Ports used by Wildix services
Make sure that these ports are open on your router / firewall in order to be able to access and use different Wildix services.
It is recommended to open incoming custom secure port or default 443 from outside on PBX.
Created: June 2018
Updated: May 2026
Permalink: https://wildix.atlassian.net/wiki/x/NhXOAQ
Introduction
Inbound to PBX – traffic entering customer PBX from the Internet/clients/providers.
Outbound from PBX – traffic initiated by PBX to Wildix Cloud/3rd parties.
Outbound from Clients – traffic from user browsers/desktop apps/mobile apps.
Outbound from Phones – traffic from Wildix IP phones to Cloud services.
Firewall and Port Rules by Component
Core PBX (Cloud PBX and HW/VM PBX)
Direction | Protocol / Ports | Destination / Source (FQDN/IP) | Purpose / Notes |
Inbound to PBX | TCP 80, 443 (or custom secure) | PBX public IP/FQDN | Management UI, HTTPS services, PBX APIs. |
Inbound to PBX |
| PBX public IP/FQDN | Registrations, trunks. |
Inbound to PBX |
| PBX public IP/FQDN | Such services as SMSD, GNATS, Zabbix, Syslog, NTP. |
Inbound to PBX – RTP (Cloud PBX) | UDP 10000–59999 | Cloud PBX public IP/FQDN | Cloud PBX media |
Inbound to PBX – RTP (HW/VM PBX) | UDP 10000–15000 (typical) | PBX public IP/FQDN | Note: The range depends on the number and type of licenses (subscription plans) on the PBX; check SIP-RTP page for details |
Outbound from PBX | TCP 443 |
WIM (Wildix Integrations Middleware service):
CDS:
Starting from WMS 6.05, in case of Hardware or Virtual PBX, for devices upgrade:
| System activation, updates, device firmware, certificates, text-to-speech, speech-to-text services, CDS, firewall checker, etc. |
Outbound from PBX |
|
| CDS |
Inbound to PBX | TCP 443 (or custom secure) | Authentication & Licensing:
Video Conference (regional):
| Cloud Services make requests to PBX to get data for authentication, CDS, storage, video conference, CLASSOUND etc. |
Inbound to PBX (Server PBX) | UDP 1194; UDP RTP range (per SIP‑RTP) | Server PBX public IP/FQDN | Access to WMS network nodes between PBXs. |
Inbound to PBX | TCP 443 or 5061 (or custom) |
| Allow these sources to reach PBX for CLASSOUND trunks. |
Inbound to PBX | 443 or another custom secure port (from any remote address) | Europe (Frankfurt) Subnet (256 IPs):
US East (N. Virginia) Video Bridge IPs:
TURN IPs:
Conference IPs:
Asia Pacific (Singapore) Video Bridge IPs:
TURN IPs:
South America (São Paulo) Video Bridge IPs:
TURN IPs:
Middle East (UAE) Video Bridge IPs:
TURN IPs:
Note: TCP 443 and UDP 10000 need to be open on the Client's side only, as well as any port within 40000 - 65535 UDP/ TCP range | Videoconference |
Outbound from PBX | TCP/UDP 443 | turn.wildix.com | To find a PBX public IP address for WMS Network correct functioning. |
Outbound from PBX | UDP 5060 (or custom) TCP 443/5061 |
CLASSOUND RTP to trunk IPs | SIP Trunks registration Registration and secure signaling for CLASSOUND; RTP as per SIP‑RTP. |
Outbound from PBX | TCP 443 |
| Caller name lookup and SMS services for CLASSOUND. Available starting from WMS 6.02.20230201.1 or higher and only for the USA and Canada. |
Outbound from Clients | TCP 443 |
| Screen sharing for Wizyconf videoconference |
Outbound from PBX | TCP 103 | msoffice.wildix.com | teams4Wildix integration |
Outbound from PBX | Adroid: TCP ports 5228, 5229, 5230, 443 iOS: TCP ports 5223, 2195, 2196, 443 | notifications.wildix.com | Mobile push notifications PBX must be connected to the internet and be able to communicate with notifications.wildix.com server iOS: a direct, unproxied connection to the Apple Push Notification servers from smartphone. Android: a direct, unproxied connection to the Google Cloud Messaging. |
Outbound from PBX | TCP 443 | vpn4.wildix.com | Remote support |
Outbound from PBX | TCP 20514 | WMS 6.xx PBXs:
WMS 7.xx PBXs:
| Rsyslog |
Inbound to PBX | TCP 8099 | 63.32.222.64 | Zabbix monitoring |
Note: Outgoing traffic towards Cloud PBX to the Internet is not limited: any port from 1-65536 range.
WIService
(Wildix Integration Service, used by CDR-View, Screen Sharing, Headset Integration, Fax printer, Click2call from Windows, Popup App and other Wildix applications):
Make sure that FQDN “wildixintegration.eu” is correctly resolved with the IP: 127.0.0.1 by your DNS (on the user PC or on the router side)
Remote Wildix IP Phones
Direction | Protocol / Ports | Destination / Source | Purpose / Notes |
|---|---|---|---|
Inbound to PBX |
|
| Remote provisioning, registration, paging, media. |
Outbound from Phones | TCP 443 |
| Upgrade of firmware/ applications |
RNA Apps (x-bees / Collaboration 7 / x-hoppers)
Direction | Protocol / Ports | Destination / Source (FQDN or IP set) | Purpose / Notes |
|---|---|---|---|
Outbound from PBX/Clients | TCP 443 |
| Chat + media files |
Outbound from PBX | TCP 443 |
| Cloud Analytics |
Outbound from PBX/Clients |
|
| Videoconference, transcription |
Inbound to PBX | TCP 443 |
| x‑bees only |
Outbound from PBX/Clients | TCP 443 |
| x‑bees only |
Inbound to PBX | TCP 443 |
| x‑hoppers only |
Outbound from PBX/Clients | TCP 443 | app.wildix.com | Collaboration 7 only |
Remote Collaboration Apps
Direction | Protocol / Ports | Destination / Source (FQDN or IP set) | Purpose / Notes |
|---|---|---|---|
Outbound from PBX/Clients – Cloud‑stored group chats | TCP 443 |
| Cloud‑stored group chats in Collaboration apps |
Outbound from PBX/Clients – File / image sharing (both PBX and Client) |