Device Traffic Required from the Device VLAN

Endpoint

Port

Protocol

Direction

Purpose

Service Device URL

Tenant-specific URL returned by the Redirect Server

443

HTTPS / TLS

Outbound

Maintains device connectivity, keep-alive messages, and status reporting to AudioCodes Live Platform Device Manager through the Web Application Firewall (WAF). The URL is in the following format:

https://<live-platform-host>/ltcfordevice/c/<ServiceID>/

Where:

<live-platform-host> is the tenant's regional Live Platform host. The regional FQDNs are listed below.
Device Manager is hosted on Live Platform and is reached through the same regional host used for administrative access.

Imperva Cloud WAF

IP ranges only required for IP-based firewall rules

443

HTTPS

Outbound

terminates at WAF

The Imperva Cloud WAF is not a separate destination. The WAF fronts all Live Platform web and REST interfaces, including Device Manager. Allowlisting the FQDNs above is therefore sufficient for environments that support FQDN-based firewall rules.

Only firewalls that filter traffic by destination IP address rather than FQDN require Imperva's published IP ranges to be maintained. Because these ranges may change, they should be retrieved periodically from Imperva's published documentation. For details see

Allowlisting Imperva IP addresses and Setting IP restriction rules [c85245b7]

*.blob.core.windows.net

443

HTTPS

Outbound

Firmware, software, and configuration file downloads from Azure Storage. AudioCodes does not rely on a single Azure Storage account, so firewall policies should allow access to the required Azure Storage endpoints in accordance with Microsoft's Azure Storage networking guidance.