Note: We highly recommend consulting an IT or network professional when configuring advanced network settings or devices.
The following options and port settings are typically available in your router/firewall's web interface (GUI) and are generally required to ensure quality 8x8 service. (Not every setting will be available in every router.) Consult your network administrator and or your manufacturer's documentation for more details on setting up your router for optimal Quality of Service (QoS). QoS refers to bandwidth allocation. See this article for more information on the benefits of QoS.
For your convenience, routers and firewalls pre-configured for optimal QoS are also available from 8x8. Contact your 8x8 Sales representative to ask about ordering.
See also: Virtual Office Technical Requirements
Disable All of the Following
- SIP Normalization
- SPI (or set to Pass Thru)
- SIP/VOIP ALG
Enable or Allow the Following
- https through the firewall
- Set default UDP Timeout to 300 seconds (if applicable)
Enable Traffic Through Security Service IPs
8x8 employs third-party security measures against cyber attacks, which requires traffic to be routed through that service's IP addresses. Please click here for the list of the latest ranges and ensure to allow outbound TCP connections to them from your network.
Note: These IP ranges are subject to irregular update without prior notification. Please review the link above for any changes in the event of a suspected network issue with your 8x8 services.
Traffic Shaping and Specific Subnet and Port Configuration
Unrestrict Traffic to and from 8x8 Subnets
In addition to unrestricting network traffic, it is strongly recommended that admins add the subnets below to any URL filtering whitelists. These subnets host various 8x8 resources that resolve within the 8x8 application and not a web browser. Some firewalls will occasionally detect this traffic as URL traffic. When this happens, the traffic could be marked as "unknown" and be blocked if not whitelisted.
Note: Some enterprise-class firewalls require inputting subnets in IP range format, shown in brackets.
- 188.8.131.52/23 [184.108.40.206 - 220.127.116.11]
- 18.104.22.168/22 [22.214.171.124 - 126.96.36.199]
- 188.8.131.52/24 [184.108.40.206 - 220.127.116.11]
- 18.104.22.168/23 [22.214.171.124 - 126.96.36.199]
- 188.8.131.52/23 [184.108.40.206 - 220.127.116.11]
- 18.104.22.168/22 [22.214.171.124 - 126.96.36.199]
- 188.8.131.52/24 [184.108.40.206 - 220.127.116.11]
- 18.104.22.168/24 [22.214.171.124 - 126.96.36.199] UK
- 188.8.131.52/24 [184.108.40.206 - 220.127.116.11] Australia
- 18.104.22.168/24 [22.214.171.124 - 126.96.36.199] Hong Kong
- 188.8.131.52/28 [184.108.40.206 - 220.127.116.11] Brazil
- 18.104.22.168/28 [22.214.171.124 - 126.96.36.199] Amsterdam
- 188.8.131.52/28 [184.108.40.206 - 220.127.116.11] Singapore
- 18.104.22.168/28 [22.214.171.124 - 126.96.36.199] India
- 188.8.131.52/28 [184.108.40.206 - 220.127.116.11] Canada
- 18.104.22.168/22 [22.214.171.124 - 126.96.36.199] (Reserved for future use)
- 188.8.131.52/21 [184.108.40.206 - 220.127.116.11] (Reserved for future use)
Configure these Ports with High Priority
- UDP 30000-30040 (source port range for VOD aac)
- UDP 5196-5199 (SIP signaling)
- UDP 3478-3480 (STUN)
- UDP 2222-2269 (Polycom media)
- UDP 16384-16404 (Linksys media)
- TCP 80 (http for Virtual Office Pro)
- TCP 443 (https for Virtual Office Pro)
- TCP 3443 (Virtual Office Desktop)
- TCP 8443 (Exchange/Outlook integration and https for Virtual Office Pro)
- TCP 54545 (Content Sharing for Virtual Office Pro)
- TCP 16003, 15215, 37210 (Virtual Office Online)
Configure these Ports as Needed
- UDP 5299 (KIRK/Spectralink signaling)
- UDP 58000-58050 (KIRK/Spectralink base media)
- UDP 15044 (MGCP - Aastra / BPG / BPA / Tango)
- UDP 15062 (MSRP)
- TCP 5133 (Virtual Office Desktop)
- TCP/UDP 5060 (Virtual Office Mobile app over Wi-fi)
- TCP/UDP 5199 (Virtual Office Mobile iOS/Android app over Wi-fi)
- TCP 15000 (Switchboard)
- TCP 2099 (Switchboard base registry)
- TCP20080-23080 (Switchboard OUTBOUND)
If your firewall allows you to edit your UDP session timeout, set it to 30 seconds or more.