Firewall & Router Configuration
- Introduction
- Ports required for your SIP Trunk / VoIP Provider
- Ports required for remote 3CX Apps & SBC
- Ports required for 3CX Video Conference
- IP Address Whitelisting for 3CX Transcription Service (Cloud)
- Ports Required for Other Services
- Configure Split DNS / Hairpin NAT
- Disable SIP ALG
- Run the Firewall Checker
- ACL/Firewall
- Step by Step Instructions for Popular Firewalls
- See Also
Introduction
If you have 3CX installed on-premise you need to make changes to your firewall configuration to allow 3CX to communicate successfully with your SIP trunks and apps. This guide gives you a general overview of the ports that need to be opened/statically forwarded on your firewall.
If you have remote IP phones, you need to put an SBC or router phone in front of them. Alternatively we recommend the use of our apps which have an inbuilt tunnel. More information on SBC can be found here.
Ports required for your SIP Trunk / VoIP Provider
Open these ports to allow 3CX to communicate with the VoIP Provider/SIP Trunk and WebRTC:
- Port 5060 (inbound, UDP) and 5060-5061 (inbound, TCP) for SIP communications.
- Port 9000-10999 (inbound, UDP) for RTP (Audio) communications, i.e. the actual call. Each call requires 2 RTP ports, one to control the call and one for the call data, so the number of ports you need to open is double the number of simultaneous calls.
Ports required for remote 3CX Apps & SBC
To allow users to use their 3CX apps remotely, on Android, iOS or Windows, you need to ensure that these ports are open:
- Port 5090 (inbound, UDP and TCP) for the 3CX tunnel.
- Port 443 or 5001 (inbound, TCP) HTTPS for Presence and Provisioning, or the custom HTTPS port you specified.
- Port 443 (outbound, TCP) for Google Android Push.
- Port 443, 2197 and 5223 (outbound, TCP) for Apple iOS Push. More information here.
PUSH messages are sent by the 3CX System to Extensions using smartphones to wake up the devices for calls. This greatly enhances the usability of the smartphone apps.
Ports required for 3CX Video Conference
To create and participate in web-based meetings, the 3CX-hosted cloud service must be able to communicate with the 3CX PBX and vice versa. To do so, these ports need to be configured:
- Port 443 (inbound, TCP) must be allowed for participants to connect your 3CX System
- 3CX System: Port 443 (outbound, TCP) must be allowed to connect to 3CX’s cloud infrastructure
- Users: Port 443 (outbound, TCP) and 48000-65535 (outbound, UDP) must be allowed to exchange audio and video with other participants
IP Address Whitelisting for 3CX Transcription Service (Cloud)
Your firewall settings must allow incoming (TCP) transcription traffic from source wmr-in.3cx.net (IP Address 34.40.92.110) to port 443 (or whatever alternative port you may be using for HTTPS).
Ports Required for Other Services
3CX connects to various services provided in the cloud.
- SMTP Service: Cloud Service for SMTP Messages
mailproxy.3cx.com, 443 (outbound, TCP) - Activation Service: Activation of 3CX Products
activate.3cx.com, 443 (outbound, TCP, uninspected traffic) - Discovery Service: Discover your Public IP
discoverv4.3cx.com, 443 (outbound, TCP, uninspected traffic) - RPS Service: Provisioning of Remote IP Phones
rps.3cx.com, 443 (outbound, TCP) - Update Server: For 3CX updates and IP Phone firmware
downloads-global.3cx.com, 443 (outbound, TCP) - WebMeeting Service and Transcription
wmr.3cx.net, 443 (outbound & inbound, TCP) - Push Service (Android & iOS)
pbxservicespush.3cx.com, 443 (outbound, TCP, uninspected traffic)
Configure Split DNS / Hairpin NAT
You will need to configure the 3CX FQDN to work both internally on your local network and externally outside of your network (unless you do not want to give access to your phone system from outside the network). Read how to configure split DNS here.
Disable SIP ALG
Use a router/firewall without a SIP Helper or SIP ALG (Application Layer Gateway), or a device on which SIP ALG can be disabled.
Run the Firewall Checker
After configuring your firewall, run the 3CX Firewall Checker to verify its configuration!
ACL/Firewall
Each on-premise installation environment is different, therefore, it is your responsibility to define the appropriate ACL/firewall rules that will not allow the 3CX host to reach sensitive subnets/endpoints within your network. This must be handled on the networking layer in gateways and firewalls and in the forefront of 3CX, to prevent pivoting our infrastructure in the case of a compromise.
Step by Step Instructions for Popular Firewalls
Example configurations for popular firewalls:
- Configuring a Sonicwall Firewall for 3CX
- Configuring a Draytek 2820 Router for 3CX with QoS configuration
- Configuring AVM FritzBox as a Firewall with 3CX
- Configuring a CISCO router to allow connection to a VOIP provider
- Configuring FortiGate 40F for 3CX
- Configuring a WatchGuard XTM Firewall for 3CX
- Configuring a pfSense Firewall for 3CX
- Configuring MikroTik Firewall
- Installing a 3CX SBC
- 3CX Firewall Checker
See Also
- Learn more about Routers, NAT and VoIP.
- What ports to open if you have trouble with PUSH - PUSH Troubleshooting guide
Last Updated
This document was last updated on 3 July 2026
https://www.3cx.com/docs/manual/firewall-router-configuration/