Skip to main content

SIP Signaling

10 IP addresses · Port 5060/5061

RTP Media

9 entries · UDP 5000–65535

Callbacks

3 IP addresses · HTTPS 443

WebSocket Streaming

9 entries · TCP 443 to your wss://
Important: IP addresses are subject to change. Always verify the latest list with the Vobiz team before making firewall changes. Contact support@vobiz.ai to subscribe to IP change notifications.

SIP Signaling

Allow inbound and outbound SIP traffic from these IPs. Used for call setup, tear-down, and control messages between your SIP infrastructure and Vobiz. India
Firewall rule: Allow TCP/UDP on ports 5060 and 5061 for all SIP signaling IPs in both directions.

Which of these your trunk points at

If you are configuring a SIP trunk or bringing your own carrier, two subsets of the table above matter most: Whitelist the full table regardless — the remaining IPs carry signaling for other call paths on the platform.

RTP Media

Allow UDP traffic from these IPs for the audio media stream. RTP carries the actual voice packets during a live call. India
Firewall rule: Allow UDP port range 5000–65535 for all nine entries in both directions.
Whitelist the CIDR blocks, not individual hosts. The media fleet scales with load and new hosts are added inside 18.96.230.96/28, 18.96.230.112/28, 18.96.230.208/29, and 18.96.232.168/29. Pinning the individual addresses that answer today will drop media when the fleet grows.Media flows directly between your equipment and the media layer above — it does not pass through the signaling SBCs. A firewall that allows 5060/5061 but not this UDP range produces a call that connects with no audio.

Callbacks

Vobiz sends webhook callbacks from these IP addresses to your server. Allow inbound HTTPS traffic from these IPs so your application receives call status, hangup, and recording events. India
Firewall rule: Allow inbound TCP port 443 (HTTPS) from all three IPs to your callback server. Port 80 only if you use plain HTTP callbacks.

WebSocket Streaming

When you use the <Stream> element, Vobiz initiates the connection to you — your wss:// URL is the server, and our media fleet is the client. You do not need inbound SIP or RTP rules for a WebSocket-only integration. If your WebSocket endpoint is IP-restricted, it must accept inbound TCP 443 from the media fleet addresses below. India
These are the same addresses as the RTP Media table, but the RTP rule does not cover them. The RTP rule allows UDP 5000–65535; WebSocket streaming needs TCP 443. If you use both SIP media and <Stream>, you need both rules — allowing one does not imply the other.
Firewall rule: Allow inbound TCP port 443 from all nine entries to your WebSocket server. Whitelist the CIDR blocks rather than the individual hosts — the media fleet scales with load.

Protocol Whitelisting

In addition to IP addresses, ensure your firewall and ISP do not block the following protocols.

All IPs at a Glance

Bringing your own carrier?

Bring Your Own Carrier (BYOC)

What to send Vobiz to onboard your existing carrier, SBC, or PBX — and how these IPs fit into the provisioning process.