Setting up site survivability for Webex Calling
webex-calling
Verified 2026-09-24 · 62 sources · tier 2–4
For A Webex Calling administrator configuring site survivability on a Cisco IOS XE router.
When a site loses its connection to the Webex cloud, supported endpoints automatically switch to Survivability mode and register with the local Survivability Gateway to provide fallback calling 51. Each site deploying Site Survivability requires a Survivability Gateway within its local network 55.
Before you start
Before configuring Site Survivability, the router platform must be supported and enrolled as a Cisco IOS managed gateway 26. Supported hardware platforms include the ISR 4000 series (4321 to 4461), Catalyst 8200 and 8300 edge platforms, and the virtual ISRv and Catalyst 8000V 46.
The gateway must use an IPv4 address, as IPv6 is not supported 37. Survivability-capable endpoints include Cisco MPP phones on firmware 12.0(1) or later (6800 and 7800 and 8800 series), 9800 series on PhoneOS 3.2(1) or later, Webex App for Windows and Mac 43.2 or later, and VG400/410/420 and ATA 191/192 adapters 25. Third-party devices are not supported 58.
What changes by situation
Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.
Three questions. One permanent page you can send to your manager.
Step 1 Verify platform eligibility and capacity
A dedicated router that runs only the Survivability Gateway service
Do
Confirm the router is running Cisco IOS XE Dublin 17.12.3 or later 36. Note that hunt groups, call forwarding, and auto attendant require IOS XE 17.18.2 or later 35. Verify that the endpoint registrations for the site do not exceed the platform limits: ISR 4321 supports up to 50 endpoint registrations, ISR 4331 supports 100, and ISR 4351 supports 700 8. Higher-capacity platforms support 1200 on an ISR 4431, 2000 on an ISR 4451-X or 4461, 2500 on a Catalyst 8200-1N-4T, and 2000 on a large Catalyst 8000V 9.
Verify
Suggested check: run a command to check the operating system release and verify endpoint inventory against platform registration limits.
Rollback
Suggested rollback: no configuration changes are made in this step.
The same Cisco IOS router as a registration-based Local Gateway trunk
Do
Confirm that the router runs Cisco IOS XE Dublin 17.12.3 or later 18 36. Colocation applies only to Cisco IOS gateways; third-party Local Gateways and partner-deployed Local Gateways shared across multiple customers cannot be colocated 12. When sizing, the total platform registration capacity must cover the sum of phone registrations and trunk registrations 17. Note that colocation does not support High Availability or configuration validation for the Local Gateway 14. Confirm that the registration-based Local Gateway trunk has already been created in Control Hub to supply registrar domain, OTG/DTG, line/port, credentials, and outbound proxy settings 38.
Verify
Suggested check: verify the registration trunk exists in the management portal and verify with system version commands that the router runs an approved release.
Rollback
Suggested rollback: no configuration changes are made in this step.
The same Cisco IOS router as a certificate-based Local Gateway trunk
Do
Confirm the router runs Cisco IOS XE Dublin 17.12.3 or later 18 36. Colocation applies only to Cisco IOS gateways and is not supported for third-party or partner-shared Local Gateways 12. Sizing must account for both phone and trunk registrations within the platform capacity 17. Local Gateway High Availability and configuration validation are not supported when colocated 14. Ensure the certificate-based Local Gateway trunk is already created in Control Hub before proceeding 38.
Verify
Suggested check: verify the certificate trunk exists in Control Hub and confirm the router version using system version commands.
Rollback
Suggested rollback: no configuration changes are made in this step.
Step 2 Prepare the router licenses, network services, and resources
Do
On an ISR 4000 series router, configure the uck9 and securityk9 boot-level licenses 40. On a Catalyst edge platform, configure a DNA Network Advantage feature license or better along with a throughput license 39.
Ensure the router has at least 256 MB free memory, 2000 MB free hard disk (SSD) space for the connector, and 50 MB free bootflash 30. Configure NTP synchronization and public DNS name resolution, import the Cisco IOS public CA bundle into the trustpool, and permit outbound HTTPS access to *.ucmgmt.cisco.com, *.webex.com, and *.wbx2.com (directly or through an HTTP proxy) 28. Configure a local user credential with privilege level 15 access for the connector management portal 27.
Verify
Suggested check: inspect active licenses, check clock synchronization, and test DNS name resolution from the router command-line interface.
Rollback
Suggested rollback: remove the configured connector credential and revert any added DNS or NTP configurations using the negation form of the commands.
Step 3 Enroll the router to Webex Cloud
Do
In Control Hub, navigate to Services > PSTN & Routing > Gateway configurations > Manage Gateways > Add Gateway 29. Run the onboarding TCL script in the gateway GuestShell via tclsh https://binaries.webex.com/ManagedGatewayScriptProdStable/gateway_onboarding.tcl 31. Enter the connector IP address and display name in Control Hub, then sign in to the connector management portal using the local privilege 15 credentials and click Enroll Now 2729.
Verify
Confirm that the gateway displays connector status Online under Manage Gateways in Control Hub 29.
Rollback
A managed gateway can be removed from Control Hub by selecting Delete Gateway in the Actions menu once all services on it are unassigned 21.
Step 4 Configure and install the gateway certificate
Do
Configure crypto pki trustpoint webex-sgw with fqdn, subject-name, and subject-alt-name set to the gateway FQDN 60. Generate an RSA key with a minimum size of 2048 bits 53. The certificate must be issued by a publicly known certificate authority; private or enterprise CA certificates are not supported 50. Wildcard certificates are not supported 45. Enroll, authenticate, and import the signed certificate using crypto pki enroll, crypto pki authenticate, and crypto pki import 60.
Verify
Suggested check: inspect installed public key certificates to verify that the router certificate is installed and matches the configured FQDN.
Rollback
Suggested rollback: delete the trustpoint using the negation form of the trustpoint command and remove the associated key pair.
Step 5 Adjust service assignments for colocation
A dedicated router that runs only the Survivability Gateway service
Do
Confirm on the Manage Gateways page in Control Hub that no services are currently assigned to the gateway 6.
Verify
Suggested check: check the gateway row in the management portal to confirm no service is active.
Rollback
Suggested rollback: no changes are needed.
The same Cisco IOS router as a registration-based Local Gateway trunk
Do
Because a colocated gateway must be provisioned in Control Hub as a Survivability Gateway service, any existing Local Gateway service assignment on this gateway must be unassigned on the Manage Gateways page by confirming the removal after the warning prompt 1661.
Verify
Confirm that the gateway row under Manage Gateways no longer shows the Local Gateway service 61.
Rollback
Reassign the Local Gateway service from the Manage Gateways page in Control Hub 6.
The same Cisco IOS router as a certificate-based Local Gateway trunk
Do
Unassign any existing Local Gateway service provisioned on the gateway from the Manage Gateways page in Control Hub, confirming the action through the prompt 1661.
Verify
Confirm that the Local Gateway service is no longer listed on the gateway row under Manage Gateways 61.
Rollback
Reassign the Local Gateway service on the Manage Gateways page 6.
Step 6 Assign the Survivability Gateway service
One Webex Calling location
Do
In Control Hub, go to Services > PSTN & Routing > Gateway configurations > Manage Gateways, select the gateway, and choose Assign Service > Survivability Gateway 6. Select the target Location, enter the Host Name matching the certificate trustpoint FQDN, enter the IPv4 address to which endpoints register, and click Assign 560. After assignment, use the Download Config Template action on the gateway details page to download the reference configuration 19.
Verify
Suggested check: check that the gateway details page displays the assigned Survivability Gateway service and associated location.
Rollback
Unassign the Survivability Gateway service under Manage Gateways 61.
Several smaller locations on the same LAN
Do
In Control Hub, go to Services > PSTN & Routing > Gateway configurations > Manage Gateways, select the gateway, and choose Assign Service > Survivability Gateway 6. Select all required locations served on the same LAN 43. Enter the Host Name matching the certificate trustpoint FQDN and the registration IPv4 address, then complete the assignment 560. Download the reference configuration using Download Config Template on the gateway details page 19.
Verify
Suggested check: verify that all assigned locations are listed under the Survivability Gateway service details in the portal.
Rollback
Unassign the service from the gateway in Control Hub under Manage Gateways 61.
Step 7 Apply core survivability configuration
Do
Under voice register global, configure mode webex-sgw, which enables Webex Calling Survivability mode and configures the gateway to listen on port 8933 for incoming secure TLS connections 42. TLS 1.3 is not supported for the Webex Survivability Gateway mode 59.
Do not configure the bind command in voice service voip configuration mode under sip, because doing so causes MPP phone registrations to fail 44. Ensure local firewalls permit inbound TCP port 8933 traffic from endpoint subnets to the gateway IP address 42.
Verify
Suggested check: inspect the running configuration to confirm the survivability mode setting under voice register global, and verify voice service configuration contains no bind command under sip.
Rollback
Suggested rollback: negate the mode by entering the negation command under voice register global.
Step 8 Configure dial-peers and routing preferences
A dedicated router that runs only the Survivability Gateway service
Do
The Survivability Gateway routes internal calls automatically using data synchronized from Webex 34.
Verify
Suggested check: confirm that internal calls route automatically using data synchronized from Webex.
Rollback
Suggested rollback: no configuration changes are made in this step.
The same Cisco IOS router as a registration-based Local Gateway trunk
Do
Re-apply or retain the registration-based Local Gateway tenant and dial-peers using the parameters provided in Control Hub 38. Configure outbound dial-peer preference 0 for locally registered endpoints, preference 2 for the Webex Calling trunk, and preference 3 for the PSTN trunk, and apply dial-peer hunt 2 to select by preference 15.
Verify
Suggested check: check dial-peer summaries to confirm dial-peer preferences and hunt selection in the running configuration.
Rollback
Suggested rollback: restore the saved dial-peer configuration or remove the added preferences using the negation form of the preference command under each dial-peer.
The same Cisco IOS router as a certificate-based Local Gateway trunk
Do
Configure the certificate-based Local Gateway trunk parameters: a TLS profile with cn-san validate bidirectional, a SIP OPTIONS keepalive profile over TLS, and a DNS session target pointing to the Webex SIP connect address 11. Configure outbound dial-peer preferences with preference 0 routing to locally registered endpoints, preference 2 routing to the Webex Calling trunk, and preference 3 routing to the PSTN trunk, and configure dial-peer hunt 2 15.
Verify
Suggested check: execute dial-peer summary checks to confirm preference ordering and verify OPTIONS keepalive status.
Rollback
Suggested rollback: restore the previous dial-peer and tenant configuration using the negation form of the relevant voice class commands.
Step 9 Configure PSTN connectivity for survivability mode
A SIP trunk to a PSTN gateway or provider that stays reachable during a Webex outage
Do
Configure a SIP trunk toward an on-premises PSTN gateway or provider using voice class tenant 300 bound to the PSTN-facing interface, an outbound dial-peer using tenant 300 with dtmf-relay rtp-nte, and an inbound dial-peer 4849. Ensure the PSTN trunk path remains accessible independently of WAN circuits to the Webex cloud, as survivability PSTN availability depends on available circuits during an outage 47.
Verify
Suggested check: check dial-peer summaries to confirm the configured PSTN dial-peer is up and active.
Rollback
Suggested rollback: remove the PSTN dial-peers and voice class tenant configuration using their respective negation forms.
A voice interface card in the router connected directly to a PSTN circuit
Do
Configure the router voice interface card (VIC) connected directly to the PSTN circuit and create outbound dial-peers pointing to the voice ports 48. The circuit must remain active during a WAN disconnect to maintain PSTN access 47.
Verify
Suggested check: check voice port summaries to verify the hardware voice ports are in an up state.
Rollback
Suggested rollback: remove the dial-peers pointing to the voice ports and shut down the ports using the shutdown command under voice port configuration.
Step 10 Configure emergency calling
A dedicated router that runs only the Survivability Gateway service
Do
Configure an Emergency Response Location with an ELIN and subnet mapping using voice emergency response location, and bind it to a voice emergency response zone so that outbound emergency calls in survivability mode present the defined ELIN 24.
Verify
Suggested check: inspect the running configuration to verify the configured ELIN and subnets.
Rollback
Suggested rollback: remove the emergency location and zone configurations using the negation forms of the emergency location and zone commands.
The same Cisco IOS router as a registration-based Local Gateway trunk
Do
Configure voice emergency response location with the appropriate ELIN and subnets, and configure voice emergency response zone 24. Configure an emergency e164-pattern-map (such as 300 with pattern 911) so emergency dial-peers match only calls originating from endpoints registered directly to the Survivability Gateway in survivability mode 13.
Verify
Suggested check: inspect the running configuration and confirm the pattern map is applied to the emergency dial-peer.
Rollback
Suggested rollback: remove the pattern map and the emergency location configuration using their negation forms.
The same Cisco IOS router as a certificate-based Local Gateway trunk
Do
Configure voice emergency response location with an ELIN and subnets, attached to a voice emergency response zone 24. Create an emergency e164-pattern-map to restrict emergency dial-peer matching to endpoints directly registered to the Survivability Gateway during survivability mode 13.
Verify
Suggested check: verify the emergency configuration and pattern map assignment in the running configuration.
Rollback
Suggested rollback: remove the pattern map and emergency location blocks using their negation forms.
Step 11 Configure optional survivability call features
A dedicated router that runs only the Survivability Gateway service
Do
On routers running IOS XE 17.18.2 or later, configure optional hunt groups, call forwarding, or auto attendant 35. The Survivability Gateway supports up to 100 hunt groups with at most 32 users each, supporting sequential, parallel, peer, or longest-idle algorithms; weighted routing is not supported 33. WarmTransfer's reading of the sources is that Basic Automatic Call Distribution (B-ACD) can be configured on a dedicated gateway, since B-ACD is documented as unsupported only when the Survivability Gateway is colocated with a Local Gateway 7.
Verify
Verify hunt group activity using show voice hunt-group statistics and B-ACD sessions using show call application sessions 54.
Rollback
Suggested rollback: remove hunt groups and call application configurations using the negation commands for hunt groups and call applications.
The same Cisco IOS router as a registration-based Local Gateway trunk
Do
On routers running IOS XE 17.18.2 or later, configure optional hunt groups, call forwarding, and auto attendant 35. The gateway supports up to 100 hunt groups with up to 32 users each using sequential, parallel, peer, or longest-idle routing 33. Do not configure B-ACD, as B-ACD is not supported when the Survivability Gateway is colocated with a Local Gateway 7.
Verify
Check hunt group operation using show voice hunt-group statistics 54.
Rollback
Suggested rollback: remove configured hunt groups using the negation command for hunt groups.
The same Cisco IOS router as a certificate-based Local Gateway trunk
Do
On routers running IOS XE 17.18.2 or later, configure hunt groups, call forwarding, and auto attendant as required 35. Up to 100 hunt groups with at most 32 users each are supported; weighted routing is not supported 33. Do not deploy B-ACD because it is unsupported on colocated gateways 7.
Verify
Verify hunt group status using show voice hunt-group statistics 54.
Rollback
Suggested rollback: delete hunt group configuration blocks using their negation forms.
Step 12 Trigger cloud data synchronization
Do
In Control Hub, navigate to the gateway details page and click Sync 56. An on-demand sync may take up to 10 minutes to complete 56, and the sync status update can take up to 30 minutes to reflect in Control Hub 57. A daily call data sync from the Webex cloud automatically refreshes credentials and routing information for registered users 20. The Webex cloud pushes the Survivability Gateway IP address, hostname, and port in each endpoint's device configuration file 22.
Verify
Suggested check: check the gateway details page in Control Hub until the sync status reflects successful completion.
Rollback
Suggested rollback: no rollback is necessary for a configuration sync.
Step 13 Execute failover testing
Do
When a site loses its connection to the Webex cloud, supported endpoints automatically switch to Survivability mode and register with the local Survivability Gateway, which provides fallback calling 51. Any Webex App call in progress when the site enters survivability is terminated 2. Users must not sign out of the Webex App during the outage, as a user who signs out cannot sign back in until cloud connectivity is restored 4.
Verify
Confirm that endpoints register to the local gateway 51. When the Webex App switches to survivability mode, a banner displays in the app 1. Confirm that internal calls route automatically between endpoints 34. Verify PSTN calls route successfully across the configured trunk or interface 47, and confirm emergency test calls present the configured ELIN 24.
Verify that dial patterns function as intended, noting that dialing patterns can operate differently in survivability mode compared to active cloud mode 23. Verify expected limitations: conferencing and three-way calling are not supported, Park, Unpark, Barge, and Pickup softkeys do not function (though they may not appear disabled on the phone), and the Webex App does not support messaging, meetings, or other calling services 362. Note that devices retaining 4G or 5G connectivity may remain registered to Webex Calling and fail to reach local site extensions 41.
Rollback
Suggested rollback: proceed immediately to the next step to re-establish normal network connectivity.
Step 14 Restore cloud connectivity and verify failback
Do
Registrations and call control revert to the Webex cloud once the Webex network connection has been restored for at least 30 seconds 32.
Verify
Confirm that registrations and call control revert to the Webex cloud once the Webex network connection has been continuously restored for at least 30 seconds 32. Confirm that the survivability banner disappears from the Webex App and that cloud messaging and meetings resume normal operation 13.
Rollback
Suggested rollback: no rollback is required once normal cloud operation has been restored.
Applicability
Applies to: Cisco Webex App, Cisco Webex Calling, and Cisco Unified SRST on IOS XE. Deployments: multi-tenant. Sources checked 2026-09-24. Webex Calling Survivability Gateway features require Cisco IOS XE Dublin 17.12.3 or later releases 36, and colocating Local Gateway and Survivability Gateway services on a single Cisco IOS gateway also requires Cisco IOS XE Dublin 17.12.3 or later 18. Advanced telephony features including Hunt Group, Call Forward, and Auto Attendant require IOS XE 17.18.2 or later 35. Supported endpoints require Cisco MPP phone firmware 12.0(1) or later, 9800 series PhoneOS 3.2(1) or later, or Webex App version 43.2 or later 25.
See also Remote site survivability patterns.
What remains uncertain
The exact safe procedure for simulating a WAN disruption during failover testing is not covered by the sources below.
The impact on active Local Gateway calls during the momentary unassignment of Local Gateway services in Control Hub is not covered by the sources below.
A specific Cisco IOS XE CLI command to view active survivability registration lists and local sync cache state on the router is not covered by the sources below.
See also
Builds on
- Remote site survivability patterns — This guide is the Webex Calling configuration walk-through; survivability-remote-site carries the general remote-site survivability concepts
Sources
- 2A Webex App call in progress when the site switches to survivability is terminated.Webex App | Site survivability · Known issues · Checked 2026-09-24
- 3Site survivability does not support messaging, meetings or other calling services in the Webex App.Webex App | Site survivability · Page body (supported features) · Checked 2026-09-24
- 4A Webex App user who signs out during survivability cannot sign in again until the network connection is restored.Webex App | Site survivability · Known issues · Checked 2026-09-24
- 5Assigning the Survivability Gateway service requires the Location, the Host Name used in the trustpoint certificate, and the IPv4 address to which endpoints register.Assign services to managed gateways · Assign Survivability Gateway service · Checked 2026-09-24
- 6The Survivability Gateway service is assigned in Control Hub from Services > PSTN & Routing > Gateway configurations > Manage Gateways by selecting the gateway, choosing Assign Service and picking Survivability Gateway.Assign services to managed gateways · Assign Survivability Gateway service · Checked 2026-09-24
- 7Basic Automatic Call Distribution (B-ACD) is not supported when the Survivability Gateway is colocated with a Local Gateway.Site survivability for Webex Calling · Limitations and restrictions (B-ACD) · Checked 2026-09-24
- 8Maximum endpoint registrations on the Survivability Gateway are 50 on an ISR 4321 and 100 on an ISR 4331 and 700 on an ISR 4351.Site survivability for Webex Calling · Requirements for Site Survivability / Supported platforms table (Maximum endpoint registrations column) · Checked 2026-09-24
- 9Maximum endpoint registrations on the Survivability Gateway are 1200 on an ISR 4431 and 2000 on an ISR 4451-X or 4461 and 2500 on a Catalyst 8200-1N-4T and 2000 on a large Catalyst 8000V.Site survivability for Webex Calling · Requirements for Site Survivability / Supported platforms table (Maximum endpoint registrations column) · Checked 2026-09-24
- 10The Webex Managed Gateway Command Reference marks Survivability Gateway commands such as voice register global, voice register pool and registrar server as introduced in Cisco IOS XE Cupertino 17.9.3a, an earlier floor than the 17.12.3 minimum stated in the site survivability article.disputedWebex Managed Gateway Command Reference · Command entries voice register global; voice register pool; registrar server (Command history) · Checked 2026-09-24
- 11For certificate-based trunking the colocation configuration differs only in Local Gateway trunk and tenant parts: a TLS profile with cn-san validate bidirectional, a SIP OPTIONS keepalive profile over TLS, and a DNS session target for the Webex SIP connect address.Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways · Certificate-based trunking (Before you begin; configuration) · Checked 2026-09-24
- 12Colocation applies only to Cisco IOS gateways: customers with a third-party Local Gateway must deploy the Survivability Gateway separately, and colocation does not apply to a partner-deployed Local Gateway shared across multiple customers.Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways · Limitations · Checked 2026-09-24
- 13In the colocation configuration an emergency e164-pattern-map (300, pattern 911 in the example) is used so the emergency dial-peers match only calls from endpoints registered directly to the Survivability Gateway in Survivability mode.Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways · Registration-based trunking configuration (emergency dial-peers) · Checked 2026-09-24
- 14On a colocated gateway, High Availability and config validation are not supported for the Local Gateway.Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways · Limitations · Checked 2026-09-24
- 15In the colocation configuration, outbound dial-peer preference 0 (default) routes to locally registered endpoints, preference 2 to the Webex Calling trunk and preference 3 to the PSTN trunk, with dial-peer hunt 2 selecting by preference.Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways · Registration-based trunking configuration (dial-peer preference and dial-peer hunt) · Checked 2026-09-24
- 16A colocated gateway must be provisioned in Control Hub as a Survivability Gateway service; a gateway already provisioned as a Local Gateway must be unassigned and then reassigned as Survivability Gateway.Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways · Limitations · Checked 2026-09-24
- 17On a colocated gateway the total registrations supported by the platform is the sum of phone and trunk registrations.Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways · Overview / capacity note · Checked 2026-09-24
- 18Colocating Local Gateway and Survivability Gateway services on one Cisco IOS gateway requires Cisco IOS XE Dublin 17.12.3 or later.Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways · Prerequisites · Checked 2026-09-24
- 19After assignment, a Download Config Template action on the gateway details page in Control Hub provides a reference configuration for the gateway.Site survivability for Webex Calling · Configure Survivability Gateway in Control Hub (final step) · Checked 2026-09-24
- 20A daily call data sync from the Webex cloud to the Survivability Gateway carries authentication information for registered users and their routing information.Site survivability for Webex Calling · Key conditions for Site Survivability · Checked 2026-09-24
- 21A managed gateway is removed from Control Hub with Delete Gateway in the Actions menu, which requires all services to be unassigned first.Enroll Cisco IOS managed gateways to Webex Cloud · Remove a gateway · Checked 2026-09-24
- 22The Webex cloud includes the Survivability Gateway IP address, hostname and port in each endpoint's device configuration file so endpoints can register to it during an outage.Site survivability for Webex Calling · How Site Survivability works · Checked 2026-09-24
- 23Dialing patterns can work differently in Survivability mode than in Active mode.Site survivability for Webex Calling · Limitations and restrictions · Checked 2026-09-24
- 24Emergency calls in Survivability mode go out with the ELIN defined for an Emergency Response Location, configured with voice emergency response location (elin and subnet) and voice emergency response zone.Site survivability for Webex Calling · Supported features table (Emergency calling); Configure emergency calling · Checked 2026-09-24
- 25Survivability-capable endpoints include Cisco MPP phones on firmware 12.0(1) or later (6800 and 7800 and 8800 series), 9800 series on PhoneOS 3.2(1) or later, Webex App for Windows and Mac 43.2 or later, and VG400/410/420 and ATA 191/192 adapters.Site survivability for Webex Calling · Supported devices · Checked 2026-09-24
- 26Before configuring Site Survivability the gateway must be enrolled to the Webex cloud as a Cisco IOS managed gateway.Site survivability for Webex Calling · Configure Survivability Gateway in Control Hub / Before you begin · Checked 2026-09-24
- 27Enrolment requires a local gateway credential with privilege level 15 access, which is used to sign in to the connector management portal.Enroll Cisco IOS managed gateways to Webex Cloud · Prerequisites; Enroll the gateway · Checked 2026-09-24
- 28Enrolment requires NTP and DNS resolution of public names on the gateway and outbound HTTPS to *.ucmgmt.cisco.com and *.webex.com and *.wbx2.com (optionally through an HTTP proxy), and the IOS public CA bundle imported into the trustpool.Enroll Cisco IOS managed gateways to Webex Cloud · Prerequisites · Checked 2026-09-24
- 29After Add Gateway in Services > PSTN & Routing > Gateway configurations > Manage Gateways, entering the connector IP and display name, and completing Enroll Now in the connector portal, a successfully enrolled gateway shows connector status Online in Control Hub.Enroll Cisco IOS managed gateways to Webex Cloud · Enroll the gateway; Verify enrollment · Checked 2026-09-24
- 30Enrolling a managed gateway requires at least 256 MB free memory and 2000 MB free on the hard disk (SSD) for the connector and 50 MB free on bootflash.Enroll Cisco IOS managed gateways to Webex Cloud · Prerequisites · Checked 2026-09-24
- 31The management connector is installed in the gateway GuestShell by running the TCL onboarding script copied from Control Hub Add Gateway, currently tclsh https://binaries.webex.com/ManagedGatewayScriptProdStable/gateway_onboarding.tcl.Enroll Cisco IOS managed gateways to Webex Cloud · Install the management connector · Checked 2026-09-24
- 32Registrations and call control revert to the Webex cloud once the Webex network connection has been restored for at least 30 seconds.Site survivability for Webex Calling · How Site Survivability works · Checked 2026-09-24
- 33The Survivability Gateway supports up to 100 hunt groups of at most 32 users each using sequential, parallel, peer or longest-idle algorithms; weighted routing is not supported.Site survivability for Webex Calling · Hunt group configuration; Limitations and restrictions · Checked 2026-09-24
- 34The Survivability Gateway routes internal calls automatically using routing information from Webex, and a PSTN trunk configuration must be added to it to provide external calling.Site survivability for Webex Calling · Key conditions for Site Survivability · Checked 2026-09-24
- 35Hunt Group, Call Forward and Auto Attendant features on the Survivability Gateway require IOS XE 17.18.2 or later.Site survivability for Webex Calling · Requirements for Site Survivability / Supported platforms · Checked 2026-09-24
- 36Webex Calling Survivability Gateway features are available with Cisco IOS XE Dublin 17.12.3 or later releases.Site survivability for Webex Calling · Requirements for Site Survivability / Supported platforms · Checked 2026-09-24
- 37The Survivability Gateway must use an IPv4 address; IPv6 is not supported.Site survivability for Webex Calling · Limitations and restrictions · Checked 2026-09-24
- 38A Local Gateway trunk must be created in Control Hub before configuring the gateway; it supplies values such as registrar domain, trunk group OTG/DTG, line/port, credentials and outbound proxy.Configure Local Gateway on Cisco IOS XE for Webex Calling · Registration-based Local Gateway / trunk information · Checked 2026-09-24
- 39A Catalyst edge platform Survivability Gateway requires a DNA Network Advantage feature license or better plus a throughput license.Site survivability for Webex Calling · Requirements for Site Survivability / Licenses · Checked 2026-09-24
- 40An ISR 4000 series Survivability Gateway requires the uck9 and securityk9 boot-level licenses.Site survivability for Webex Calling · Requirements for Site Survivability / Licenses · Checked 2026-09-24
- 41Devices with 4G or 5G connectivity may stay registered to Webex Calling during a site outage and may be unable to call other numbers at the same site location.Site survivability for Webex Calling · Limitations and restrictions · Checked 2026-09-24
- 42The mode webex-sgw command under voice register global enables Webex Calling Survivability mode and makes the gateway listen on port 8933 for incoming secure (TLS) connections.Site survivability for Webex Calling · Configure the Survivability Gateway / voice register global · Checked 2026-09-24
- 43One Survivability Gateway can be assigned to multiple locations by selecting all required locations in the assignment dialog, for multiple smaller locations within the same LAN.Site survivability for Webex Calling · Configure Survivability Gateway in Control Hub; Multi location set up · Checked 2026-09-24
- 44Configuring the SIP bind command in voice service voip configuration mode on the Survivability Gateway causes MPP phone registration to the gateway to fail.Site survivability for Webex Calling · Limitations and restrictions · Checked 2026-09-24
- 45The Survivability Gateway does not support wildcard certificates.Site survivability for Webex Calling · Certificate requirements / Configure certificates · Checked 2026-09-24
- 46Supported Survivability Gateway platforms include the ISR 4000 series (4321 to 4461), Catalyst 8200 and 8300 edge platforms, and the virtual ISRv and Catalyst 8000V.Site survivability for Webex Calling · Requirements for Site Survivability / Supported platforms table · Checked 2026-09-24
- 47PSTN service availability in Survivability mode depends on the SIP trunks or PSTN circuits available during the network outage.Site survivability for Webex Calling · Limitations and restrictions · Checked 2026-09-24
- 48PSTN access for the Survivability Gateway is configured either through a voice interface card connected directly to the PSTN or through a SIP trunk to a PSTN gateway or provider.Site survivability for Webex Calling · Configure PSTN connectivity (Voice Interface Card; SIP trunk) · Checked 2026-09-24
- 49The documented SIP trunk example uses voice class tenant 300 with a sip-server target and bind to the PSTN-facing interface, and an outbound dial-peer 300 with session target sip-server, voice-class sip tenant 300, a codec class and dtmf-relay rtp-nte.Site survivability for Webex Calling · Configure PSTN connectivity / SIP trunk to PSTN gateway · Checked 2026-09-24
- 50The Survivability Gateway supports only certificates from publicly known certificate authorities; private or enterprise CA certificates cannot be used.Site survivability for Webex Calling · Certificate requirements / Configure certificates · Checked 2026-09-24
- 51When a site loses its connection to the Webex cloud, supported endpoints automatically switch to Survivability mode and register with the local Survivability Gateway, which provides fallback calling.Site survivability for Webex Calling · Overview (How Site Survivability works) · Checked 2026-09-24
- 52When an outage occurs it may take a few minutes for devices to register to the Survivability Gateway.inferredSite Survivability for Webex Calling | Verizon · Page body (outage behaviour) · Checked 2026-09-24
- 53The Survivability Gateway certificate key must be RSA with a minimum size of 2048 bits.Site survivability for Webex Calling · Configure certificates (crypto key generate rsa step) · Checked 2026-09-24
- 54B-ACD sessions on the gateway can be checked with show call application sessions and hunt group activity with show voice hunt-group statistics.Site survivability for Webex Calling · B-ACD configuration; Hunt group statistics · Checked 2026-09-24
- 55Each site that deploys Site Survivability requires a Survivability Gateway within its local network.Site survivability for Webex Calling · Key conditions for Site Survivability · Checked 2026-09-24
- 56An on-demand sync is started with the Sync button on the gateway in Control Hub and may take up to 10 minutes to complete.Site survivability for Webex Calling · Key conditions for Site Survivability (sync) · Checked 2026-09-24
- 57The status update for an on-demand sync can take up to 30 minutes to appear in Control Hub.Site survivability for Webex Calling · Limitations and restrictions · Checked 2026-09-24
- 58Third-party devices are not supported with the Survivability Gateway.Site survivability for Webex Calling · Supported devices · Checked 2026-09-24
- 59TLS version 1.3 is not supported for the Webex Survivability Gateway operating mode.Cisco Unified SRST Administration Guide (All Versions) - Cisco Unified SRST Feature Overview · Secure SRST section · Checked 2026-09-24
- 60The gateway certificate is created under crypto pki trustpoint webex-sgw with fqdn and subject-name and subject-alt-name set to the gateway FQDN, which must match the Host Name entered in Control Hub; the CA-signed certificate is then enrolled, authenticated and imported with crypto pki enroll, authenticate and import.Site survivability for Webex Calling · Configure certificates (crypto pki trustpoint webex-sgw) · Checked 2026-09-24
- 61A service is unassigned from a managed gateway on the same Manage Gateways page by confirming the removal after a warning message.Assign services to managed gateways · Unassign services · Checked 2026-09-24
- 62In Survivability mode conferencing and three-way calling are not supported, and the Park, Unpark, Barge and Pickup softkeys are not supported although they do not appear disabled on the phone.Site survivability for Webex Calling · Limitations and restrictions (Survivability mode) · Checked 2026-09-24
Documents
Assign services to managed gateways
Cisco Unified SRST Administration Guide (All Versions) - Cisco Unified SRST Feature Overview
Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways
Configure Local Gateway on Cisco IOS XE for Webex Calling
Enroll Cisco IOS managed gateways to Webex Cloud
Site survivability for Webex Calling
Webex App | Site survivability
Webex Managed Gateway Command Reference
Site Survivability for Webex Calling | Verizon
Cite this page
APA
WarmTransfer. (2026, September 24). Setting up site survivability for Webex Calling. WarmTransfer. https://warmtransfer.net/guides/survivability-gateway-setup
BibTeX
@misc{warmtransfer-survivability-gateway-setup,
title = {Setting up site survivability for Webex Calling},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/guides/survivability-gateway-setup},
note = {Verified 2026-09-24}
}