background image

Purpose

Src. IP

Src. ports

Protocol

Dest. IP

Dst. Ports

Assent RTCP

(traversed
media)

SIP endpoint
(or its
firewall)

>=1024

Could be translated by
the firewall to port where
the media egressed,
rather than an endpoint
port

UDP

Expressway-
E

36000-59999

Assent RTP

(traversed
media)

Expressway-
E

36000-59999

UDP

SIP endpoint
(or its
firewall)

>=1024

Expressway waits until it
receives media, then sends
media to that source port
(which could be the port where
the media egressed the firewall,
not an endpoint port)

TURN control Any

IP address

>=1024 (signaling port
from endpoint or the
firewall)

UDP
& TCP

Expressway-
E

3478 (Small/Medium)

3478-3483 (Large)

TURN media

Expressway-
E

24000-29999

UDP
& TCP

Any
IP address

>=1024

TURN media

Any
IP address

>=1024

Port of relevant
ICE candidate: host
IP port, server reflexive
port (outside firewall
port), or TURN server
port

UDP
& TCP

Expressway-
E

24000-29999

Table 9 SIP Calls Port Reference (continued)

† The request could be from any IP address, unknown to the TURN server. Assume for example, that endpoint A and
endpoint C (TURN clients) in the diagram can use the Expressway-E TURN server. The actual IP address from which
the TURN server receives the request could be the endpoint's firewall egress address (NATed).

‡ The media could go to any of the candidate addresses. For example, before ICE negotiation the TURN server does
not know which of endpoint B's candidate addresses will be the highest priority.

Note:

 The endpoints A, B, and C in the diagram only show media connections to avoid unnecessary lines. They would

use the same signaling connections as shown for the other endpoints / bridges.

17

Cisco Expressway IP Port Usage Configuration Guide

Summary of Contents for Expressway Series

Page 1: ...Cisco Expressway IP Port Usage Configuration Guide First Published April 2017 X8 9 2 Cisco Systems Inc www cisco com ...

Page 2: ...e Deployment Guide on the Expressway configuration guides page See the Cisco Expressway Cluster Creation and Maintenance Deployment Guide for your version on the Cisco Expressway Series configuration guides page For Basic Call Control Deployment See Cisco Expressway Registrar Deployment Guide on the Expressway configuration guides page For Mobile and Remote Access to Cisco Unified Communications M...

Page 3: ...ing Connections 12 Cluster Connections Before X8 8 12 Cluster Port Reference Before X8 8 12 Cluster Connections X8 8 Onwards 13 Cluster Port Reference X8 8 Onwards 13 Provisioning Registrations Authentication and Calls 14 SIP Calls 15 SIP Calls Port Reference 16 H 323 Calls 18 H 323 Calls Port Reference 20 TMS Connections 22 TMS Port Reference 22 LDAP Connections 24 LDAP Port Reference 24 Mobile a...

Page 4: ...Proxy for Cisco Meeting Server WebRTC Connections 38 Web Proxy for Cisco Meeting Server Port Reference 39 SIP Edge for Meeting Server Connections 40 SIP Edge for Cisco Meeting Server Port Reference 41 XMPP Federation 43 XMPP Federation Connections 43 XMPP Port Reference 44 Serviceability 45 Serviceability Expressway C 45 Serviceability Traversal Pair 46 Serviceability Ports Traversal Pair 46 Cisco...

Page 5: ...ocuments list the current default ports for the given version number Note In some cases throughout this document we list port ranges used by third party infrastructure These are default values and we cannot guarantee that these are correct for your environment We recommend you follow the supplier s documentation to configure those connections Protocol Purpose Current Range Details TCP Ephemeral po...

Page 6: ...77 UDP Multiplexed media on Large Expressway E systems 36000 36011 New range introduced with Large system option This range is always the first twelve ports of the RTP RTCP media range so it will be different if you configure a different media range On Expressway E Large OVAs or large scale appliances only Note In the connection maps and port references we do not show all the port options for the ...

Page 7: ...CP Expressway C 22 Administrator HTTP Admin PCs 1024 65535 TCP Expressway C 80 Administrator HTTPS Admin PCs 1024 65535 TCP Expressway C 443 Name resolution DNS Expressway C 1024 65535 UDP TCP Internal name server 53 Time synchronization NTP Expressway C 123 UDP Internal time server 123 Table 3 Basic Networking Ports for Expressway C 7 Cisco Expressway IP Port Usage Configuration Guide ...

Page 8: ...by default You don t need to open the HTTP port but you can allow HTTP for convenience and redirect to HTTPS Expressway will attempt DNS resolution over TCP if the response is too large 8 Cisco Expressway IP Port Usage Configuration Guide ...

Page 9: ...Basic Networking Traversal Pair 9 Cisco Expressway IP Port Usage Configuration Guide ...

Page 10: ...n over TCP if the response is too large Purpose Src IP Src ports Protocol Dest IP Dst Ports Administrator SSH Admin PCs 1024 65535 TCP Expressway E private IP 22 Administrator HTTP Admin PCs 1024 65535 TCP Expressway E private IP 80 Administrator HTTPS Admin PCs 1024 65535 TLS Expressway E private IP 443 Internal name resolution DNS Expressway E private IP 1024 65535 UDP TCP Internal name server 5...

Page 11: ...11 Cisco Expressway IP Port Usage Configuration Guide ...

Page 12: ... Other peers N A Key exchange between peers ISAKMP This peer 500 UDP Other peers 500 Cluster recovery This peer 30000 35999 UDP Other peers 4371 Cluster communication This peer 30000 35999 TCP Other peers 4369 4380 Bandwidth management Expressway C cluster only This peer 1719 UDP Other peers 1719 Table 6 Cluster Synchronization and Communications 12 Cisco Expressway IP Port Usage Configuration Gui...

Page 13: ...er peers 1719 Table 7 Expressway C Cluster Database Synchronization and Communications Purpose Src IP Src ports Protocol Dest IP Dst Ports SIP TCP Signaling This peer 25000 29999 TCP Other peers 5061 SIP TLS Signaling This peer 25000 29999 TLS Other peers 5061 RTP RTCP This peer 36000 59999 UDP Other peers 36000 59999 Bandwidth management This peer 1719 UDP Other peers 1719 Table 8 SIP Calls Route...

Page 14: ...tion and Calls SIP Calls 15 SIP Calls Port Reference 16 H 323 Calls 18 H 323 Calls Port Reference 20 TMS Connections 22 TMS Port Reference 22 LDAP Connections 24 LDAP Port Reference 24 14 Cisco Expressway IP Port Usage Configuration Guide ...

Page 15: ...SIP Calls 15 Cisco Expressway IP Port Usage Configuration Guide ...

Page 16: ...for internet facing connections SIP signaling SIP endpoint or its firewall 1024 TCP Expressway E 5060 SIP TCP disabled by default X8 9 2 and later SIP signaling SIP endpoint or its firewall 1024 TLS Expressway E 5061 SIP signaling SIP endpoint or its firewall 1024 MTLS Expressway E 5062 Assent RTP traversed media Expressway C 36000 59999 UDP Expressway E 2776 or 36000 Small Medium 36000 36010 even...

Page 17: ... Port of relevant ICE candidate host IP port server reflexive port outside firewall port or TURN server port UDP TCP Expressway E 24000 29999 Table 9 SIP Calls Port Reference continued The request could be from any IP address unknown to the TURN server Assume for example that endpoint A and endpoint C TURN clients in the diagram can use the Expressway E TURN server The actual IP address from which...

Page 18: ...able apply specifically to Cisco VCS deployments You can use this information to prepare an Expressway based H 323 deployment but remember that Expressway E does not accept H 323 registrations 18 Cisco Expressway IP Port Usage Configuration Guide ...

Page 19: ...19 Cisco Expressway IP Port Usage Configuration Guide ...

Page 20: ...60 18 calls H 245 Expressway C 15000 19999 TCP Expressway E private 2776 Assent calls H 245 Expressway C 15000 19999 TCP Expressway E private 2777 H 460 18 calls H 245 Any endpoint in the Internet 1024 TCP Expressway E public Expressway E public H 245 Expressway E public 15000 19999 TCP Any endpoint in the Internet 1024 endpoint H 245 signaling port H 245 External address of firewall protecting of...

Page 21: ... 59998 even ports UDP Any endpoint in the Internet 1024 endpoint media range RTCP non multiplexed Expressway E public 36001 59999 odd ports UDP Any endpoint in the Internet 1024 endpoint media range RTP non multiplexed Any endpoint in the Internet 1024 endpoint media range UDP Expressway E public 36000 59998 even ports RTCP non multiplexed Any endpoint in the Internet 1024 endpoint media range UDP...

Page 22: ...tems or managing systems on the LAN On Cisco TMS go to Administrative Tools Configuration Network Settings Advanced Network Settings You should use the TMS public address with the Expressway E and the default LAN address with the Expressway C 22 Cisco Expressway IP Port Usage Configuration Guide ...

Page 23: ... TCP Expressway E private IP 80 HTTPS Management of Expressway E Cisco TMS External IP 1024 65535 TCP Expressway E private 443 HTTPS Management of Expressway C Cisco TMS 1024 65535 TCP Expressway C 443 Feedback events HTTP Expressway E private 1024 65535 TCP Cisco TMS External IP 80 Feedback events HTTP Expressway C 1024 65535 TCP Cisco TMS 80 Feedback events HTTPS Expressway E private 1024 65535 ...

Page 24: ...ze administrator or user logins You would only need to allow the LDAP ports inbound from the Expressway E in the rare case where you want a user to log in from outside the network and you also do not allow credentials to be stored on the Expressway 24 Cisco Expressway IP Port Usage Configuration Guide ...

Page 25: ...m the Expressway E Expressway E private 1024 65535 TCP Directory Server 389 Encrypted authentication requests from the Expressway C Expressway C 1024 65535 TLS Directory Server 636 Encrypted authentication requests from the Expressway E Expressway E private 1024 65535 TLS Directory Server 636 Table 12 LDAP Port Reference 25 Cisco Expressway IP Port Usage Configuration Guide ...

Page 26: ...Mobile and Remote Access MRA Connections 26 Cisco Expressway IP Port Usage Configuration Guide ...

Page 27: ...ay E Private IP 2222 SIP signaling Expressway C 25000 29999 TLS Expressway E Private IP 7001 SIP media Expressway C 36000 59999 UDP Expressway E Private IP 2776 7 or 36000 11 XMPP IM and Presence Expressway C 30000 35999 TCP Expressway E Private IP 7400 Table 14 Connections Between Expressway C and Expressway E Purpose Src IP Src ports Protocol Dest IP Dst Ports SIP signaling TCP Expressway C 2500...

Page 28: ...and Presence Service Node 8443 File transfer IM and Presence Expressway C 30000 35999 TLS IM and Presence Service Node 7336 HTTPS to visual voicemail Expressway C 30000 35999 TLS Cisco Unity Connection 443 or 8443 MWI Message Waiting Indicator Expressway C 30000 35999 TCP Cisco Unity Connection 7080 MWI Message Waiting Indicator Expressway C 30000 35999 TLS Cisco Unity Connection 7443 Audio Video ...

Page 29: ...ices Jabber Guest Dual NIC Deployment 30 Jabber Guest Dual NIC Deployment Ports 31 Jabber Guest Single NIC Deployment 32 Jabber Guest Single NIC Deployment Ports 33 29 Cisco Expressway IP Port Usage Configuration Guide ...

Page 30: ...Jabber Guest Dual NIC Deployment 30 Cisco Expressway IP Port Usage Configuration Guide ...

Page 31: ...AT to private 9443 TLS Expressway EPrivate IP Outward NIC 9443 Jabber Guest Client Media TURN Any web browser 1024 65535 UDP Expressway E Public IP 3478 S M systems 3478 3483 L systems SIP TCP signaling Expressway E private IP 30000 35999 TCP Jabber Guest Server 5060 SIP TLS signaling Expressway E private IP 30000 35999 TLS Jabber Guest Server 5061 SIP TCP signaling Jabber Guest Server Eph TCP Exp...

Page 32: ...Jabber Guest Single NIC Deployment 32 Cisco Expressway IP Port Usage Configuration Guide ...

Page 33: ...2 SIP Signaling Expressway C 25000 25999 TLS Expressway E Public IP 7001 TURN media relays Expressway C 36000 59999 UDP Expressway E Public IP 24000 29999 TURN media relays Expressway E Public IP 24000 29999 UDP Expressway C 36000 59999 SIP TCP signaling Expressway C 30000 35999 TCP Jabber Guest Server 5060 SIP TLS signaling Expressway C 30000 35999 TLS Jabber Guest Server 5061 SIP TCP signaling J...

Page 34: ...Microsoft Interoperability Using Gateway Expressway On Premises Microsoft Clients Cisco Expressway IP Port Usage Configuration Guide 34 ...

Page 35: ...Off Premises Microsoft Clients Cisco Expressway IP Port Usage Configuration Guide 35 ...

Page 36: ... pool of media ports default 56000 57000 The service can use any port in the range for media connection on either TCP or UDP transport The drawing shows two IP addresses on the Expressway E because you may have one or two NICs enabled on the Expressway E The address you enter for the TURN server on the Microsoft interoperability configuration of the gateway Expressway is the one that should listen...

Page 37: ...URN server Gateway Expressway 56000 57000 UDP or TCP Expressway E TURN server UDP 3478 TCP 3478 3478 3483 on large systems UDP TURN media relays Expressway E TURN server 24000 29999 UDP Any reflexive or relay from MS client or Edge 50000 59999 Edge range or client media ports TCP TURN media relays Expressway E TURN server 24000 29999 TCP Any reflexive or relay from MS client or Edge 50000 59999 Ed...

Page 38: ...Cisco Meeting Server Web Proxy for Cisco Meeting Server WebRTC Connections 38 Cisco Expressway IP Port Usage Configuration Guide ...

Page 39: ... IP 24000 29999 UDP and TCP Expressway E public IP 24000 29999 Table 20 Web Proxy for Meeting Server You must change the administration port because WebRTC clients use 443 If the WebRTC browser tries to access port 80 the Expressway E redirects the connection to 443 Options for alternative management ports are shown on the web interface You can use the CLI to change it to a different port eg 7443 ...

Page 40: ...SIP Edge for Meeting Server Connections 40 Cisco Expressway IP Port Usage Configuration Guide ...

Page 41: ...CP traversed media Expressway C 36000 59999 UDP Expressway E 2777 or 36001 Small Medium 36001 36011 odd ports Large Assent RTP traversed media SIP endpoint or its firewall 1024 Could be the firewall port where the media egressed rather than an endpoint port UDP Expressway E 36000 59999 Assent RTCP traversed media SIP endpoint or its firewall 1024 Could be the firewall port where the media egressed...

Page 42: ...l Medium 3478 3483 Large TURN media Expressway E 24000 29999 UDP Any IP address 1024 TURN media Any 1024 Port of relevant ICE candidate host IP port server reflexive port outside firewall port or TURN server port UDP Expressway E 24000 29999 Table 21 SIP Edge for Meeting Server Port Reference continued 42 Cisco Expressway IP Port Usage Configuration Guide ...

Page 43: ...XMPP Federation XMPP Federation Connections 43 Cisco Expressway IP Port Usage Configuration Guide ...

Page 44: ...traversal Expressway C Ephemeral 30000 35999 TCP Expressway E 7400 Inbound XMPP connections from federated domain Any An XMPP server Ephemeral TCP or TLS Expressway E 5269 Outbound XMPP connections to federated domain Expressway E Ephemeral 30000 35999 TCP or TLS Any An XMPP server 5269 Table 22 XMPP Federation Port Reference 44 Cisco Expressway IP Port Usage Configuration Guide ...

Page 45: ...Serviceability Serviceability Expressway C 45 Cisco Expressway IP Port Usage Configuration Guide ...

Page 46: ... System metrics Expressway 25826 UDP Analytics server s 25826 Remote logging syslog Expressway 30000 35999 UDP Syslog server s 514 Remote logging syslog Expressway 30000 35999 TCP Syslog server s 514 Remote logging syslog Expressway 30000 35999 TLS Syslog server s 6514 Table 23 Serviceability Ports for Expressway E and Expressway C 46 Cisco Expressway IP Port Usage Configuration Guide ...

Page 47: ...R TRADE PRACTICE IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT SPECIAL CONSEQUENTIAL OR INCIDENTAL DAMAGES INCLUDING WITHOUT LIMITATION LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL EVEN IF CISCO OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES Any Internet Protocol IP addresses and phone numbers used in thi...

Reviews: