpoints, Ports, Protocols
This document describes:
|
■
|
Which public Internet services an AudioCodes phone or meeting room device communicates with. |
|
■
|
Which outbound connections must be permitted by the enterprise firewall to allow the device to provision successfully, remain managed, obtain certificates, and support AI meeting summaries. |
Rules of Thumb
|
■
|
Allowlist by FQDN, not IP Address. AudioCodes services are hosted in Azure. Because the underlying IP addresses can change without notice, firewall policies should be based on fully qualified domain names (FQDNs) rather than IP addresses. Any IP addresses referenced in this document are provided for illustration only and must not be used as permanent firewall rules. |
|
■
|
TLS interception prevents device provisioning. AudioCodes devices authenticate to both the Redirect Server and Device Manager using a factory-installed client certificate and mutual TLS. |
TLS/SSL inspection or interception of these connections can prevent successful authentication and provisioning. Ensure that the relevant AudioCodes service FQDNs are excluded from SSL/TLS inspection.
|
■
|
Microsoft Teams Devices Require Additional Microsoft Endpoints. For AudioCodes Teams-native phones and meeting-room devices, the endpoints specified in this document cover AudioCodes services only. |
The Microsoft Teams application running on the device also requires access to Microsoft-managed network endpoints for services such as:
|
✔
|
User sign-in and authentication |
|
✔
|
Real-time media traffic |
|
✔
|
Application and firmware updates |
Ensure that the Microsoft 365 and Teams endpoints documented by Microsoft are also permitted:
learn.microsoft.com/microsoft-365/enterprise/urls-and-ip-address-ranges