# Setting up Genesys Cloud BYOC Cloud with a carrier or SBC

Systems: Genesys Cloud CX

For A Genesys Cloud telephony administrator working alongside a carrier or SBC engineer.

Canonical: https://warmtransfer.net/guides/genesys-cloud-byoc-setup

Last verified: 2026-09-30

Genesys Cloud offers BYOC as BYOC Premises and BYOC Cloud, named according to where the SIP connection terminates against Genesys Cloud[^66]. This guide covers configuring a third-party SIP trunk, mapping DID ranges, and validating routing with the call simulator[^45].

## Before you start

Creating trunks requires the `Telephony > Plugin > All` permission[^62]. Creating sites requires the Telephony Admin role with both `Telephony > Plugin > All` and `Directory > Organization > Admin` permissions[^51]. A BYOC Premises connection requires an on-site Genesys Cloud Edge appliance, whereas BYOC Cloud terminates carrier connections without a premises Edge[^42].

## What changes by situation

- Where does the SIP trunk terminate against Genesys Cloud? BYOC Cloud: internet connection terminating directly in Genesys Cloud without an on-premises Edge; BYOC Premises: connection terminating on a Genesys Cloud Edge appliance at your site.
- How will the trunk carry signaling and media? TLS signaling with SRTP media; UDP signaling.
- How does the carrier authenticate calls sent by Genesys Cloud? SIP digest authentication with credentials; Source IP address allowlisting only.

## Step 1: Verify carrier and SBC readiness

**BYOC Cloud: internet connection terminating directly in Genesys Cloud without an on-premises Edge**

### Do
Confirm that the carrier or SBC is SIP-compliant and fully supports RFC 3261 Record-Routing[^9]. Verify the carrier endpoint provides a publicly routable IP address or host name[^8] and supports UDP, TCP, or TLS transport[^10]. Genesys states that new customers and customers creating new BYOC Cloud SIP trunks should use the Dynamic Cloud Voice platform[^13]. Organizations in the Mexico or Singapore regions use the Dynamic Cloud Voice platform IP addresses[^33].

### Verify
Suggested check: obtain written confirmation affirming RFC 3261 compliance and transport support. Genesys recommends using the FQDN or TGRP method for inbound identification, with DNIS Replacement as an alternative when carrier requirements prevent both[^25].

**BYOC Premises: connection terminating on a Genesys Cloud Edge appliance at your site**

### Do
Confirm that a Genesys Cloud Edge appliance is deployed and reachable on your network[^42].

### Verify
Suggested check: verify that the Edge appears in the admin console and is available to be taken in and out of service.

## Step 2: Create the site

**BYOC Cloud: internet connection terminating directly in Genesys Cloud without an on-premises Edge**

### Do
Create or identify a location, which in BYOC Cloud is also used for emergency services[^28]. Navigate to **Telephony** > **Sites**, click **Create New**, provide a name, select the location and time zone, select **Cloud** under **Media Model**, and click **Create Site**[^50]. On the site's **General** tab, enter the outbound Caller Address in E.164 format[^52].

### Verify
Confirm the Edit Site page displays the General, Number Plans, Outbound Routes, and Simulate Call tabs[^52].

### Rollback
A site's media model cannot be changed after the site is created[^31]. Suggested rollback: delete the incorrectly configured site and recreate it.

**BYOC Premises: connection terminating on a Genesys Cloud Edge appliance at your site**

### Do
Navigate to **Telephony** > **Sites**, click **Create New**, configure the site details, and select **Premises** under **Media Model**[^32].

### Verify
Confirm the site is created with the Premises media model[^32].

### Rollback
A site's media model cannot be changed after the site is created[^31]. Suggested rollback: delete the site and recreate it if an incorrect model was selected.

## Step 3: Create the external trunk

**BYOC Cloud: internet connection terminating directly in Genesys Cloud without an on-premises Edge**

### Do
Navigate to **Menu** > **Digital and Telephony** > **Telephony** > **Trunks**, select the **External Trunks** tab, and click **Create New**[^62]. Set **Type** to **BYOC Carrier** (with subtype Generic, Verizon, or WhatsApp Business Calling) or **BYOC PBX** (subtype Generic BYOC PBX)[^65]. Set the **Trunk State** switch to **In-Service**[^63]. Under **Inbound**, set **Number Plan Site** to your newly created site[^34].

### Verify
Confirm that the trunk appears on the External Trunks tab with In-Service state[^62][^63].

### Rollback
Suggested rollback: toggle the trunk state switch out of service or delete the external trunk record.

**BYOC Premises: connection terminating on a Genesys Cloud Edge appliance at your site**

### Do
Navigate to **Menu** > **Digital and Telephony** > **Telephony** > **Trunks**, select the **External Trunks** tab, click **Create New**, and set **Type** to **Premises External SIP**[^41]. Configure the **Protocol** and set the **Listen Port**, a setting that applies only to Premises External SIP trunks[^27][^41]. Set **Trunk State** to **In-Service**[^63].

### Verify
Confirm that the trunk is saved with Trunk State set to In-Service[^63].

### Rollback
Suggested rollback: toggle the trunk state switch out of service or delete the trunk.

## Step 4: Configure trunk transport and media

**TLS signaling with SRTP media**

### Do
Set **Protocol** to **TLS** on the external trunk[^43]. The trunk TLS method defaults to TLS v1.2[^64]. BYOC Cloud TLS trunks use TLS 1.2 on port 5061 with SIPS for signaling and SRTP to protect media[^55]. Select the supported suites under the **SRTP Cipher Suite List**, which offers AES_CM_128_HMAC_SHA1_80, AES_CM_128_HMAC_SHA1_32, and 192-bit and 256-bit variants[^53]. For BYOC Cloud TLS, the customer endpoint's X.509 certificate must be signed by one of the public certificate authorities Genesys lists[^57]. Genesys BYOC Cloud TLS endpoints present certificates chaining to Amazon Trust Services Root CA 1 and 2 on the Dynamic Cloud Voice platform and to DigiCert roots on the legacy platform[^61]. BYOC Cloud supports only one-way (server-side) TLS, not mutual TLS[^60].

### Verify
Suggested check: verify the carrier establishes a successful TLS handshake and test media is encrypted.

### Rollback
Suggested rollback: change protocol settings back to unencrypted transport and disable secure media on both sides.

**UDP signaling**

### Do
Set **Protocol** to **UDP**, which is selected in most cases according to the external trunk settings reference[^43]. Choose codecs from G.722, G.729, PCMA, PCMU, and Opus[^29]. Retain the default DTMF setting of RTP Events with payload type 101 unless your carrier requires an alternate configuration[^29].

### Verify
Suggested check: verify that the chosen codec and DTMF payload type match the carrier or SBC trunk specification.

### Rollback
Suggested rollback: adjust the protocol or codec selections on the external trunk settings.

## Step 5: Configure outbound SIP endpoints

**BYOC Cloud: internet connection terminating directly in Genesys Cloud without an on-premises Edge + TLS signaling with SRTP media**

### Do
Under **Outbound** > **SIP Servers or Proxies**, configure carrier host names[^8]. WarmTransfer's reading of the sources is that host names should be entered rather than IP addresses[^59], because Genesys validates the carrier certificate's CN or SAN against SIP Servers or Proxies values by host name and does not accept IP addresses[^56]. Optionally configure Outbound SIP Termination FQDN, Outbound SIP TGRP Attribute, or Outbound SIP DNIS to populate the Request-URI domain, TGRP parameter, or DNIS[^38]. If using Bandwidth's Universal Platform, set Address Omit + Prefix to Disabled for E.164 traffic[^5].

### Verify
Suggested check: verify that outbound test SIP INVITEs reach the carrier target host with expected Request-URI domain, TGRP, and DNIS formatting.

### Rollback
Suggested rollback: edit or delete the entries listed under SIP Servers or Proxies.

**BYOC Cloud: internet connection terminating directly in Genesys Cloud without an on-premises Edge + UDP signaling**

### Do
Under **Outbound** > **SIP Servers or Proxies**, enter the carrier's host names or IP addresses and ports[^8]. Optionally configure Outbound SIP Termination FQDN, Outbound SIP TGRP Attribute, or Outbound SIP DNIS to adjust the Request-URI domain, TGRP parameter, or DNIS[^38]. If connecting to Bandwidth's Universal Platform, set Address Omit + Prefix to Disabled for E.164 traffic[^5].

### Verify
Suggested check: verify that outbound test SIP INVITEs target the configured carrier addresses.

### Rollback
Suggested rollback: edit or remove the entries under SIP Servers or Proxies.

**BYOC Premises: connection terminating on a Genesys Cloud Edge appliance at your site + TLS signaling with SRTP media**

### Do
Under **Outbound** > **SIP Servers or Proxies**, add the carrier or SBC endpoints and ports[^41].

### Verify
Suggested check: confirm the SIP server entries are listed in the required priority order.

### Rollback
Suggested rollback: modify or remove the configured server endpoints.

**BYOC Premises: connection terminating on a Genesys Cloud Edge appliance at your site + UDP signaling**

### Do
Under **Outbound** > **SIP Servers or Proxies**, enter the carrier or SBC IP addresses or host names and ports[^41].

### Verify
Suggested check: verify that the SIP server endpoints reflect the planned failover priority.

### Rollback
Suggested rollback: edit or delete the SIP server entries.

## Step 6: Configure outbound carrier authentication

**BYOC Cloud: internet connection terminating directly in Genesys Cloud without an on-premises Edge + Source IP address allowlisting only**

### Do
Leave Digest Authentication disabled[^40]. Provide the carrier with Genesys Cloud's public SIP signaling addresses for your region so the carrier can implement source IP allowlisting[^6].

### Verify
Suggested check: confirm with the carrier that public signaling addresses are allowlisted and that outbound calls pass without authentication challenges.

### Rollback
Suggested rollback: request that the carrier remove the allowlisted signaling IP addresses.

**BYOC Premises: connection terminating on a Genesys Cloud Edge appliance at your site + Source IP address allowlisting only**

### Do
Leave Digest Authentication disabled on the Premises trunk[^40].

### Verify
Suggested check: confirm the carrier or SBC allowlists the local egress IP of your Edge.

### Rollback
Suggested rollback: remove the Edge IP from the carrier allowlist.

**SIP digest authentication with credentials**

### Do
On the external trunk, enable **Outbound** > **Digest Authentication**[^20]. Enter the **Realm**, **User Name**, and **Password** provided by the carrier, then click **Save External Trunk**[^20]. External trunk digest authentication applies to outbound requests only; inbound digest authentication is a phone-trunk feature[^21]. For Bandwidth Universal Platform trunks, digest authentication is required[^5].

### Verify
Suggested check: observe the outbound INVITE exchange to verify that the carrier challenges the call and accepts credentials without sending a SIP error.

### Rollback
Suggested rollback: disable digest authentication under outbound settings and save the trunk.

## Step 7: Configure inbound admission and trunk assignment

**BYOC Cloud: internet connection terminating directly in Genesys Cloud without an on-premises Edge**

### Do
In **SIP Access Control**, enter the carrier's signaling IP or CIDR addresses in the **Add an IP or CIDR address** box[^2]. Set **Use Source Address** to **Yes** to match on message source address or **No** for the Via header[^2]. BYOC Cloud trunks support only an allowlist in SIP Access Control and do not have a denylist[^3]. Do not check **Allow All**, as Genesys warns this is a security risk allowing any entity on the Internet to contact Genesys Cloud using the trunk[^1]. Configure a regionally unique **Inbound SIP Termination Identifier** on the trunk to associate incoming calls with your organization[^24]. The Inbound SIP Termination Header is optional and intended for use only when standard identification methods are unavailable[^23]. When multiple inbound identification methods match, Genesys Cloud evaluates them in the order: TGRP, FQDN, custom header, DNIS[^26]. Provide the carrier with the formatting shown in the trunk's dynamic help[^22]. Ensure firewalls allow SIP and media traffic, noting that media IP addresses in SDP differ from signaling IP addresses because BYOC Cloud handles them in separate services[^11][^46].

### Verify
Suggested check: verify that inbound INVITEs matching the termination identifier are accepted by the trunk.

### Rollback
Suggested rollback: remove the carrier IP addresses from access control settings and clear the termination identifier.

**BYOC Premises: connection terminating on a Genesys Cloud Edge appliance at your site**

### Do
In **SIP Access Control**, set **Use Source Address** to **Yes**, add the carrier addresses to the allowlist, and leave **Allow All** unchecked[^40]. Navigate to **Edges**, select your Edge, and take it out of service[^39]. Assign the site and Edge group[^39]. Under **External Trunks**, select **Use the following trunks**, choose this external trunk, return the Edge to service, and click **Save Edge**[^39].

### Verify
Confirm the Edge displays In-Service status and lists the external SIP trunk under External Trunks[^39].

### Rollback
Take the Edge out of service, remove the trunk under External Trunks, set the Edge back in service, and click Save Edge[^39].

## Step 8: Assign the external trunk to an outbound route

### Do
Navigate to the site's **Outbound Routes** tab[^37]. Genesys Cloud creates default outbound routes automatically, but a trunk must be assigned to an outbound route before it carries calls[^36]. Edit an existing route or click **Create New**, configure a name, select call classifications, and add the external trunk[^37]. If multiple trunks are assigned, select **Sequential** to route calls to the first trunk until capacity is reached before overflowing, or **Random** to spread calls across available trunks[^35]. Enable the **State** toggle and click **Save**[^37].

### Verify
Confirm that the route appears on the Outbound Routes tab with State enabled and the external trunk assigned[^37].

### Rollback
Suggested rollback: edit the route to disable state or remove the external trunk from the route.

## Step 9: Add carrier DID ranges

### Do
Navigate to **Admin** > **Telephony** > **DID Numbers** > **DID Ranges** and click **Create Range**[^18]. Enter the **DID Start**, **DID End**, and **Service Provider**[^18]. Setting identical start and end numbers creates a single DID[^18]. Ensure each number has a valid country code and area code, does not exceed the limit of 100,000 numbers per range, and does not overlap existing ranges[^19]. Note that Genesys Cloud Voice numbers are managed in Number Management rather than the DID Ranges feature[^17].

### Verify
Confirm that the new range appears in the DID Ranges list[^18].

### Rollback
Suggested rollback: select the range in the table and delete it.

## Step 10: Assign DIDs

### Do
Open the **DID Assignments** tab, select a number from the list, click **Assign**, and assign the DID to a person, call flow, or phone[^16].

### Verify
Confirm that the assignee's name appears next to the DID on the DID Assignments tab[^16].

### Rollback
Suggested rollback: select the DID on the DID Assignments tab and click Unassign.

## Step 11: Validate routing with the call simulator

### Do
Navigate to the site's **Simulate Call** tab[^47]. Enter a national number, an international number, and an emergency test pattern to evaluate routing configurations[^47]. The simulator evaluates number normalization, number plans, classifications, outbound routes, external trunk settings, in-service Edges, and destination sites[^47].

### Verify
Verify that each test returns a successful routing result and selects the expected external trunk[^47]. For any failure, open the **Log** tab within the simulator results to inspect the error[^47]. Note that the call simulator is a configuration validator and does not place an actual phone call[^48].

### Rollback
Suggested rollback: not applicable; the call simulator tests configuration without making changes.

## Step 12: Place live test calls

### Do
If trunk issues remain unresolved, open a support case with Genesys including the organization name, trunk name, test call details, and carrier packet captures[^54]. See also [Troubleshooting Genesys Cloud BYOC trunks](https://warmtransfer.net/knowledge/genesys-byoc-troubleshooting).

### Verify
Suggested check: verify that audio flows in both directions and that DTMF digits register successfully.

### Rollback
Suggested rollback: toggle the trunk state to out of service if test failures impact live production traffic.

## Applicability

Applies to: Genesys Cloud CX and Bandwidth Universal Platform voice. Deployments: multi-tenant. Sources checked 2026-10-01. Organizations in the Mexico or Singapore regions use the Dynamic Cloud Voice platform IP addresses[^33].

## What remains uncertain

Whether specific cipher suite requirements or public CA restrictions apply to BYOC Premises TLS connections is not covered by the sources below. The specific Edge IP addresses that an external carrier must allowlist for BYOC Premises egress traffic are not covered by the sources below.

## Sources

[^1]: Genesys warns that checking Allow All in SIP Access Control is a security risk because any entity on the Internet can then contact Genesys Cloud using the trunk. Source: [Configure SIP Access Control](https://help.genesys.cloud/articles/configure-sip-access-control/), Configure SIP Access Control, Allow All warning. Checked 2026-09-30.
[^2]: SIP Access Control on a trunk takes allowed IP or CIDR addresses entered in the Add an IP or CIDR address box, and a Use Source Address setting chooses between the message source address (Yes) and the Via header (No). Source: [Configure SIP Access Control](https://help.genesys.cloud/articles/configure-sip-access-control/), Configure SIP Access Control, procedure. Checked 2026-09-30.
[^3]: BYOC Cloud trunks support only an allowlist in SIP Access Control; there is no denylist for BYOC Cloud trunks. Source: [Configure SIP Access Control](https://help.genesys.cloud/articles/configure-sip-access-control/), Configure SIP Access Control, BYOC Cloud note. Checked 2026-09-30.
[^4]: The external trunk setting Address Omit + Prefix, enabled by default, excludes the plus (+) prefix from the outgoing origination address. Source: [External trunk settings](https://help.genesys.cloud/articles/external-trunk-settings/), External trunk settings, Address Omit + Prefix. Checked 2026-09-30.
[^5]: Bandwidth's Universal Platform guide for Genesys Cloud BYOC requires digest authentication on the Generic BYOC Carrier trunk, Address Omit + Prefix set to Disabled, and E.164 traffic. Source: [BYOC for Genesys Cloud on the Universal Platform](https://www.bandwidth.com/support/en/articles/12823444-byoc-for-genesys-cloud-on-the-universal-platform), BYOC for Genesys Cloud on the Universal Platform, Genesys configuration section. Checked 2026-09-30.
[^6]: A BYOC Cloud carrier must implement carrier-side ACL allowlisting of Genesys Cloud's public SIP signaling addresses. Source: [Carrier requirements for BYOC Cloud](https://help.genesys.cloud/articles/carrier-requirements-byoc-cloud/), Carrier requirements for BYOC Cloud, requirements list. Checked 2026-09-30.
[^7]: For the Dynamic Cloud Voice platform a carrier must additionally support RFC 3261 sections 8.2.6.2 (return the Via header untouched), 19.1.1 (the recommended FQDN method) and 19.1.5 (send unknown Contact URI parameters). Source: [Carrier requirements for BYOC Cloud](https://help.genesys.cloud/articles/carrier-requirements-byoc-cloud/), Carrier requirements for BYOC Cloud, Dynamic Cloud Voice platform requirements. Checked 2026-09-30.
[^8]: A BYOC Cloud carrier must have a publicly routable IP address or host name. Source: [Carrier requirements for BYOC Cloud](https://help.genesys.cloud/articles/carrier-requirements-byoc-cloud/), Carrier requirements for BYOC Cloud, requirements list. Checked 2026-09-30.
[^9]: A BYOC Cloud carrier must be SIP-compliant and fully support Record-Routing as required by RFC 3261. Source: [Carrier requirements for BYOC Cloud](https://help.genesys.cloud/articles/carrier-requirements-byoc-cloud/), Carrier requirements for BYOC Cloud, requirements list. Checked 2026-09-30.
[^10]: A BYOC Cloud carrier must support the UDP, TCP or TLS trunk transport protocol. Source: [Carrier requirements for BYOC Cloud](https://help.genesys.cloud/articles/carrier-requirements-byoc-cloud/), Carrier requirements for BYOC Cloud, requirements list. Checked 2026-09-30.
[^11]: The BYOC Cloud checklist requires ACLs configured on both sides of the connection and SIP and media access allowed through the customer firewall. Source: [BYOC Cloud configuration checklist](https://help.genesys.cloud/articles/byoc-cloud-configuration-checklist/), BYOC Cloud configuration checklist, ACL and firewall items. Checked 2026-09-30.
[^12]: On the Dynamic Cloud Voice platform, inbound Request-URIs use the genesys.cloud domain suffix with a single byoc subdomain, in the form <identifier>.byoc.<region>.genesys.cloud. Source: [Dynamic Cloud Voice platform overview and migration guide](https://help.genesys.cloud/articles/dynamic-cloud-voice-platform-overview/), Dynamic Cloud Voice platform overview, FQDN changes. Checked 2026-09-30.
[^13]: Genesys states that new customers and customers creating new BYOC Cloud SIP trunks should use the Dynamic Cloud Voice platform. Source: [Dynamic Cloud Voice platform overview and migration guide](https://help.genesys.cloud/articles/dynamic-cloud-voice-platform-overview/), Dynamic Cloud Voice platform overview, introduction. Checked 2026-09-30.
[^14]: The Dynamic Cloud Voice platform publishes three ingress and three egress signaling addresses per region, while the legacy platform lists four addresses per region. Source: [BYOC Cloud public SIP IP addresses](https://help.genesys.cloud/articles/byoc-cloud-public-sip-ip-addresses/), BYOC Cloud public SIP IP addresses, Legacy and Dynamic Cloud Voice sections. Checked 2026-09-30.
[^15]: Moving a BYOC Cloud trunk to the Dynamic Cloud Voice platform involves allowlisting the new egress ranges and Amazon roots at the remote endpoint, enabling the trunk's high capacity outbound platform toggle, and repointing SIP targets to the ingress addresses. Source: [Dynamic Cloud Voice platform overview and migration guide](https://help.genesys.cloud/articles/dynamic-cloud-voice-platform-overview/), Dynamic Cloud Voice platform overview, migration steps. Checked 2026-09-30.
[^16]: On the DID Assignments tab a DID is selected and assigned to a person, a call flow or a phone. Source: [Manage DID and toll-free number assignments](https://help.genesys.cloud/articles/manage-did-and-toll-free-number-number-assignments/), Manage DID and toll-free number assignments, assign a number. Checked 2026-09-30.
[^17]: Genesys Cloud Voice customers manage numbers in Number Management rather than the DID Ranges feature. Source: [Manage DID and toll-free number ranges](https://help.genesys.cloud/articles/did-numbers/), Manage DID and toll-free number ranges, note. Checked 2026-09-30.
[^18]: DID and toll-free ranges are added at Admin > Telephony > DID Numbers > DID Ranges > Create Range with DID Start, DID End and Service Provider; equal start and end create a single number. Source: [Manage DID and toll-free number ranges](https://help.genesys.cloud/articles/did-numbers/), Manage DID and toll-free number ranges, add a range. Checked 2026-09-30.
[^19]: Each number in a DID range must be valid with a valid country code and area code, a range cannot exceed 100,000 numbers, and ranges cannot overlap existing ranges. Source: [Manage DID and toll-free number ranges](https://help.genesys.cloud/articles/did-numbers/), Manage DID and toll-free number ranges, range requirements. Checked 2026-09-30.
[^20]: To enable external trunk digest authentication, select the trunk, enable Outbound > Digest Authentication, enter Realm, User Name and Password, and click Save External Trunk. Source: [Enable digest authentication](https://help.genesys.cloud/articles/enable-digest-authentication/), Enable digest authentication, External trunks procedure. Checked 2026-09-30.
[^21]: On external trunks, Genesys Cloud digest authentication applies to outbound requests only; inbound digest is a phone-trunk feature. Source: [Enable digest authentication](https://help.genesys.cloud/articles/enable-digest-authentication/), Enable digest authentication, External trunks and Phone trunks sections. Checked 2026-09-30.
[^22]: The trunk configuration UI shows dynamic help with INVITE formatting examples that include the termination identifier and the organization's regional address. Source: [Configure SIP routing for a BYOC Cloud trunk](https://help.genesys.cloud/articles/configure-sip-routing-for-a-byoc-cloud-trunk/), Configure SIP routing for a BYOC Cloud trunk, Inbound, FQDN and TGRP methods. Checked 2026-09-30.
[^23]: The Inbound SIP Termination Header is optional and intended for use only when the standard identification methods are unavailable. Source: [Create a trunk under BYOC Cloud](https://help.genesys.cloud/articles/create-a-byoc-cloud-trunk/), Create a trunk under BYOC Cloud, SIP routing step notes. Checked 2026-09-30.
[^24]: Genesys Cloud requires a unique identifier in the inbound INVITE to associate a call with the right organization's BYOC Cloud trunk, configured as a regionally unique Inbound SIP Termination Identifier. Source: [Configure SIP routing for a BYOC Cloud trunk](https://help.genesys.cloud/articles/configure-sip-routing-for-a-byoc-cloud-trunk/), Configure SIP routing for a BYOC Cloud trunk, Inbound. Checked 2026-09-30.
[^25]: For inbound identification Genesys recommends the FQDN or TGRP method, with DNIS Replacement as the alternative when carrier requirements prevent both. Source: [Carrier requirements for BYOC Cloud](https://help.genesys.cloud/articles/carrier-requirements-byoc-cloud/), Carrier requirements for BYOC Cloud, inbound routing methods. Checked 2026-09-30.
[^26]: When more than one inbound identification method matches, Genesys Cloud applies them in the order TGRP, FQDN, custom header, DNIS. Source: [Configure SIP routing for a BYOC Cloud trunk](https://help.genesys.cloud/articles/configure-sip-routing-for-a-byoc-cloud-trunk/), Configure SIP routing for a BYOC Cloud trunk, Inbound precedence. Checked 2026-09-30.
[^27]: The Listen Port trunk setting applies only to Premises External SIP trunks, not to BYOC Cloud trunk types. Source: [External trunk settings](https://help.genesys.cloud/articles/external-trunk-settings/), External trunk settings, Listen Port. Checked 2026-09-30.
[^28]: In BYOC Cloud, the location assigned to a site is also used for emergency services. Source: [BYOC Cloud quick start guide](https://help.genesys.cloud/articles/byoc-cloud-configuration-overview/), BYOC Cloud quick start guide, step: Create a location. Checked 2026-09-30.
[^29]: External trunk codec choices are G.722, G.729, PCMA, PCMU and Opus, and DTMF defaults to RTP Events with payload type 101. Source: [External trunk settings](https://help.genesys.cloud/articles/external-trunk-settings/), External trunk settings, Media > Codecs and DTMF. Checked 2026-09-30.
[^30]: A site used with the BYOC Cloud (or Genesys Cloud Voice) telephony connection option uses the Cloud media model. Source: [Sites overview](https://help.genesys.cloud/articles/sites/), Sites overview, media model section. Checked 2026-09-30.
[^31]: A site's media model cannot be changed after the site is created. Source: [Create a site under BYOC Cloud](https://help.mypurecloud.com/articles/create-a-site-under-byoc-cloud/), Create a site under BYOC Cloud, note under Media Model step. Checked 2026-09-30.
[^32]: A site used with the BYOC Premises telephony connection option uses the Premises media model. Source: [Sites overview](https://help.genesys.cloud/articles/sites/), Sites overview, media model section. Checked 2026-09-30.
[^33]: Organizations in the Mexico or Singapore regions use the Dynamic Cloud Voice platform IP addresses. Source: [BYOC Cloud public SIP IP addresses](https://help.genesys.cloud/articles/byoc-cloud-public-sip-ip-addresses/), BYOC Cloud public SIP IP addresses, regional note. Checked 2026-09-30.
[^34]: A BYOC Cloud trunk has an Inbound > Number Plan Site setting that is chosen when creating the trunk. Source: [Create a trunk under BYOC Cloud](https://help.genesys.cloud/articles/create-a-byoc-cloud-trunk/), Create a trunk under BYOC Cloud, Inbound > Number Plan Site step. Checked 2026-09-30.
[^35]: With several trunks on a route, Sequential sends calls to the first trunk until it reaches capacity and then the next, while Random spreads calls randomly across available trunks. Source: [Create an outbound route](https://help.genesys.cloud/articles/create-outbound-route/), Create an outbound route, Distribution. Checked 2026-09-30.
[^36]: Genesys Cloud creates default outbound routes automatically, but a trunk must be assigned to an outbound route before it carries calls. Source: [Create an outbound route](https://help.genesys.cloud/articles/create-outbound-route/), Create an outbound route, introduction. Checked 2026-09-30.
[^37]: An outbound route is created on the site's Outbound Routes tab with a name, classifications and external trunks, and is activated by enabling State and saving. Source: [Create an outbound route](https://help.genesys.cloud/articles/create-outbound-route/), Create an outbound route, procedure. Checked 2026-09-30.
[^38]: Outbound SIP Termination FQDN, Outbound SIP TGRP Attribute and Outbound SIP DNIS set, respectively, the domain, TGRP parameter and DNIS of the outbound Request-URI, and any or all may be used. Source: [Configure SIP routing for a BYOC Cloud trunk](https://help.genesys.cloud/articles/configure-sip-routing-for-a-byoc-cloud-trunk/), Configure SIP routing for a BYOC Cloud trunk, Outbound. Checked 2026-09-30.
[^39]: For BYOC Premises, an Edge is taken out of service, assigned a site and Edge group, given its trunk under External Trunks > Use the following trunks, put back in service and saved. Source: [Assign a site, Edge group, and external SIP trunk](https://help.genesys.cloud/articles/assign-site-edge-grp-sip-trunk/), Assign a site, Edge group, and external SIP trunk, procedure. Checked 2026-09-30.
[^40]: The BYOC Premises trunk procedure leaves Digest Authentication, Availability and Registration disabled and sets SIP Access Control with Use Source Address Yes, the carrier addresses allowed and Allow All unchecked. Source: [Create a trunk under BYOC Premises](https://help.genesys.cloud/articles/create-a-byoc-premises-trunk/), Create a trunk under BYOC Premises, steps 10-14. Checked 2026-09-30.
[^41]: A BYOC Premises trunk is created on the same External Trunks page with Type set to Premises External SIP, a Protocol and a Listen Port. Source: [Create a trunk under BYOC Premises](https://help.genesys.cloud/articles/create-a-byoc-premises-trunk/), Create a trunk under BYOC Premises, steps 1-6. Checked 2026-09-30.
[^42]: A BYOC Premises connection uses a Genesys Cloud Edge, whereas BYOC Cloud provides cloud-based carrier connections without a premises Edge. Source: [About BYOC](https://help.genesys.cloud/articles/about-byoc-bring-your-own-carrier/), About BYOC, BYOC Premises and BYOC Cloud descriptions. Checked 2026-09-30.
[^43]: The external trunk Protocol setting offers UDP, TCP and TLS, and the settings reference says that in most cases UDP is selected. Source: [External trunk settings](https://help.genesys.cloud/articles/external-trunk-settings/), External trunk settings, Protocol. Checked 2026-09-30.
[^44]: With BYOC Cloud, the PureCloud Voice - AWS site is a Genesys-managed placeholder created at activation and should not be selected when creating phones. Source: [Create a site under BYOC Cloud](https://help.mypurecloud.com/articles/create-a-site-under-byoc-cloud/), Create a site under BYOC Cloud, note on PureCloud Voice - AWS. Checked 2026-09-30.
[^45]: The Genesys BYOC Cloud quick start orders setup as: carrier requirements, location, site, SIP trunk, outbound route, number plan, DID and toll-free numbers, number assignment, then testing with the call simulator. Source: [BYOC Cloud quick start guide](https://help.genesys.cloud/articles/byoc-cloud-configuration-overview/), BYOC Cloud quick start guide, steps 1 to 9. Checked 2026-09-30.
[^46]: BYOC Cloud handles signaling and media in separate services, so the media IP addresses in SDP differ from the signaling IP addresses. Source: [BYOC Cloud public SIP IP addresses](https://help.genesys.cloud/articles/byoc-cloud-public-sip-ip-addresses/), BYOC Cloud public SIP IP addresses, introductory note. Checked 2026-09-30.
[^47]: The site's Simulate Call tab checks number normalization, number plan, classification, outbound route, external trunk settings, in-service Edges and destination sites, with a Log for detail. Source: [Test destination phone numbers with the call simulator](https://help.genesys.cloud/articles/test-destination-phone-numbers-with-the-call-simulator/), Test destination phone numbers with the call simulator, overview and results. Checked 2026-09-30.
[^48]: The Genesys Cloud call simulator is a configuration validator and does not place an actual phone call. Source: [Test destination phone numbers with the call simulator](https://help.genesys.cloud/articles/test-destination-phone-numbers-with-the-call-simulator/), Test destination phone numbers with the call simulator, note. Checked 2026-09-30.
[^49]: SIP Servers or Proxies lists the servers to which all outgoing requests are sent regardless of destination; BYOC Carrier and BYOC PBX trunks choose among them randomly, Premises trunks by priority with failover. Source: [External trunk settings](https://help.genesys.cloud/articles/external-trunk-settings/), External trunk settings, Outbound > SIP Servers or Proxies. Checked 2026-09-30.
[^50]: To create a BYOC Cloud site, go to Telephony > Sites, click Create New, enter a name, select a location and time zone, select Cloud under Media Model and click Create Site. Source: [Create a site under BYOC Cloud](https://help.mypurecloud.com/articles/create-a-site-under-byoc-cloud/), Create a site under BYOC Cloud, procedure. Checked 2026-09-30.
[^51]: Creating a site requires the Telephony Admin role with the Telephony > Plugin > All and Directory > Organization > Admin permissions. Source: [Create a site under BYOC Cloud](https://help.mypurecloud.com/articles/create-a-site-under-byoc-cloud/), Create a site under BYOC Cloud, Prerequisites. Checked 2026-09-30.
[^52]: After creation the Edit Site page has General, Number Plans, Outbound Routes and Simulate Call tabs, and the site's outbound Caller Address is entered in E.164 format. Source: [Create a site under BYOC Cloud](https://help.mypurecloud.com/articles/create-a-site-under-byoc-cloud/), Create a site under BYOC Cloud, General tab configuration. Checked 2026-09-30.
[^53]: The external trunk Media section has an SRTP Cipher Suite List offering AES_CM_128_HMAC_SHA1_80, AES_CM_128_HMAC_SHA1_32 and 192-bit and 256-bit variants. Source: [External trunk settings](https://help.genesys.cloud/articles/external-trunk-settings/), External trunk settings, Media > SRTP Cipher Suite List. Checked 2026-09-30.
[^54]: If BYOC Cloud issues remain unresolved, Genesys asks for a support case with the organization name, trunk name, test call details and carrier packet captures. Source: [BYOC Cloud configuration checklist](https://help.genesys.cloud/articles/byoc-cloud-configuration-checklist/), BYOC Cloud configuration checklist, final item. Checked 2026-09-30.
[^55]: BYOC Cloud TLS trunks use TLS 1.2 on port 5061 with SIPS for signaling and SRTP to protect media. Source: [TLS trunk transport protocol specification for BYOC Cloud](https://help.genesys.cloud/articles/tls-trunk-transport-protocol-specification/), TLS trunk transport protocol specification for BYOC Cloud, overview. Checked 2026-09-30.
[^56]: Genesys validates the carrier certificate's CN or SAN against the trunk's SIP Servers or Proxies values by host name; an IP address is not acceptable. Source: [TLS trunk transport protocol specification for BYOC Cloud](https://help.genesys.cloud/articles/tls-trunk-transport-protocol-specification/), TLS trunk transport protocol specification for BYOC Cloud, subject name validation. Checked 2026-09-30.
[^57]: For BYOC Cloud TLS the customer endpoint's X.509 certificate must be signed by one of the public certificate authorities Genesys lists. Source: [TLS trunk transport protocol specification for BYOC Cloud](https://help.genesys.cloud/articles/tls-trunk-transport-protocol-specification/), TLS trunk transport protocol specification for BYOC Cloud, certificate authorities. Checked 2026-09-30.
[^58]: Genesys deprecated TLS_RSA_WITH_AES_256_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 for BYOC Cloud TLS on 24 March 2025 and marks the ECDHE AES-GCM suites as NIST-preferred. Source: [TLS trunk transport protocol specification for BYOC Cloud](https://help.genesys.cloud/articles/tls-trunk-transport-protocol-specification/), TLS trunk transport protocol specification for BYOC Cloud, cipher suites table. Checked 2026-09-30.
[^59]: Because certificate names are matched against SIP Servers or Proxies by host name, a TLS trunk's SIP Servers or Proxies entries should be host names that appear in the carrier certificate, not IP addresses (inferred). Source: [TLS trunk transport protocol specification for BYOC Cloud](https://help.genesys.cloud/articles/tls-trunk-transport-protocol-specification/), TLS trunk transport protocol specification for BYOC Cloud, subject name validation. Checked 2026-09-30.
[^60]: BYOC Cloud supports only one-way (server-side) TLS, not mutual TLS, with the originating device initiating the connection. Source: [TLS trunk transport protocol specification for BYOC Cloud](https://help.genesys.cloud/articles/tls-trunk-transport-protocol-specification/), TLS trunk transport protocol specification for BYOC Cloud, TLS mode. Checked 2026-09-30.
[^61]: Genesys BYOC Cloud TLS endpoints present certificates chaining to Amazon Trust Services Root CA 1 and 2 on the Dynamic Cloud Voice platform and to DigiCert roots on the legacy platform. Source: [TLS trunk transport protocol specification for BYOC Cloud](https://help.genesys.cloud/articles/tls-trunk-transport-protocol-specification/), TLS trunk transport protocol specification for BYOC Cloud, certificate authority by platform. Checked 2026-09-30.
[^62]: External trunks are created at Menu > Digital and Telephony > Telephony > Trunks, External Trunks tab, Create New, and require the Telephony > Plugin > All permission. Source: [Create a trunk under BYOC Cloud](https://help.genesys.cloud/articles/create-a-byoc-cloud-trunk/), Create a trunk under BYOC Cloud, steps 1-2 and prerequisites. Checked 2026-09-30.
[^63]: An external trunk has a Trunk State switch that is set to In-Service when the trunk is created. Source: [Create a trunk under BYOC Cloud](https://help.genesys.cloud/articles/create-a-byoc-cloud-trunk/), Create a trunk under BYOC Cloud, Trunk State step. Checked 2026-09-30.
[^64]: The external trunk TLS settings default the method to TLS v1.2 and let the admin build a preferred cipher order list. Source: [External trunk settings](https://help.genesys.cloud/articles/external-trunk-settings/), External trunk settings, TLS. Checked 2026-09-30.
[^65]: A BYOC Cloud trunk type is BYOC Carrier (subtypes Generic, Verizon or WhatsApp Business Calling) or BYOC PBX (subtype Generic BYOC PBX). Source: [Create a trunk under BYOC Cloud](https://help.genesys.cloud/articles/create-a-byoc-cloud-trunk/), Create a trunk under BYOC Cloud, Type and subtype step. Checked 2026-09-30.
[^66]: Genesys Cloud offers BYOC as two offerings, BYOC Premises and BYOC Cloud, named according to where the SIP connection terminates against Genesys Cloud. Source: [About BYOC](https://help.genesys.cloud/articles/about-byoc-bring-your-own-carrier/), About BYOC, opening section. Checked 2026-09-30.
