Using sipgate with a firewall
Here you will find IP addresses, ports and configuration notes for smooth operation in your company network.
Signaling & audio transmission (SIP & RTP)
These endpoints are used for SIP signaling and RTP voice transmission. Which rows are relevant depends on which sipgate product you use.
SIP signaling
sipgate.de
217.10.79.9
2001:ab7::1, 2001:ab7::2, 2001:ab7::3, 2001:ab7::4
5060
UDP
SIP signaling
sip.sipgate.de
212.9.44.242, 212.9.44.244, 217.10.77.242, 217.10.77.244
2001:ab7::17, 2001:ab7::18, 2001:ab7::19, 2001:ab7::1a
5060
TCP
SIP signaling (TLS)
sip.sipgate.de
212.9.44.242, 212.9.44.244, 217.10.77.242, 217.10.77.244
2001:ab7::17, 2001:ab7::18, 2001:ab7::19, 2001:ab7::1a
5061
TCP
SIP signaling WebSocket (TLS)
sip.sipgate.de
212.9.44.242, 212.9.44.244, 217.10.77.242, 217.10.77.244
2001:ab7::17, 2001:ab7::18, 2001:ab7::19, 2001:ab7::1a
443
TCP
SIP signaling sipgate trunking
sipconnect.sipgate.de
217.10.68.150
2001:ab7::9, 2001:ab7::10, 2001:ab7::11, 2001:ab7::12
5060
UDP
Voice data (RTP, SRTP)
–
212.9.44.0/24, 217.10.77.0/24
2001:ab7:2000:3::0/64, 2001:ab7:3000:2::0/64
15000 - 30000
UDP
SIP signaling UK
sipgate.co.uk
217.10.79.23
2001:ab7::5, 2001:ab7::6, 2001:ab7::7, 2001:ab7::8
5060
UDP
SIP signaling UK
sip.sipgate.co.uk
212.9.44.243, 212.9.44.245, 217.10.77.243, 217.10.77.245
2001:ab7::1b, 2001:ab7::1c, 2001:ab7::21, 2001:ab7::22
5060
TCP
SIP signaling UK (TLS)
sip.sipgate.co.uk
212.9.44.243, 212.9.44.245, 217.10.77.243, 217.10.77.245
2001:ab7::1b, 2001:ab7::1c, 2001:ab7::21, 2001:ab7::22
5061
TCP
SIP signaling WebSocket UK (TLS)
sip.sipgate.co.uk
212.9.44.243, 212.9.44.245, 217.10.77.243, 217.10.77.245
2001:ab7::1b, 2001:ab7::1c, 2001:ab7::21, 2001:ab7::22
443
TCP
SIP signaling sipgate trunking UK
sipconnect.sipgate.co.uk
217.10.68.151
2001:ab7::13, 2001:ab7::14, 2001:ab7::15, 2001:ab7::16
5060
UDP
Note: IP addresses and port ranges may change due to extensions to the sipgate platform. Where possible, we recommend using the DNS hostnames. Otherwise, the IP addresses should be checked regularly against this documentation.
sipgate apps
Additional services are integrated to use all features of the sipgate apps. In addition to the permissions from "Signaling & audio transmission (SIP & RTP)", further firewall permissions are therefore required, for example for real-time events, contacts, and app updates.
sipgate app
Depending on the account, the sipgate app runs on one of two platforms: the modern neo platform (NeoPBX) or the older classic platform. Both use different backend infrastructures, which is why the required permissions differ. You can see which platform your account uses after logging in, at the top right in the account.
neo platform (NeoPBX)
Authentication
workspace.sipgate.com
443
TCP
Authentication
login.sipgate.com
443
TCP
Call control
socket.clinq.com
443
TCP
Contacts, CRM
integration.sipgate.com
443
TCP
Event list, settings
35.208.0.0 - 35.247.255.255
443
TCP
App updates
s3-eu-central-1.amazonaws.com
443
TCP
classic platform
SIP signaling (TLS)
–
3.64.29.229, 3.74.37.174, 3.75.1.227, 3.77.130.221, 3.125.165.239, 18.153.199.104, 18.192.192.27, 18.193.158.169, 18.195.254.166, 18.196.255.246, 18.197.212.58, 18.199.119.88, 35.157.146.136, 52.29.34.109
443
TCP
Voice data (SRTP)
–
3.64.29.229, 3.74.37.174, 3.75.1.227, 3.77.130.221, 3.125.165.239, 18.153.199.104, 18.192.192.27, 18.193.158.169, 18.195.254.166, 18.196.255.246, 18.197.212.58, 18.199.119.88, 35.157.146.136, 52.29.34.109
15000 - 20000
UDP
Call setup
gateway.clinq.com
443
TCP
Codec negotiation
api.q.clinq.com
443
TCP
Call control
socket.clinq.com
443
TCP
Event list
ws-eu.pusher.com
443
TCP
Events, settings
–
35.208.0.0 - 35.247.255.255
443
TCP
satellite app
Authentication
login.sipgate.com
443
TCP
Authentication
api.sipgate.com
443
TCP
Authentication, feedback
gateway.clinq.com
443
TCP
Contacts, CRM
integration.sipgate.cloud
443
TCP
satellite backend
api.satellite.me
443
TCP
How-to videos
embed-ssl.wistia.com
443
TCP
Observability
eum-blue-saas.instana.io
443
TCP
Observability
crashlytics.com
443
TCP
Account, feature toggles, porting, survey
satellite-29f5c.firebaseio.com
443
TCP
Call information
satellite-calls-29f5c.europe-west1.firebasedatabase.app
443
TCP
Channel data, presence
satellite-channels-29f5c.europe-west1.firebasedatabase.app
443
TCP
Organization data
satellite-organisations-29f5c.europe-west1.firebasedatabase.app
443
TCP
Tracking
amp.sipgate.de
443
TCP
Tracking
api.mixpanel.com
443
TCP
Google SDK
*.googleapis.com
443
TCP
Google SDK
*.google.com
443
TCP
Google push socket
*.mtalk.google.com
5228 - 5230
TCP
sipgate fax printer
Contacts, PDF upload
api.sipgate.com
443
TCP
sipgate Webphone
Contacts
api.sipgate.com
443
TCP
Basic requirements for trouble-free telephony
Your internet connection should meet the following basic requirements:
Bandwidth
approx. 100 kbit/s per simultaneous call (upload and download)
Latency (round-trip)
under 250 ms
General recommendations
Firewall rules usually only need to be configured for outbound traffic.
When using SIP via UDP, we send keepalive packets every few seconds after registration. If these packets do not arrive and the end device itself does not send keepalive packets, the end device may be unreachable from the outside. Switching to TCP can help here.
Static port forwarding to specific end devices is usually not necessary and poses a security risk.
Last updated

