> For the complete documentation index, see [llms.txt](https://help.sipgate.de/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.sipgate.de/cloud-telefonanlage/en/getting-started/alles-fur-den-start-mit-sipgate/nutzung-von-sipgate-mit-einer-firewall.md).

# Using sipgate with a firewall

### Signaling & audio transmission (SIP & RTP) <a href="#signalisierung-and-audioubertragung-sip-and-rtp" id="signalisierung-and-audioubertragung-sip-and-rtp"></a>

These endpoints are used for SIP signaling and RTP voice transmission. Which rows are relevant depends on which sipgate product you use.

| Function                          | DNS hostname             | IPv4                                                     | IPv6                                                   | Port          | Protocol |
| --------------------------------- | ------------------------ | -------------------------------------------------------- | ------------------------------------------------------ | ------------- | -------- |
| SIP signaling                     | sipgate.de               | 217.10.79.9                                              | 2001:ab7::1, 2001:ab7::2, 2001:ab7::3, 2001:ab7::4     | 5060          | UDP      |
| SIP signaling                     | sip.sipgate.de           | 212.9.44.242, 212.9.44.244, 217.10.77.242, 217.10.77.244 | 2001:ab7::17, 2001:ab7::18, 2001:ab7::19, 2001:ab7::1a | 5060          | TCP      |
| SIP signaling (TLS)               | sip.sipgate.de           | 212.9.44.242, 212.9.44.244, 217.10.77.242, 217.10.77.244 | 2001:ab7::17, 2001:ab7::18, 2001:ab7::19, 2001:ab7::1a | 5061          | TCP      |
| SIP signaling WebSocket (TLS)     | sip.sipgate.de           | 212.9.44.242, 212.9.44.244, 217.10.77.242, 217.10.77.244 | 2001:ab7::17, 2001:ab7::18, 2001:ab7::19, 2001:ab7::1a | 443           | TCP      |
| SIP signaling sipgate trunking    | sipconnect.sipgate.de    | 217.10.68.150                                            | 2001:ab7::9, 2001:ab7::10, 2001:ab7::11, 2001:ab7::12  | 5060          | UDP      |
| Voice data (RTP, SRTP)            | –                        | 212.9.44.0/24, 217.10.77.0/24                            | 2001:ab7:2000:3::0/64, 2001:ab7:3000:2::0/64           | 15000 - 30000 | UDP      |
| SIP signaling UK                  | sipgate.co.uk            | 217.10.79.23                                             | 2001:ab7::5, 2001:ab7::6, 2001:ab7::7, 2001:ab7::8     | 5060          | UDP      |
| SIP signaling UK                  | sip.sipgate.co.uk        | 212.9.44.243, 212.9.44.245, 217.10.77.243, 217.10.77.245 | 2001:ab7::1b, 2001:ab7::1c, 2001:ab7::21, 2001:ab7::22 | 5060          | TCP      |
| SIP signaling UK (TLS)            | sip.sipgate.co.uk        | 212.9.44.243, 212.9.44.245, 217.10.77.243, 217.10.77.245 | 2001:ab7::1b, 2001:ab7::1c, 2001:ab7::21, 2001:ab7::22 | 5061          | TCP      |
| SIP signaling WebSocket UK (TLS)  | sip.sipgate.co.uk        | 212.9.44.243, 212.9.44.245, 217.10.77.243, 217.10.77.245 | 2001:ab7::1b, 2001:ab7::1c, 2001:ab7::21, 2001:ab7::22 | 443           | TCP      |
| SIP signaling sipgate trunking UK | sipconnect.sipgate.co.uk | 217.10.68.151                                            | 2001:ab7::13, 2001:ab7::14, 2001:ab7::15, 2001:ab7::16 | 5060          | UDP      |

{% hint style="warning" %}
Note: IP addresses and port ranges may change due to extensions to the sipgate platform. We recommend using the DNS hostnames whenever possible. Otherwise, the IP addresses should be checked regularly against this documentation.
{% endhint %}

### sipgate apps <a href="#sipgate-apps" id="sipgate-apps"></a>

To use all functions of the sipgate apps, additional services are integrated. **In addition** to the permissions from "[Signaling & audio transmission (SIP & RTP)](#signalisierung-and-audioubertragung-sip-and-rtp)" further firewall permissions are therefore required, for example for real-time events, contacts and app updates.

#### sipgate app <a href="#sipgate-app" id="sipgate-app"></a>

Depending on the account, the sipgate app runs on one of two platforms: the modern neo platform (NeoPBX) or the older classic platform. Both use different backend infrastructures, which is why the required permissions differ. You can see which platform your account uses after logging in, at the top right in the account.

**neo platform (NeoPBX)**

| Function             | DNS hostname/IP               | Port | Protocol |
| -------------------- | ----------------------------- | ---- | -------- |
| Authentication       | workspace.sipgate.com         | 443  | TCP      |
| Authentication       | login.sipgate.com             | 443  | TCP      |
| Connection control   | socket.clinq.com              | 443  | TCP      |
| Contacts, CRM        | integration.sipgate.com       | 443  | TCP      |
| Event list, settings | 35.208.0.0 - 35.247.255.255   | 443  | TCP      |
| App updates          | s3-eu-central-1.amazonaws.com | 443  | TCP      |

**classic platform**

| Function            | DNS hostname      | IPv4                                                                                                                                                                                                         | Port          | Protocol |
| ------------------- | ----------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------- | -------- |
| SIP signaling (TLS) | –                 | 3.64.29.229, 3.74.37.174, 3.75.1.227, 3.77.130.221, 3.125.165.239, 18.153.199.104, 18.192.192.27, 18.193.158.169, 18.195.254.166, 18.196.255.246, 18.197.212.58, 18.199.119.88, 35.157.146.136, 52.29.34.109 | 443           | TCP      |
| Voice data (SRTP)   | –                 | 3.64.29.229, 3.74.37.174, 3.75.1.227, 3.77.130.221, 3.125.165.239, 18.153.199.104, 18.192.192.27, 18.193.158.169, 18.195.254.166, 18.196.255.246, 18.197.212.58, 18.199.119.88, 35.157.146.136, 52.29.34.109 | 15000 - 20000 | UDP      |
| Call setup          | gateway.clinq.com |                                                                                                                                                                                                              | 443           | TCP      |
| Codec negotiation   | api.q.clinq.com   |                                                                                                                                                                                                              | 443           | TCP      |
| Connection control  | socket.clinq.com  |                                                                                                                                                                                                              | 443           | TCP      |
| Event list          | ws-eu.pusher.com  |                                                                                                                                                                                                              | 443           | TCP      |
| Events, settings    | –                 | 35.208.0.0 - 35.247.255.255                                                                                                                                                                                  | 443           | TCP      |

### satellite app

| Function                                  | DNS hostname                                                    | Port        | Protocol |
| ----------------------------------------- | --------------------------------------------------------------- | ----------- | -------- |
| Authentication                            | login.sipgate.com                                               | 443         | TCP      |
| Authentication                            | api.sipgate.com                                                 | 443         | TCP      |
| Authentication, feedback                  | gateway.clinq.com                                               | 443         | TCP      |
| Contacts, CRM                             | integration.sipgate.cloud                                       | 443         | TCP      |
| satellite backend                         | api.satellite.me                                                | 443         | TCP      |
| How-to videos                             | embed-ssl.wistia.com                                            | 443         | TCP      |
| Observability                             | eum-blue-saas.instana.io                                        | 443         | TCP      |
| Observability                             | crashlytics.com                                                 | 443         | TCP      |
| Account, feature toggles, porting, survey | satellite-29f5c.firebaseio.com                                  | 443         | TCP      |
| Call information                          | satellite-calls-29f5c.europe-west1.firebasedatabase.app         | 443         | TCP      |
| Channel data, presence                    | satellite-channels-29f5c.europe-west1.firebasedatabase.app      | 443         | TCP      |
| Organization data                         | satellite-organisations-29f5c.europe-west1.firebasedatabase.app | 443         | TCP      |
| Tracking                                  | amp.sipgate.de                                                  | 443         | TCP      |
| Tracking                                  | api.mixpanel.com                                                | 443         | TCP      |
| Google SDK                                | \*.googleapis.com                                               | 443         | TCP      |
| Google SDK                                | \*.google.com                                                   | 443         | TCP      |
| Google push socket                        | \*.mtalk.google.com                                             | 5228 - 5230 | TCP      |

### sipgate fax printer

| Function             | DNS hostname                                  | Port | Protocol |
| -------------------- | --------------------------------------------- | ---- | -------- |
| Contacts, PDF upload | api.sipgate.com                               | 443  | TCP      |
| Authentication       | [login.sipgate.com](http://login.sipgate.com) | 443  | TCP      |

### sipgate webphone

| Function | DNS hostname    | Port | Protocol |
| -------- | --------------- | ---- | -------- |
| Contacts | api.sipgate.com | 443  | TCP      |

## Basic requirements for trouble-free telephony

Your internet connection should meet the following basic requirements:

| Criterion            | Requirement                                                    |
| -------------------- | -------------------------------------------------------------- |
| Bandwidth            | approx. 100 kbit/s per simultaneous call (upload and download) |
| Latency (round-trip) | under 250 ms                                                   |

## General recommendations

* Firewall rules usually only need to be set up for outgoing traffic (outbound).
* When using SIP via UDP, after registration we send keepalive packets every few seconds. If these packets do not arrive and the end device itself does not send any keepalive packets, the end device may be unreachable from the outside. Switching to TCP can help here.
* Static port forwarding to specific end devices is usually not necessary and poses a security risk.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.sipgate.de/cloud-telefonanlage/en/getting-started/alles-fur-den-start-mit-sipgate/nutzung-von-sipgate-mit-einer-firewall.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
