> For the complete documentation index, see [llms.txt](https://help.sipgate.de/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.sipgate.de/cloud-telefonanlage/erste-schritte/alles-fur-den-start-mit-sipgate/nutzung-von-sipgate-mit-einer-firewall.md).

# Nutzung von sipgate mit einer Firewall

### Signalisierung & Audioübertragung (SIP & RTP) <a href="#signalisierung-and-audioubertragung-sip-and-rtp" id="signalisierung-and-audioubertragung-sip-and-rtp"></a>

Diese Endpunkte werden für die SIP-Signalisierung und RTP-Sprachübertragung verwendet. Welche Zeilen relevant sind, hängt davon ab, welches sipgate-Produkt Sie nutzen.​

| Funktion                               | DNS-Hostname             | IPv4                                                     | IPv6                                                   | Port          | Protokoll |
| -------------------------------------- | ------------------------ | -------------------------------------------------------- | ------------------------------------------------------ | ------------- | --------- |
| SIP Signalisierung                     | sipgate.de               | 217.10.79.9                                              | 2001:ab7::1, 2001:ab7::2, 2001:ab7::3, 2001:ab7::4     | 5060          | UDP       |
| SIP Signalisierung                     | sip.sipgate.de           | 212.9.44.242, 212.9.44.244, 217.10.77.242, 217.10.77.244 | 2001:ab7::17, 2001:ab7::18, 2001:ab7::19, 2001:ab7::1a | 5060          | TCP       |
| SIP Signalisierung (TLS)               | sip.sipgate.de           | 212.9.44.242, 212.9.44.244, 217.10.77.242, 217.10.77.244 | 2001:ab7::17, 2001:ab7::18, 2001:ab7::19, 2001:ab7::1a | 5061          | TCP       |
| SIP Signalisierung Websocket (TLS)     | sip.sipgate.de           | 212.9.44.242, 212.9.44.244, 217.10.77.242, 217.10.77.244 | 2001:ab7::17, 2001:ab7::18, 2001:ab7::19, 2001:ab7::1a | 443           | TCP       |
| SIP Signalisierung sipgate trunking    | sipconnect.sipgate.de    | 217.10.68.150                                            | 2001:ab7::9, 2001:ab7::10, 2001:ab7::11, 2001:ab7::12  | 5060          | UDP       |
| Sprachdaten (RTP, SRTP)                | –                        | 212.9.44.0/24, 217.10.77.0/24                            | 2001:ab7:2000:3::0/64, 2001:ab7:3000:2::0/64           | 15000 - 30000 | UDP       |
| SIP Signalisierung UK                  | sipgate.co.uk            | 217.10.79.23                                             | 2001:ab7::5, 2001:ab7::6, 2001:ab7::7, 2001:ab7::8     | 5060          | UDP       |
| SIP Signalisierung UK                  | sip.sipgate.co.uk        | 212.9.44.243, 212.9.44.245, 217.10.77.243, 217.10.77.245 | 2001:ab7::1b, 2001:ab7::1c, 2001:ab7::21, 2001:ab7::22 | 5060          | TCP       |
| SIP Signalisierung UK (TLS)            | sip.sipgate.co.uk        | 212.9.44.243, 212.9.44.245, 217.10.77.243, 217.10.77.245 | 2001:ab7::1b, 2001:ab7::1c, 2001:ab7::21, 2001:ab7::22 | 5061          | TCP       |
| SIP Signalisierung Websocket UK (TLS)  | sip.sipgate.co.uk        | 212.9.44.243, 212.9.44.245, 217.10.77.243, 217.10.77.245 | 2001:ab7::1b, 2001:ab7::1c, 2001:ab7::21, 2001:ab7::22 | 443           | TCP       |
| SIP Signalisierung sipgate trunking UK | sipconnect.sipgate.co.uk | 217.10.68.151                                            | 2001:ab7::13, 2001:ab7::14, 2001:ab7::15, 2001:ab7::16 | 5060          | UDP       |

{% hint style="warning" %}
Hinweis: IP-Adressen und Port-Ranges können sich durch Erweiterungen an der sipgate-Plattform ändern. Wir empfehlen nach Möglichkeit die Verwendung der DNS-Hostnamen. Andernfalls sollten die IP-Adressen regelmäßig gegen diese Dokumentation geprüft werden.
{% endhint %}

### sipgate Apps <a href="#sipgate-apps" id="sipgate-apps"></a>

Um alle Funktionen der sipgate Apps zu nutzen, werden weitere Dienste eingebunden. **Zusätzlich** zu den Freigaben aus "[Signalisierung & Audioübertragung (SIP & RTP)](#signalisierung-and-audioubertragung-sip-and-rtp)" sind daher weitere Firewall-Freigaben erforderlich, zum Beispiel für Echtzeit-Events, Kontakte und App-Updates.

#### sipgate App <a href="#sipgate-app" id="sipgate-app"></a>

Die sipgate App läuft je nach Account auf einer von zwei Plattformen: der modernen neo-Plattform (NeoPBX) oder der älteren classic-Plattform. Beide nutzen unterschiedliche Backend-Infrastrukturen, weshalb die erforderlichen Freigaben voneinander abweichen. Welche Plattform Ihr Account nutzt, sehen Sie nach dem Login oben rechts im Account.

**neo-Plattform (NeoPBX)**

| Funktion                  | DNS-Hostname/IP               | Port | Protokoll |
| ------------------------- | ----------------------------- | ---- | --------- |
| Authentifizierung         | workspace.sipgate.com         | 443  | TCP       |
| Authentifizierung         | login.sipgate.com             | 443  | TCP       |
| Verbindungssteuerung      | socket.clinq.com              | 443  | TCP       |
| Kontakte, CRM             | integration.sipgate.com       | 443  | TCP       |
| Eventliste, Einstellungen | 35.208.0.0 - 35.247.255.255   | 443  | TCP       |
| App-Updates               | s3-eu-central-1.amazonaws.com | 443  | TCP       |

**classic-Plattform**

| Funktion                 | DNS-Hostname      | IPv4                                                                                                                                                                                                         | Port          | Protokoll |
| ------------------------ | ----------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------- | --------- |
| SIP Signalisierung (TLS) | –                 | 3.64.29.229, 3.74.37.174, 3.75.1.227, 3.77.130.221, 3.125.165.239, 18.153.199.104, 18.192.192.27, 18.193.158.169, 18.195.254.166, 18.196.255.246, 18.197.212.58, 18.199.119.88, 35.157.146.136, 52.29.34.109 | 443           | TCP       |
| Sprachdaten (SRTP)       | –                 | 3.64.29.229, 3.74.37.174, 3.75.1.227, 3.77.130.221, 3.125.165.239, 18.153.199.104, 18.192.192.27, 18.193.158.169, 18.195.254.166, 18.196.255.246, 18.197.212.58, 18.199.119.88, 35.157.146.136, 52.29.34.109 | 15000 - 20000 | UDP       |
| Anrufaufbau              | gateway.clinq.com |                                                                                                                                                                                                              | 443           | TCP       |
| Codec-Aushandlung        | api.q.clinq.com   |                                                                                                                                                                                                              | 443           | TCP       |
| Verbindungssteuerung     | socket.clinq.com  |                                                                                                                                                                                                              | 443           | TCP       |
| Eventliste               | ws-eu.pusher.com  |                                                                                                                                                                                                              | 443           | TCP       |
| Events, Einstellungen    | –                 | 35.208.0.0 - 35.247.255.255                                                                                                                                                                                  | 443           | TCP       |

### satellite App

| Funktion                                  | DNS-Hostname                                                    | Port        | Protokoll |
| ----------------------------------------- | --------------------------------------------------------------- | ----------- | --------- |
| Authentifizierung                         | login.sipgate.com                                               | 443         | TCP       |
| Authentifizierung                         | api.sipgate.com                                                 | 443         | TCP       |
| Authentifizierung, Feedback               | gateway.clinq.com                                               | 443         | TCP       |
| Kontakte, CRM                             | integration.sipgate.cloud                                       | 443         | TCP       |
| satellite Backend                         | api.satellite.me                                                | 443         | TCP       |
| How-to-Videos                             | embed-ssl.wistia.com                                            | 443         | TCP       |
| Observability                             | eum-blue-saas.instana.io                                        | 443         | TCP       |
| Observability                             | crashlytics.com                                                 | 443         | TCP       |
| Account, Feature-Toggles, Porting, Survey | satellite-29f5c.firebaseio.com                                  | 443         | TCP       |
| Anruf-Informationen                       | satellite-calls-29f5c.europe-west1.firebasedatabase.app         | 443         | TCP       |
| Channel-Daten, Presence                   | satellite-channels-29f5c.europe-west1.firebasedatabase.app      | 443         | TCP       |
| Organisationsdaten                        | satellite-organisations-29f5c.europe-west1.firebasedatabase.app | 443         | TCP       |
| Tracking                                  | amp.sipgate.de                                                  | 443         | TCP       |
| Tracking                                  | api.mixpanel.com                                                | 443         | TCP       |
| Google SDK                                | \*.googleapis.com                                               | 443         | TCP       |
| Google SDK                                | \*.google.com                                                   | 443         | TCP       |
| Google Push-Socket                        | \*.mtalk.google.com                                             | 5228 - 5230 | TCP       |

### sipgate Faxdrucker

| Funktion             | DNS-Hostname                                  | Port | Protokoll |
| -------------------- | --------------------------------------------- | ---- | --------- |
| Kontakte, PDF-Upload | api.sipgate.com                               | 443  | TCP       |
| Authentifizierung    | [login.sipgate.com](http://login.sipgate.com) | 443  | TCP       |

### sipgate Webphone

| Funktion | DNS-Hostname    | Port | Protokoll |
| -------- | --------------- | ---- | --------- |
| Kontakte | api.sipgate.com | 443  | TCP       |

## Grundsätzliche Voraussetzungen für störungsfreie Telefonie

Ihre Internetverbindung sollte folgende Grundvoraussetzungen erfüllen:

| Kriterium           | Anforderung                                                   |
| ------------------- | ------------------------------------------------------------- |
| Bandbreite          | ca. 100 kbit/s pro gleichzeitigem Gespräch (Up- und Download) |
| Latenz (Round-Trip) | unter 250 ms                                                  |

## Allgemeine Empfehlungen

* Firewall-Regeln müssen meist nur ausgehend (outbound) eingerichtet werden.
* Bei SIP via UDP versenden wir nach der Registrierung alle paar Sekunden Keepalive-Pakete. Falls diese Pakete nicht ankommen und das Endgerät selbst keine Keepalive-Pakete versendet, ist ein Endgerät unter Umständen eingehend nicht erreichbar. Ein Wechsel auf TCP kann hier helfen.
* Statisches Port-Forwarding auf bestimmte Endgeräte ist in der Regel nicht erforderlich und stellt ein Sicherheitsrisiko dar.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.sipgate.de/cloud-telefonanlage/erste-schritte/alles-fur-den-start-mit-sipgate/nutzung-von-sipgate-mit-einer-firewall.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
