# Setting up bring-your-own PSTN for Webex Contact Center

For Webex Contact Center administrators and voice engineers configuring PSTN ingress and egress through Control Hub and Cisco Unified Border Element (CUBE).

Canonical: https://warmtransfer.net/guides/wxcc-byo-pstn-setup

Last verified: 2026-09-30

Webex Contact Center routes voice interactions through Webex Calling PSTN infrastructure using either direct cloud PSTN or premises-based Local Gateways[^18][^41]. This guide walks through configuring carrier connectivity, Control Hub locations, signaling trunks, gateway dial-peers, and entry points[^25][^14].

## Before you start

- Check subscriptions under Account > Subscriptions to confirm the organization holds active Contact Center Standard or Premium agent subscriptions[^54].
- If agents will use Webex Calling devices or the Webex App, confirm an active Webex Calling subscription is assigned[^54][^64]. Calling subscriptions are not required for routing PSTN into the contact center, and new contact center subscriptions include Webex Calling PSTN services[^41].
- Complete the initial Webex Contact Center tenant setup and record the organization name and ID from Account > Organization Profile for TAC support cases[^53].
- In Control Hub under Contact Center > Settings > Service Details, verify that the Voice Media Platform is Real Time Media Service and the Telephony type is Webex Calling[^7][^65]. WarmTransfer's reading of the sources is that checking Service Details before building locations and entry points prevents creating resources on a tenant that must be reprovisioned[^66].
- If the tenant service details are incorrect, contact the Cisco account team, partner, or customer success manager, as administrators cannot self-correct telephony types[^67].

## What changes by situation

- How will PSTN calls reach Webex Contact Center? Cisco-provided Webex Contact Center PSTN; CUBE Local Gateway on a registration-based trunk; CUBE Local Gateway on a certificate-based trunk.
- Will agents in this organization use Webex Calling devices or the Webex App? Yes, agents use Webex Calling devices or the Webex App; No, agents use browser WebRTC desktop or external dial numbers.
- Will agents place outbound calls through Webex Contact Center? Yes, agents will place outdial calls; No, inbound only.

## Step 1: Verify platform and route prerequisites

**Cisco-provided Webex Contact Center PSTN**

### Do
Verify that all contact center phone numbers and incoming callers are located within the contiguous United States or Canada[^10][^68]. Ensure that no international dialing is required, as Webex Contact Center PSTN numbers are restricted to North American Numbering Plan destinations[^9]. If toll-free numbers are needed, confirm the tenant has the Bundle 2 inbound toll-free access add-on, or plan to use standard toll numbers[^58][^69].

### Verify
Suggested check: review the inventory of inbound numbers and caller geographic origins against the North American Numbering Plan boundaries.

### Rollback
Suggested rollback: abandon the cloud PSTN path and select a Local Gateway path if international dialing or non-US/Canada locations are required.

**CUBE Local Gateway on a registration-based trunk**

### Do
Confirm that peak concurrent contact center calls per trunk will not exceed 250 calls, including IVR and agent call legs[^59][^70]. Confirm the CUBE router is running Cisco IOS XE 17.6.1a or later[^30]. Verify that the organization is not deployed on Webex for Government, which does not support registration-based Local Gateway trunks[^19]. Check hardware platform licenses: an ISR4000 Local Gateway needs Unified Communications and Security technology licenses, while a Catalyst 8000 Edge router requires DNA Advantage with voice cards or DSPs and at least DNA Essentials without them[^28]. Confirm the PSTN carrier routes directly to the gateway; chaining a second carrier's forwarding before the contact center is not supported[^4][^71].

### Verify
Suggested check: run `show version` on the router CLI to confirm the software release meets requirements, and inspect license utilization.

### Rollback
Suggested rollback: if call volume projections exceed capacity or if Webex for Government is used, switch to a certificate-based trunk design.

**CUBE Local Gateway on a certificate-based trunk**

### Do
Confirm the CUBE router is running Cisco IOS XE 17.9.1a or later (17.12.2 or later is recommended)[^20]. On Webex for Government, confirm the router runs IOS XE 17.12.1a or later configured with FIPS-compliant GCM ciphers[^19]. Verify that you own a public domain name claimed in Control Hub and that you can publish public DNS A or SRV records for the gateway FQDN[^6]. Check hardware licenses: an ISR4000 Local Gateway needs Unified Communications and Security licenses, and a Catalyst 8000 Edge requires DNA Advantage with voice cards or DSPs or at least DNA Essentials without them[^28]. Confirm the upstream carrier connects directly without a second forwarding hop[^4].

### Verify
Suggested check: perform a public DNS lookup against the gateway FQDN to ensure resolution matches the gateway's external interface IP address.

### Rollback
Suggested rollback: verify DNS authority and certificate enrollment requirements before continuing.

## Step 2: Create Webex Calling locations

**Yes, agents use Webex Calling devices or the Webex App**

### Do
In Control Hub, go to Locations > Manage location > Create manually and enter the unique location name, address, country/region, languages, and time zone to create a dedicated contact center PSTN location[^12][^72]. Do not assign any endpoint devices, users, or workspaces to this PSTN location[^42][^73]. Next, create a separate Webex Calling location to house agent devices and users[^8]. Repeat the PSTN location creation if deploying across multiple interconnects or geographical regions[^12][^55].

### Verify
Suggested check: view Locations in Control Hub to confirm both locations are listed, and ensure the PSTN location shows no devices and no users assigned.

### Rollback
Suggested rollback: delete the created locations in Control Hub provided no services, trunks, or numbers have been attached.

**No, agents use browser WebRTC desktop or external dial numbers**

### Do
In Control Hub, navigate to Locations > Manage location > Create manually to create a dedicated contact center PSTN location[^12]. Populate the location name, physical address, country, announcement languages, and time zone[^72]. Ensure no endpoint devices, workspaces, or user entities are placed inside this location[^42][^74]. If deploying multi-region ingress, add additional dedicated PSTN locations as needed[^12][^55].

### Verify
Suggested check: navigate to Locations in Control Hub and verify the dedicated PSTN location exists with no endpoint devices.

### Rollback
Suggested rollback: delete the newly created PSTN location from Control Hub before assigning trunks or phone numbers.

## Step 3: Configure network security and media firewall rules

**Cisco-provided Webex Contact Center PSTN**

### Do
No gateway firewall modifications are required because media and signaling are cloud-hosted directly[^18].

### Verify
Suggested check: confirm the organization network connectivity meets standard cloud requirements.

### Rollback
Suggested rollback: no configuration to roll back.

**CUBE Local Gateway on a registration-based trunk**

### Do
On corporate firewalls protecting the CUBE gateway, disable SIP Application Layer Gateway (SIP ALG)[^57]. Allow outbound TCP signaling traffic from the CUBE interface to Webex Calling on destination port 8934 for SIP TLS[^50]. Configure firewall rules to allow SRTP media: allow outbound UDP from source ports 8000-48199 to destination ports 5004, 9000, 8500-8699, and 19560-65535, and allow inbound UDP on ports 19560-65535[^49]. Verify network transport delivers maximums of 100 ms one-way latency, 10 ms jitter, and 0.5 percent packet loss[^40].

### Verify
Suggested check: verify firewall traffic monitors record incrementing session hit counters on outbound signaling and UDP media ports during call setup.

### Rollback
Suggested rollback: remove the outbound signaling and UDP media port exceptions from the network firewall rules.

**CUBE Local Gateway on a certificate-based trunk**

### Do
Disable SIP ALG on firewalls sitting in the media and signaling paths[^57]. Allow outbound TCP traffic from CUBE to Webex Calling destination port 5062[^50]. Allow inbound TCP connections from Webex Calling IP ranges to CUBE destination port 8934[^50]. Permit SRTP media traffic: outbound UDP from source ports 8000-48199 to destination ports 5004, 9000, 8500-8699, and 19560-65535, plus inbound UDP on ports 19560-65535[^49]. Ensure path performance satisfies the 100 ms one-way latency, 10 ms jitter, and 0.5 percent packet loss limits[^40].

### Verify
Suggested check: check firewall logs to ensure inbound TCP connections from cloud IP blocks are permitted and not dropped.

### Rollback
Suggested rollback: delete the inbound signaling rule, outbound signaling rule, and SRTP port policies on the firewall.

## Step 4: Configure trunk and PSTN connection in Control Hub

**Cisco-provided Webex Contact Center PSTN**

### Do
In Control Hub, go to Management > Location, select the dedicated contact center PSTN location, and open its Calling settings[^75][^76]. Set the PSTN connection type to Cisco PSTN[^76]. Assign a designated main number to the location[^37][^77].

### Verify
Suggested check: verify under Location details that the calling settings display cloud PSTN as the active PSTN connection.

### Rollback
Suggested rollback: change the location PSTN connection to None or an alternative provider, noting that number management is blocked during connection changes[^39].

**CUBE Local Gateway on a registration-based trunk**

### Do
Navigate to Services > Calling > Call Routing > Trunk and click Add Trunk[^60]. Select the dedicated PSTN location, enter a trunk name of 24 characters or fewer, and select Registration-based[^60]. Record the generated parameters immediately: registrar domain, trunk group OTG/DTG, line/port, outbound proxy address, username, and password[^61]. If needed for redundancy, add the trunk to a route group with up to 10 trunks and configure priority weights[^56]. In Control Hub under Management > Location > Manage, select Premises-based PSTN and choose the trunk or route group[^38]. Assign a main telephone number to the location[^37].

### Verify
Suggested check: check the trunk in Services > Calling > Call Routing > Trunk to confirm it appears with status Unknown prior to gateway registration[^63].

### Rollback
In Control Hub under Management > Location > Manage, remove the trunk from the location's Premises-based PSTN setting, wait for the transition to finish, and delete the trunk via More Options > Delete Trunk[^39][^62].

**CUBE Local Gateway on a certificate-based trunk**

### Do
Navigate to Services > Calling > Call Routing > Trunk and click Add Trunk[^60]. Choose the dedicated PSTN location, provide a name up to 24 characters, select Certificate-based, and specify the claimed domain and gateway FQDN[^60][^6]. If load distribution or failover is required, assign the trunk to a route group containing up to 10 trunks with priority weights[^56]. Under Management > Location > Manage, set the location's PSTN connection to Premises-based PSTN and associate the trunk or route group[^38]. Assign a location main number[^37].

### Verify
Suggested check: view the trunk entry in Control Hub to verify its status displays Unknown or Offline pending gateway configuration[^63].

### Rollback
Revert the location's PSTN connection setting away from Premises-based PSTN, and delete the trunk in Control Hub using More Options > Delete Trunk once it is unassigned[^39][^62].

## Step 5: Configure the Webex-facing parameters on the CUBE router

**Cisco-provided Webex Contact Center PSTN**

### Do
No customer-premises gateway configuration is required for cloud PSTN[^18].

### Verify
Suggested check: confirm no Local Gateway is configured for this location in Control Hub.

### Rollback
Suggested rollback: no configuration to roll back.

**CUBE Local Gateway on a registration-based trunk**

### Do
On the CUBE router CLI under `sip-ua`, configure SIP TLS 1.2 and import the Cisco root CA bundle into the IOS XE trustpool[^34][^78]. Under `voice service voip`, configure the baseline parameters: enable `ip address trusted list`, `allow-connections sip to sip`, media statistics, and `early-offer forced`[^36]. Configure a STUN usage class with ICE-lite[^24][^79]. Create a `voice class srtp-crypto` class offering `AES_CM_128_HMAC_SHA1_80`[^33]. Create a `voice class codec` class prioritizing G.711 mu-law, followed by G.711 A-law[^21][^11]. Configure the Webex-facing `voice class tenant` containing the registrar domain, line/port, digest credentials, TLS transport, SRTP class, and source interface bindings[^31][^80]. Configure the Webex-facing VOIP dial-peer with `srtp`, attach the tenant, and set `max-conn` to 250 or lower[^27][^81].

### Verify
Suggested check: execute `show voice class tenant` and `show run | section dial-peer` on the CUBE CLI to verify registrar domain, transport, and dial-peer parameters[^35].

### Rollback
Suggested rollback: enter router configuration mode and remove the added dial-peer, voice class tenant, srtp-crypto, and codec class configurations, or restore the saved pre-change configuration file.

**CUBE Local Gateway on a certificate-based trunk**

### Do
On the CUBE CLI under `sip-ua`, enforce TLS 1.2 and import the Cisco root CA bundle into the trustpool[^34][^78]. Install a local PKI identity certificate with an RSA keypair matching the gateway FQDN claimed in Control Hub[^6][^82]. Create a `voice class srtp-crypto` class offering `AES_CM_128_HMAC_SHA1_80` (or FIPS-compliant GCM ciphers on Webex for Government)[^33][^19]. Create a `voice class codec` class with G.711 mu-law and G.711 A-law[^21][^11]. Under `voice service voip`, apply `allow-connections sip to sip`, `early-offer forced`, and media statistics[^36]. Configure STUN ICE-lite (except on Webex for Government, where ICE-lite is unsupported)[^24]. Build the Webex-facing tenant and dial-peer using TLS transport, the local certificate trustpoint, and the SRTP class[^6][^81].

### Verify
Suggested check: run `show voice class tenant` and `show crypto pki certificates` on the CUBE CLI to confirm the certificate trustpoint is active and mapped[^35].

### Rollback
Suggested rollback: delete the certificate trustpoint, Webex-facing dial-peer, and associated tenant profile from the running configuration.

## Step 6: Configure the carrier-facing dial-peers and routing on CUBE

**Cisco-provided Webex Contact Center PSTN**

### Do
Carrier routing is managed entirely by Cisco; no premises routing configuration is required[^18].

### Verify
Suggested check: confirm inbound telephony is configured through the cloud provider.

### Rollback
Suggested rollback: no configuration to roll back.

**CUBE Local Gateway on a registration-based trunk**

### Do
Create an incoming dial-peer matching traffic from the carrier's signaling IP address using `voice class uri`[^22]. Add the carrier IP addresses to the `ip address trusted list` under `voice service voip`[^36]. Create dial-peer groups to link the legs: point the destination of the carrier dial-peer to the Webex dial-peer group, and point the destination of the Webex dial-peer to the carrier dial-peer group[^22]. Configure G.711 and RFC 2833 on the carrier dial-peer[^11][^13]. WarmTransfer's reading of the sources is that the carrier-facing leg uses unencrypted RTP unless the carrier specifically requires SRTP[^29]. If connecting premises PBXs over the same CUBE trunk, configure PBX dial-peers and define premises dial plans under Calling > Call Routing > Dial Plans in Control Hub[^52][^51].

### Verify
Suggested check: initiate a test SIP INVITE from the carrier to ensure it matches the incoming carrier dial-peer and binds to the Webex dial-peer group[^22].

### Rollback
Suggested rollback: remove the carrier dial-peer and dial-peer group assignments from the CUBE configuration.

**CUBE Local Gateway on a certificate-based trunk**

### Do
Create the carrier-facing VOIP dial-peer using `voice class uri` to identify the carrier by signaling IP address[^22]. Add the carrier's signaling subnets to the `ip address trusted list` under `voice service voip`[^36]. Configure dial-peer groups in both directions, routing calls from the carrier dial-peer group to the Webex dial-peer and vice versa[^22]. Enforce G.711 audio codecs and RFC 2833 relay[^11][^13]. If coexisting with an on-premises PBX, create the PBX dial-peers and build premises dial plans in Control Hub under Calling > Call Routing > Dial Plans[^52][^51].

### Verify
Suggested check: run `show dial-peer voice summary` on the CUBE router to verify dial-peer operational states and dial-peer group destination bindings[^22].

### Rollback
Suggested rollback: delete the carrier dial-peer and restore the previous dial-peer table.

## Step 7: Verify gateway registration and trunk operational status

**Cisco-provided Webex Contact Center PSTN**

### Do
Cloud-based PSTN does not use premises trunks; verify that the dedicated PSTN location remains healthy in Control Hub[^18][^76].

### Verify
Suggested check: confirm the location's status is active under Control Hub Locations.

### Rollback
Suggested rollback: no configuration to roll back.

**CUBE Local Gateway on a registration-based trunk**

### Do
On the CUBE router CLI, execute `show sip-ua register status`[^35]. Monitor trunk status in Control Hub under Services > Calling > Call Routing > Trunk, which refreshes every 3 minutes[^63][^83]. If the trunk enters an Impaired state, at least one Webex Calling edge proxy cannot connect, requiring a review of outbound firewall rules and credentials[^63][^84].

### Verify
Verify that `show sip-ua register status` reports the line/port as registered[^35]. Verify that Control Hub transitions the trunk status from Unknown to Online[^63].

### Rollback
Suggested rollback: re-enter trunk credentials under the CUBE voice class tenant if registration fails with authentication errors.

**CUBE Local Gateway on a certificate-based trunk**

### Do
In Control Hub, navigate to Services > Calling > Call Routing > Trunk and observe the trunk health status[^63]. The trunk status refreshes every 3 minutes[^63][^83]. If the trunk reports Offline or Impaired, inspect inbound TCP 8934 firewall rules, public DNS A/SRV records, and gateway certificate chain validation[^63][^50][^6].

### Verify
Verify that the trunk status displays Online in Control Hub, confirming that all Webex Calling edge proxies have connected successfully[^63].

### Rollback
Suggested rollback: check certificate expiry and verify that the gateway FQDN in public DNS matches the certificate Subject Alternative Name.

## Step 8: Add and activate contact center phone numbers

**Cisco-provided Webex Contact Center PSTN**

### Do
In Control Hub, verify the telephone numbers provisioned with your Webex Contact Center PSTN subscription[^18]. Ensure that all numbers are North American Numbering Plan numbers within the lower 48 US states or Canada[^9].

### Verify
Suggested check: view the Numbers page under Calling > Numbers to ensure the assigned numbers appear active and assigned to the PSTN location.

### Rollback
Suggested rollback: unassign numbers from contact center routing if they were provisioned in error.

**CUBE Local Gateway on a registration-based trunk**

### Do
In Control Hub, go to Services > PSTN & Routing > Numbers and click Add[^44]. Select the dedicated PSTN location and input only the contact center numbers in +E.164 format (US numbers may also be entered in national format)[^44][^23][^85]. Activate the newly added numbers immediately, as inactive numbers remain inactive even if assigned to services[^46].

### Verify
Verify that the phone numbers appear in the numbers list with an Active status and are saved in +E.164 format[^46][^86].

### Rollback
Unassign the phone numbers from any features, then delete them via Services > PSTN & Routing > Numbers[^45]. Only unassigned numbers can be deleted in bulk, and numbers belonging to a block cannot be deleted unless every number in that block is unassigned[^45].

**CUBE Local Gateway on a certificate-based trunk**

### Do
Under Services > PSTN & Routing > Numbers, select Add, choose the dedicated PSTN location, and enter the numbers in +E.164 format[^44][^23]. Avoid configuring unallocated numbers to prevent routing failures[^85]. Activate the numbers, ensuring their status reflects Active prior to routing assignment[^46].

### Verify
Verify that the numbers show Active status in the Control Hub numbers table[^46].

### Rollback
Unassign the numbers and delete them from the location numbers table[^45].

## Step 9: Create inbound telephony entry point and map numbers

### Do
In Control Hub, navigate to Services > Contact Center > Customer Experience > Channels and select Create Channel[^14][^87]. Set the channel type to Inbound Telephony, select a published routing flow, and specify the time zone and service level threshold[^14][^88]. Note that in Flow Designer, flows must be validated without errors before they can be published[^89]. In the phone number section, select the dedicated PSTN location, choose the inbound arrival number in +E.164 format, and assign the PSTN region[^17][^55]. Use Add to map additional numbers to the same entry point[^17]. This mapping is subject to platform limits: tenants support up to 6000 active entry points, up to 500 dialed numbers per entry point, and up to 15000 dialed number mappings in total[^90][^91][^92]. Note that the Webex Calling location main number does not appear in the available number drop-down and cannot be mapped to an entry point[^93][^94].

### Verify
Suggested check: view the entry point channels list and use the search and sort tools to confirm each globalized phone number is mapped to the intended channel and flow version[^95][^96].

### Rollback
Suggested rollback: edit the channel to remove individual phone number associations or delete the inbound channel entry point from Control Hub.

## Step 10: Configure default outdial ANI

**Yes, agents will place outdial calls**

### Do
In Control Hub, navigate to Contact Center > Tenant Settings > Voice[^97][^98]. In the Default Outdial ANI drop-down, select a phone number that is already mapped to an inbound entry point[^48][^99]. Note that by default the first dial number mapped to an entry point is displayed, and if no dial number is mapped the field shows Not Configured[^100][^101]. If agents require caller ID choices, create Outdial ANI lists under Services > Contact Center > Desktop Experience > Outdial ANI, add mapped entry point numbers, and associate the list to desktop profiles under Services > Contact Center > Desktop experience > Desktop profiles[^102][^103][^104][^105].

### Verify
Verify that the Default Outdial ANI field displays the selected mapped phone number rather than Not Configured[^48][^106].

### Rollback
Suggested rollback: select a different previously configured mapped number from the Default Outdial ANI drop-down or clear custom ANI list assignments from agent desktop profiles.

**No, inbound only**

### Do
No outdial ANI configuration is required for an inbound-only deployment[^48].

### Verify
Suggested check: confirm the tenant voice settings remain at default.

### Rollback
Suggested rollback: no configuration to roll back.

## Step 11: Execute end-to-end acceptance testing

**Yes, agents will place outdial calls + Cisco-provided Webex Contact Center PSTN**

### Do
From an external telephone, place test calls to each mapped entry point number[^17]. When the contact center flow answers, press IVR digits to test RFC 2833 delivery[^13][^107]. Have an agent in the Available or Idle state place an outdial call to an external phone (maximum 18 digits, excluding extension or entry point numbers) and inspect the delivered caller ID[^108][^109][^110][^111].

### Verify
Verify two-way audio using G.711 mu-law or A-law[^11][^112]. Verify the external recipient sees the configured Default Outdial ANI[^111]. Suggested check: verify the call record appears in Control Hub call troubleshooting within the troubleshooting retention window[^113].

### Rollback
Suggested rollback: if call routing fails, confirm the entry point mapping and verify the routing flow version label.

**No, inbound only + Cisco-provided Webex Contact Center PSTN**

### Do
From an external PSTN phone, place inbound test calls to each phone number mapped to an entry point[^17]. Enter menu digits on the phone keypad to test RFC 2833 recognition by the ingress flow[^13][^107].

### Verify
Verify that two-way audio is established using G.711 codecs without clipping or silence[^11][^112]. Suggested check: check that the call completes along the designed flow path and generates contact session records.

### Rollback
Suggested rollback: adjust flow error handling or review number mapping in the entry point channel settings.

**Yes, agents will place outdial calls + CUBE Local Gateway on a registration-based trunk**

### Do
Place test calls through the PSTN carrier across the CUBE gateway into each mapped entry point[^22]. Press DTMF digits in the IVR menu to confirm RFC 2833 handling[^13]. Have an agent initiate an outdial call to an external PSTN number and confirm caller ID delivery[^48][^111]. If volume allows, ramp concurrent calls toward the 250 calls-per-trunk maximum to confirm gateway stability[^59].

### Verify
Verify on CUBE that SRTP with AES_CM_128_HMAC_SHA1_80 is negotiated on the Webex leg and G.711 is negotiated on both legs[^33][^11]. Verify the trunk in Control Hub remains in the Online state under load[^63]. Suggested check: confirm in Control Hub call troubleshooting that the Local Gateway trunk and route group legs are recorded correctly[^113].

### Rollback
Suggested rollback: if media or signaling drops occur, request that the carrier temporarily roll back number translation to the legacy PBX or circuit while CUBE traces are captured.

**No, inbound only + CUBE Local Gateway on a registration-based trunk**

### Do
Place inbound PSTN calls from carrier numbers through the CUBE router into the mapped entry points[^22]. Transmit DTMF tones to verify RFC 2833 reception in the ingress flow[^13]. Test concurrent calls up toward the 250 call ceiling[^59].

### Verify
Verify audio negotiates G.711 mu-law or A-law, SRTP negotiates AES_CM_128_HMAC_SHA1_80 toward Webex, and the trunk remains Online[^11][^33][^63].

### Rollback
Suggested rollback: recheck CUBE dial-peer group configuration and verify firewall counters on signaling ports.

**Yes, agents will place outdial calls + CUBE Local Gateway on a certificate-based trunk**

### Do
Place inbound calls across the carrier trunk through CUBE to each mapped entry point[^22]. Send DTMF digits to confirm RFC 2833 relay[^13]. Place an agent outdial call to verify outbound signaling and caller ID presentation[^48][^111]. If needed, test concurrent call volumes beyond 250 sessions to validate certificate-based trunk scaling[^59].

### Verify
Verify the Webex leg negotiates G.711 with SRTP (AES_CM_128_HMAC_SHA1_80, or GCM on Webex for Government)[^11][^33][^19]. Verify the trunk in Control Hub maintains an Online status throughout the test[^63].

### Rollback
Suggested rollback: if calls fail, review public DNS FQDN resolution, verify TLS handshake completion on inbound signaling, and redirect carrier routing back to backup trunks.

**No, inbound only + CUBE Local Gateway on a certificate-based trunk**

### Do
Route carrier test calls across the CUBE gateway to each configured entry point number[^22]. Test IVR menu navigation using RFC 2833[^13].

### Verify
Verify that two-way audio negotiates G.711, SRTP encryption is active on the Webex leg, and the trunk status shows Online in Control Hub[^11][^33][^63].

### Rollback
Suggested rollback: verify CUBE certificate chain bindings and inspect router SIP logs if calls fail to reach the ingress service.

## Applicability

Applies to: Cisco Webex Calling, Cisco Webex Contact Center, Cisco Webex Calling Local Gateway, Cisco Unified Border Element, Cisco Calling Plan, and Cisco Webex Contact Center with Webex Calling. Deployments: on-premises, multi-tenant, and on-premises-gateway. Sources checked 2026-09-30. Webex Contact Center PSTN is available only in the contiguous United States and Canada[^10][^68]. Registration-based Local Gateway trunks require Cisco IOS XE 17.6.1a or later and are not supported on Webex for Government[^30][^19]. Certificate-based Local Gateway trunks require IOS XE 17.9.1a or later (17.12.2 or later recommended), or IOS XE 17.12.1a or later with FIPS GCM ciphers on Webex for Government[^20][^19]. Webex Calling Local Gateway PSTN connectivity is available across more than 140 markets[^26][^114].

## What remains uncertain

Sources disagree on whether inbound telephony entry points can be mapped to extension numbers: one source states that only globalized +E.164 numbers are supported and extensions cannot be mapped, whereas another source states an entry point can be populated with a PSTN number, an extension number, or both[^115][^116]. Sources also describe conflicting guidance regarding Cisco Calling Plans: one documentation set restricts Cisco Calling Plans to Webex Contact Center trials or service numbers, while another lists it as generally not supported for contact center traffic[^2][^117]. Additionally, Cisco documents contradictory requirements regarding SIP offer types: one technical requirements document states that SIP Early Offer is not supported toward Webex Contact Center and delayed offer is required, whereas Cisco's Local Gateway configuration baseline explicitly mandates configuring `early-offer forced` on CUBE[^36][^118]. WarmTransfer's reading of the sources is that the carrier-facing leg uses unencrypted RTP unless the carrier requires otherwise[^29]. Specific public IP subnet ranges for Webex Calling edge proxies are not covered by the sources below.

## Sources

[^1]: The Cisco Calling Plans article states Cisco Calling Plans are not supported with Webex Contact Center or for high-concurrent, high-volume, or unusually short or long calls (disputed). Source: [Get Started with the Cisco Calling Plans](https://help.webex.com/en-us/article/nousk9ab/Get-Started-with-the-Cisco-Calling-Plan), Cisco Calling Plans requirements and limitations. Checked 2026-09-30.
[^2]: Cisco Calling Plans support Webex Contact Center only through the use of Service Numbers. Source: [Get Started with the Cisco Calling Plans](https://help.webex.com/en-us/article/nousk9ab/Get-Started-with-the-Cisco-Calling-Plan), Cisco Calling Plans requirements and limitations. Checked 2026-09-30.
[^3]: The Webex Contact Center voice channel article lists Cisco Webex Calling Plan as a PSTN option for Webex Contact Center trials and in regions where Cisco supports service numbers (disputed). Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), PSTN connectivity options > Cisco Webex Calling Plan. Checked 2026-09-30.
[^4]: A single upstream PSTN carrier forwarding to Local Gateway, CCP or Webex Contact Center PSTN numbers is supported, but chaining a second carrier's forwarding before the call reaches the contact center is not supported because of added delay. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), PSTN call forwarding best practices. Checked 2026-09-30.
[^5]: Cloud Connected PSTN for Webex Contact Center is offered through certified calling providers in over 65 countries, with the partner handling activation, billing and number allocation. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), PSTN connectivity options > Cloud Connected PSTN. Checked 2026-09-30.
[^6]: A certificate-based trunk requires a claimed domain and a DNS A or SRV record for the Local Gateway in public DNS, and authenticates by certificate with Local Gateway FQDN verification rather than digest. Source: [Get started with Local Gateway](https://help.webex.com/en-us/article/t9xctu/Get-started-with-Local-Gateway), Certificate-based vs registration-based trunk comparison. Checked 2026-09-30.
[^7]: Cisco's voice channel checklist includes verifying that the Voice Media Platform is Real Time Media Service and the Telephony type is Webex Calling. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Summary checklist. Checked 2026-09-30.
[^8]: Cisco's setup checklist calls for dedicated PSTN locations without endpoint devices and separate agent locations when agents use Webex Calling devices. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Summary checklist. Checked 2026-09-30.
[^9]: Webex Contact Center PSTN does not support international dialing; its numbers are limited to North American Numbering Plan destinations in the lower 48 states or Canada. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), PSTN connectivity options > Webex Contact Center PSTN. Checked 2026-09-30.
[^10]: Webex Contact Center PSTN, bought from Cisco as a bundle with Webex Contact Center, is available only in the contiguous United States and Canada. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), PSTN connectivity options > Webex Contact Center PSTN. Checked 2026-09-30.
[^11]: Webex Contact Center PSTN media supports the G.711 mu-law and G.711 A-law codecs. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Technical requirements > PSTN media and signaling standards. Checked 2026-09-30.
[^12]: A PSTN location is created in Control Hub under Locations > Manage location > Create manually, and multiple PSTN locations can be used for different interconnect options or multi-regional deployments. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Location configuration > creating PSTN location; multiple locations. Checked 2026-09-30.
[^13]: Webex Contact Center PSTN signaling uses RFC 2833 for DTMF. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Technical requirements > PSTN media and signaling standards. Checked 2026-09-30.
[^14]: An inbound entry point is created in Control Hub under Services > Contact Center > Customer Experience > Channels > Create Channel with channel type Inbound Telephony, a routing flow, time zone and service level threshold. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Number assignment to contact center > configuring entry points. Checked 2026-09-30.
[^15]: The channel setup article states that Webex Contact Center supports mapping only globalized +E.164 PSTN numbers to entry points and that extension numbers are not supported (disputed). Source: [Set up a channel](https://help.webex.com/en-us/article/ewuay1/Set-up-a-channel), Create an inbound telephony channel > Support Number. Checked 2026-09-30.
[^16]: When an entry point has both an E.164 number and an extension, Webex Contact Center always reports the call against the E.164 number, even if the extension was dialed (disputed). Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Number assignment to contact center > phone number mapping note. Checked 2026-09-30.
[^17]: Mapping a number to an entry point requires selecting the Webex Calling location, the PSTN number added in Webex Calling as the inbound arrival number, and a PSTN region; more numbers are added with Add. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Number assignment to contact center > phone number mapping. Checked 2026-09-30.
[^18]: Cisco documents four PSTN connectivity options for Webex Contact Center: Webex Contact Center PSTN, Cloud Connected PSTN, Webex Calling Local Gateway, and Cisco Webex Calling Plan. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), PSTN connectivity options section. Checked 2026-09-30.
[^19]: Webex for Government does not support registration-based Local Gateway; it requires certificate-based trunks on IOS XE 17.12.1a or later with FIPS-compliant GCM ciphers. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), Webex for Government section. Checked 2026-09-30.
[^20]: A certificate-based Local Gateway on Cisco CUBE requires Cisco IOS XE 17.9.1a or later, with 17.12.2 or later recommended. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), Prerequisites / trunk types. Checked 2026-09-30.
[^21]: Cisco's Local Gateway example codec class prefers G.711 mu-law then G.711 A-law, which Cisco says suits most deployments. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), voice class codec 100. Checked 2026-09-30.
[^22]: Cisco's Local Gateway example routes between Webex Calling and a SIP PSTN trunk with dial-peer groups: the Webex dial-peer's destination is the PSTN dpg and the PSTN dial-peer's destination is the Webex dpg. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), Configure Local Gateway with a SIP PSTN trunk; voice class dpg. Checked 2026-09-30.
[^23]: Numbers for calls routed into Webex Contact Center from a Local Gateway are provisioned in Control Hub in +E.164 format. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), PSTN connectivity options > Webex Calling Local Gateway. Checked 2026-09-30.
[^24]: Cisco's Local Gateway configuration enables STUN usage with ICE-lite so media optimization is negotiated where possible; Webex for Government does not support it. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), voice class stun-usage 100. Checked 2026-09-30.
[^25]: Webex Calling Local Gateway lets a Webex Contact Center customer keep its current on-premises PSTN carrier; the customer's SBC registers with Webex Calling and routes calls between on-premises resources and Webex Calling. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), PSTN connectivity options > Webex Calling Local Gateway. Checked 2026-09-30.
[^26]: Webex Calling Local Gateway as a Webex Contact Center PSTN option is available in over 140 markets. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), PSTN connectivity options > Webex Calling Local Gateway. Checked 2026-09-30.
[^27]: On a registration-based trunk the Webex-facing dial-peer's max-conn should be at most 250. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), dial-peer voice 100 voip. Checked 2026-09-30.
[^28]: An ISR4000 Local Gateway needs both Unified Communications and Security technology licenses; a Catalyst 8000 Edge needs DNA Advantage with voice cards or DSPs and at least DNA Essentials without them. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), Platform requirements. Checked 2026-09-30.
[^29]: In Cisco's example the srtp command is set only on the Webex-facing dial-peer, so the PSTN-facing leg appears to use unencrypted RTP unless the carrier requires otherwise (inferred). Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), dial-peer voice 100 and dial-peer voice 200 examples. Checked 2026-09-30.
[^30]: A registration-based Local Gateway on Cisco CUBE requires Cisco IOS XE 17.6.1a or later. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), Prerequisites / trunk types. Checked 2026-09-30.
[^31]: For a registration-based trunk, CUBE's voice class tenant carries the Control Hub registrar domain, line/port credentials, digest authentication, TLS transport, the SRTP crypto class and source interfaces. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), voice class tenant 100 (registration-based). Checked 2026-09-30.
[^32]: The Local Gateway SBC for Webex Contact Center can be Cisco IOS XE or an approved third-party SBC, connected to Webex Calling over the internet or privately through Webex Edge Connect. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), PSTN connectivity options > Webex Calling Local Gateway. Checked 2026-09-30.
[^33]: The Local Gateway's Webex-facing SRTP crypto class must offer AES_CM_128_HMAC_SHA1_80, the only suite Webex Calling supports. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), voice class srtp-crypto 100. Checked 2026-09-30.
[^34]: The Local Gateway signals to Webex Calling over SIP TLS 1.2 and needs the Cisco root CA bundle imported into the IOS XE trustpool. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), Configure sip-ua; upload the Cisco root CA bundle. Checked 2026-09-30.
[^35]: Cisco lists show sip-ua register status and show voice class tenant as Local Gateway verification commands. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), Verification commands. Checked 2026-09-30.
[^36]: Cisco's Local Gateway baseline under voice service voip includes ip address trusted list, allow-connections sip to sip, media statistics and early-offer forced. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), voice service voip configuration. Checked 2026-09-30.
[^37]: A main number must be assigned to a Webex Calling location if the location has any trunks or extension-only entities. Source: [Configure Webex Calling for your organization](https://help.webex.com/article/njvdjf2/Configure-Webex-Calling-for-your-organization), Main number requirement. Checked 2026-09-30.
[^38]: A location's PSTN connection is set to Premises-based PSTN in Control Hub under Management > Location > Manage by selecting Premises-based PSTN and choosing the trunk. Source: [Configure Webex Calling for your organization](https://help.webex.com/article/njvdjf2/Configure-Webex-Calling-for-your-organization), Select a trunk for Premises-based PSTN. Checked 2026-09-30.
[^39]: A location's PSTN setup can be changed after creation, but no number management change can be made for a location undergoing a PSTN connection transition. Source: [Configure Webex Calling for your organization](https://help.webex.com/article/njvdjf2/Configure-Webex-Calling-for-your-organization), Location settings; PSTN connection change. Checked 2026-09-30.
[^40]: Cisco sets maximums of 100 ms one-way latency, 10 ms jitter and 0.5 percent packet loss for consistent Local Gateway call quality. Source: [Get started with Local Gateway](https://help.webex.com/en-us/article/t9xctu/Get-started-with-Local-Gateway), Network requirements. Checked 2026-09-30.
[^41]: Calls reach Webex Contact Center through Webex Calling PSTN services, which do not require a Webex Calling subscription, and all new Webex Contact Center subscriptions include Webex Calling PSTN services. Source: [Webex Contact Center Architecture](https://help.webex.com/en-us/article/utqcm7/Webex-Contact-Center-Architecture), PSTN connectivity section. Checked 2026-09-30.
[^42]: Cisco does not support endpoint devices in the same Webex Calling location as Webex Contact Center PSTN. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Location configuration > creating PSTN location. Checked 2026-09-30.
[^43]: Webex Contact Center does not provide transcoding or media termination point services for calls using unsupported codecs. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Technical requirements > codec transcoding. Checked 2026-09-30.
[^44]: Phone numbers are added to a location under Services > PSTN & Routing > Numbers in E.164 format, with US numbers also accepted in national format. Source: [Manage phone numbers in Control Hub](https://help.webex.com/en-us/article/wkj3f0), Add phone numbers. Checked 2026-09-30.
[^45]: Only unassigned phone numbers can be deleted in bulk, and a number in a block cannot be deleted unless every number in that block is unassigned. Source: [Manage phone numbers in Control Hub](https://help.webex.com/en-us/article/wkj3f0), Delete phone numbers. Checked 2026-09-30.
[^46]: An inactive number assigned to a feature, user or workspace stays inactive until it is activated. Source: [Manage phone numbers in Control Hub](https://help.webex.com/en-us/article/wkj3f0), Number status: active and inactive. Checked 2026-09-30.
[^47]: The Webex Contact Center PSTN signaling table lists Delayed Offer as supported, Early Offer and Early Media as not supported, and a 20 ms packetization time in SDP. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Technical requirements > PSTN media and signaling standards. Checked 2026-09-30.
[^48]: A dial number must be mapped to an entry point before it can be the Default Outdial ANI; otherwise the Default Outdial ANI field shows Not Configured. Source: [Set up voice settings for Webex Contact Center](https://help.webex.com/en-us/article/gsmsaeb/Set-up-voice-settings-for-Webex-Contact-Center), Default Outdial ANI. Checked 2026-09-30.
[^49]: Local Gateway SRTP media uses UDP source ports 8000-48199 outbound to Webex Calling destination ports including 5004, 9000, 8500-8699 and 19560-65535, and inbound UDP 19560-65535. Source: [Port Reference Information for Webex Calling](https://help.webex.com/en-us/article/b2exve), Local Gateway media rows. Checked 2026-09-30.
[^50]: The Local Gateway opens outbound SIP TLS over TCP to Webex Calling on port 8934 for a registration-based trunk or 5062 for a certificate-based trunk, and a certificate-based gateway must also accept inbound TCP 8934 from Webex Calling. Source: [Port Reference Information for Webex Calling](https://help.webex.com/en-us/article/b2exve), Local Gateway signaling rows. Checked 2026-09-30.
[^51]: For Local Gateway deployments, outbound dial plans for premises destinations are created under Calling > Call Routing > Dial Plans with a name, routing choice and patterns. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Dial plan configuration (Local Gateway). Checked 2026-09-30.
[^52]: Premises-based PSTN through a Local Gateway keeps the current PSTN provider, and the same trunks can also connect to premises PBXs. Source: [Configure trunks, route groups, and dial plans for Webex Calling](https://help.webex.com/article/n0xb944/Configure-Trunks-Route-Groups-and-Dial-Plans-for-Cisco-Webex-Calling), Set location PSTN connection > Premises-based PSTN. Checked 2026-09-30.
[^53]: Prerequisites include recording the organization name and ID from Account > Organization Profile, which are needed for TAC cases, and completing the initial Webex Contact Center tenant setup. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Prerequisites > organization and initial tenant setup. Checked 2026-09-30.
[^54]: Before setting up voice channels, an administrator needs valid Contact Center Standard or Premium agent subscriptions, plus a Calling subscription for agents who use Webex devices or the Webex App, checked under Account > Subscriptions. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Prerequisites > subscription verification. Checked 2026-09-30.
[^55]: Webex Contact Center can keep media within the local region where its voice media edge and ingress services run, which Cisco hosts in several AWS regions including the US, Canada, UK, Europe, Asia Pacific and India. Source: [Webex Contact Center Architecture](https://help.webex.com/en-us/article/utqcm7/Webex-Contact-Center-Architecture), Media path and regional considerations. Checked 2026-09-30.
[^56]: A route group is a group of up to 10 trunks that lets Webex Calling distribute calls across trunks or provide redundancy, with priority weights set per trunk. Source: [Configure trunks, route groups, and dial plans for Webex Calling](https://help.webex.com/article/n0xb944/Configure-Trunks-Route-Groups-and-Dial-Plans-for-Cisco-Webex-Calling), Route groups section. Checked 2026-09-30.
[^57]: Cisco recommends turning off SIP ALG on firewalls in the Webex Calling path because some implementations break firewall traversal. Source: [Port Reference Information for Webex Calling](https://help.webex.com/en-us/article/b2exve), SIP ALG note. Checked 2026-09-30.
[^58]: When the telephony type is Cisco PSTN and the tenant lacks the Bundle 2 inbound toll-free number access add-on, a toll number should be used to map an entry point. Source: [Set up voice settings for Webex Contact Center](https://help.webex.com/en-us/article/gsmsaeb/Set-up-voice-settings-for-Webex-Contact-Center), Set up inbound dial numbers. Checked 2026-09-30.
[^59]: A registration-based Local Gateway trunk carries up to 250 concurrent calls; deployments needing more than 250 concurrent calls per trunk require a certificate-based trunk. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Trunk and route group configuration > concurrent call capacity. Checked 2026-09-30.
[^60]: A trunk is added in Control Hub under Services > Calling > Call Routing > Trunk > Add Trunk by choosing a location, a name of at most 24 characters, and a trunk type of Registration-based or Certificate-based. Source: [Configure trunks, route groups, and dial plans for Webex Calling](https://help.webex.com/article/n0xb944/Configure-Trunks-Route-Groups-and-Dial-Plans-for-Cisco-Webex-Calling), Create a trunk. Checked 2026-09-30.
[^61]: Creating a registration-based trunk yields a register domain, trunk group OTG/DTG, line/port, outbound proxy address, username and password; lost credentials must be regenerated from the trunk information screen. Source: [Configure trunks, route groups, and dial plans for Webex Calling](https://help.webex.com/article/n0xb944/Configure-Trunks-Route-Groups-and-Dial-Plans-for-Cisco-Webex-Calling), Create a trunk > generated credentials. Checked 2026-09-30.
[^62]: A trunk can be deleted from Services > Calling > Call Routing > Trunk via More Options > Delete Trunk as long as it is not in use. Source: [Configure trunks, route groups, and dial plans for Webex Calling](https://help.webex.com/article/n0xb944/Configure-Trunks-Route-Groups-and-Dial-Plans-for-Cisco-Webex-Calling), Delete a trunk. Checked 2026-09-30.
[^63]: Control Hub shows trunk status as Online (all Webex Calling edge proxies connected), Impaired (at least one proxy failing), Offline (no connection) or Unknown (connection in progress), refreshed every 3 minutes. Source: [Configure trunks, route groups, and dial plans for Webex Calling](https://help.webex.com/article/n0xb944/Configure-Trunks-Route-Groups-and-Dial-Plans-for-Cisco-Webex-Calling), Trunk status. Checked 2026-09-30.
[^64]: A valid Webex Calling subscription is required for agents who use Webex devices or the Webex App. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb/Set-Up-Voice-Channel-for-Webex-Contact-Center), Webex Calling Configuration Checklist > Active Subscriptions. Checked 2026-09-30.
[^65]: Cisco's Webex Calling configuration checklist for Webex Contact Center says to confirm under Contact Center > Settings > Service Details that the voice media platform is Real Time Media Service and telephony is Webex Calling. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb/Set-Up-Voice-Channel-for-Webex-Contact-Center), Webex Calling Configuration Checklist > Service Details. Checked 2026-09-30.
[^66]: Because the tenant's telephony selection is locked after activation and the administrator cannot correct it, checking Service Details before any other configuration avoids building locations and entry points on a tenant that Cisco must first reprovision (inferred). Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb/webexcc_t_change-the-telephony-option-for-a-webex-contact-center-tenant.html), section Verification of Webex Contact Center Service Details. Checked 2026-09-24.
[^67]: A tenant whose service details are wrong should be raised with the Cisco account team, customer success manager or partner, because the administrator cannot self-correct the telephony selection. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb), Verification of Webex Contact Center Service Details. Checked 2026-09-16.
[^68]: Webex Contact Center PSTN is available in the contiguous United States and Canada only. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb/Set-Up-Voice-Channel-for-Webex-Contact-Center), PSTN connectivity options > Webex Contact Center PSTN. Checked 2026-09-30.
[^69]: For Cisco-provided Webex Contact Center PSTN, mapping toll-free numbers requires the Bundle 2 inbound toll-free number access add-on; without it toll numbers must be used. Source: [Set up voice settings for Webex Contact Center](https://help.webex.com/en-us/article/gsmsaeb/Set-up-voice-settings-for-Webex-Contact-Center), Map dial numbers to entry points (entitlement note). Checked 2026-09-30.
[^70]: A registration-based Webex Calling Local Gateway processes up to 250 concurrent calls into Webex Contact Center, and deployments needing more than 250 concurrent calls including IVR and agent legs must select a certificate-based trunk. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb), Configuration of Webex Local Gateway / Session Border Controller Configuration for Local Gateway Connectivity. Checked 2026-09-16.
[^71]: Introducing a second upstream PSTN carrier that forwards calls to an intermediary carrier before Webex Contact Center is not a supported configuration for Cloud Connected PSTN, Local Gateway or Webex Contact Center PSTN. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb/Set-Up-Voice-Channel-for-Webex-Contact-Center), PSTN Call Forwarding Scenarios and Best Practices. Checked 2026-09-30.
[^72]: Creating a Webex Calling location requires a unique location name, a country or region, a full address, announcement and email languages, and a time zone. Source: [Configure Webex Calling for your organization](https://help.webex.com/en-us/article/njvdjf2/Configure-Webex-Calling-for-your-organization), location setup procedure, add location fields. Checked 2026-09-24.
[^73]: Cisco does not support endpoint devices in the same Webex Calling location as Webex Contact Center PSTN and warns this may cause unexpected overage charges. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb/Set-Up-Voice-Channel-for-Webex-Contact-Center), Configuration of Webex Contact Center PSTN Locations. Checked 2026-09-30.
[^74]: A dedicated Webex Calling location is created for Contact Center PSTN, and Cisco does not support endpoint devices in the same location as Webex Contact Center PSTN. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/2dputx/Set-up-voice-channels-for-Webex-Contact-Center), Set up voice channels > Location configuration. Checked 2026-09-30.
[^75]: Additional Webex Calling locations are created in Control Hub under Management, Location, after the First Time Setup Wizard has created the initial location. Source: [Configure Webex Calling for your organization](https://help.webex.com/en-us/article/njvdjf2/Configure-Webex-Calling-for-your-organization), location setup procedure, navigation step. Checked 2026-09-24.
[^76]: A Webex Calling location's PSTN connection is set on the location's Calling tab by choosing Cisco PSTN, Cloud Connected PSTN, or Premises-based PSTN through a Local Gateway. Source: [Configure Webex Calling for your organization](https://help.webex.com/en-us/article/njvdjf2/Configure-Webex-Calling-for-your-organization), section on PSTN connection for a location. Checked 2026-09-24.
[^77]: Assigning a main number to a Webex Calling location is mandatory if the location has any trunks or extension-only entities, and the main number serves as the location's default caller ID. Source: [Configure Webex Calling for your organization](https://help.webex.com/en-us/article/njvdjf2/Configure-Webex-Calling-for-your-organization), section on the location main number. Checked 2026-09-24.
[^78]: On CUBE, TLS 1.2 can be enforced globally with 'transport tcp tls v1.2' (minimum form) under sip-ua, ciphers are listed in voice class tls-cipher and bound with a trustpoint in voice class tls-profile, and a voice class tenant can apply the tls-profile with 'session transport tcp tls' and 'listen-port secure'. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), TLS cipher, TLS profile and SIP-UA/tenant configuration sections. Checked 2026-09-30.
[^79]: CUBE ICE-Lite is configured with voice class stun-usage <tag> and 'stun usage ice lite', and Cisco lists IPv6, ANAT, codec transparent, SDP passthrough, media flow-around, MTP and TCL/VXML scripts as unsupported with it. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards: ICE-Lite Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_voi-cube-icelite.html), Restrictions; Configuring ICE-Lite. Checked 2026-09-30.
[^80]: A CUBE voice class tenant acts as a per-trunk configuration template applied with voice-class sip tenant <tag>, and settings resolve in the order dial-peer, then tenant, then global. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - Configure Multiple Trunks Using Tenants](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_voi-cube-multi-tenants.html), Overview; configuration precedence. Checked 2026-09-30.
[^81]: CUBE's voice class srtp-crypto lists preferred SRTP suites (AEAD_AES_256_GCM, AEAD_AES_128_GCM, AES_CM_128_HMAC_SHA1_80, AES_CM_128_HMAC_SHA1_32) and can be applied globally under voice service voip sip, in a voice class tenant, or per dial-peer with voice-class sip srtp-crypto, with 'srtp' enabling secure calls on the dial-peer. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_srtp-srtp-interworking.html), Voice class srtp-crypto configuration; application at global, tenant and dial-peer levels. Checked 2026-09-30.
[^82]: Cisco's CUBE SIP TLS chapter builds the CUBE identity by generating an RSA key pair and a crypto pki trustpoint with rsakeypair, fqdn, subject-name CN, subject-alt-name, enrollment terminal and revocation-check settings. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), Certificate creation / trustpoint configuration section. Checked 2026-09-30.
[^83]: Local Gateway trunk status in Control Hub updates every 3 minutes. Source: [Configure trunks, route groups, and dial plans for Webex Calling](https://help.webex.com/article/n0xb944/Configure-Trunks-Route-Groups-and-Dial-Plans-for-Cisco-Webex-Calling), Trunk status. Checked 2026-09-30.
[^84]: Control Hub shows a Local Gateway trunk as Online, Offline, Impaired (at least one Webex Calling Edge proxy cannot connect) or Unknown (connection in progress for a new gateway). Source: [Configure trunks, route groups, and dial plans for Webex Calling](https://help.webex.com/article/n0xb944/Configure-Trunks-Route-Groups-and-Dial-Plans-for-Cisco-Webex-Calling), Trunk status. Checked 2026-09-30.
[^85]: Cisco warns administrators to configure only the numbers allocated to their Webex Contact Center PSTN connection because entering invalid numbers may result in call routing failures. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb/Set-Up-Voice-Channel-for-Webex-Contact-Center), Configuration of Webex Contact Center PSTN numbers (warning note). Checked 2026-09-30.
[^86]: Premises-based PSTN DIDs or toll-free numbers configured in Control Hub for Local Gateway are saved in +E.164 format. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb/Set-Up-Voice-Channel-for-Webex-Contact-Center), Local Gateway number requirements. Checked 2026-09-30.
[^87]: Inbound telephony entry points are created in Control Hub under Services, Contact Center, Customer Experience, Channels. Source: [Set up a channel](https://help.webex.com/en-us/article/ewuay1/Set-up-a-channel), procedure Create a channel, navigation step. Checked 2026-09-24.
[^88]: An inbound voice entry point is created with channel type Inbound Telephony and a routing flow selected from a drop-down, and its timezone defaults to the tenant timezone. Source: [Set up a channel](https://help.webex.com/en-us/article/ewuay1/Set-up-a-channel), procedure Create a channel, Channel Type, Timezone and Routing Flow fields. Checked 2026-09-24.
[^89]: In Flow Designer a flow must be validated and its errors fixed before it can be published. Source: [Build and manage flows with Flow Designer](https://help.webex.com/en-us/article/nhovcy4/Build-and-manage-flows-with-Flow-Designer), Flow Designer interface > Footer pane (validation and publish). Checked 2026-09-30.
[^90]: The Webex Contact Center system limits table sets a maximum of 6000 active entry points per tenant. Source: [System limits in Webex Contact Center](https://help.webex.com/en-us/article/n7s6ed7/System-limits-in-Webex-Contact-Center), Table 1. Maximum system limits for configuration entities and attributes > Entry points > Active. Checked 2026-09-30.
[^91]: The Webex Contact Center system limits table allows at most 500 dialed numbers per entry point and 15000 dialed number to entry point mappings per tenant. Source: [System limits in Webex Contact Center](https://help.webex.com/en-us/article/n7s6ed7/System-limits-in-Webex-Contact-Center), Table 1 > Dialed numbers > Entry Point; Per entry point. Checked 2026-09-30.
[^92]: Webex Contact Center system limits allow 6000 active entry points, 1000 active outdial entry points, 15000 dialed numbers configured as entry points in total and 500 dialed numbers per entry point. Source: [System limits in Webex Contact Center](https://help.webex.com/en-us/article/n7s6ed7), Table 1. Maximum system limits for configuration entities and attributes - entry point and dialed number rows. Checked 2026-09-16.
[^93]: The Webex Calling location main number does not appear in the list of numbers available for dial number to entry point mapping. Source: [Set up voice settings for Webex Contact Center](https://help.webex.com/en-us/article/gsmsaeb/Set-up-voice-settings-for-Webex-Contact-Center), Map dial numbers to entry points (note under Available numbers/DN). Checked 2026-09-30.
[^94]: A Webex Calling location's main number does not appear in the list of numbers available for entry point mapping, so using it for mapping requires changing the location's main number. Source: [Set up voice settings for Webex Contact Center](https://help.webex.com/en-us/article/gsmsaeb/Set-up-voice-settings-for-Webex-Contact-Center), section on numbers available from Webex Calling locations. Checked 2026-09-24.
[^95]: A July 24 2026 admin update added the ability to search and sort phone numbers associated with an entry point in Control Hub. Source: [What's new for administrators in Webex Contact Center](https://help.webex.com/en-us/article/nv7abhz/What's-new-for-administrators-in-Webex-Contact-Center), July 24 2026 entry > admin experience improvements. Checked 2026-09-30.
[^96]: Entry point configuration includes a routing flow selection and a Version Label field that chooses which version of that flow the entry point runs. Source: [Set up a channel](https://help.webex.com/en-us/article/ewuay1/Set-up-a-channel), Set up a channel > Entry point settings > Routing Flow; Version Label. Checked 2026-09-30.
[^97]: Dial numbers are mapped to entry points in Control Hub under Contact Center > Tenant Settings > Voice by selecting an available number or DN and the target entry point. Source: [Set up voice settings for Webex Contact Center](https://help.webex.com/en-us/article/gsmsaeb/Set-up-voice-settings-for-Webex-Contact-Center), Map dial numbers to entry points (Tenant Settings > Voice). Checked 2026-09-30.
[^98]: The tenant-wide default outdial ANI is set in Control Hub under Tenant Settings, Voice, and a dial number must be mapped to an entry point before it can be chosen as the default outdial ANI. Source: [Set up voice settings for Webex Contact Center](https://help.webex.com/en-us/article/gsmsaeb/Set-up-voice-settings-for-Webex-Contact-Center), section Default Outdial ANI. Checked 2026-09-24.
[^99]: A dial number must be mapped to an entry point to be available as the Default Outdial ANI. Source: [Set up voice settings for Webex Contact Center](https://help.webex.com/en-us/article/gsmsaeb/Set-up-voice-settings-for-Webex-Contact-Center), Set up voice settings > Default Outdial ANI. Checked 2026-09-30.
[^100]: By default, the first dial number mapped to an entry point is displayed as the Default Outdial ANI; if no dial number is mapped to an entry point, the field shows Not Configured. Source: [Set up voice settings for Webex Contact Center](https://help.webex.com/en-us/article/gsmsaeb/Set-up-voice-settings-for-Webex-Contact-Center), Set up voice settings > Default Outdial ANI. Checked 2026-09-30.
[^101]: By default the first dial number mapped to an entry point is shown as the default outdial ANI, and if no dial number is mapped to an entry point the field reads Not Configured. Source: [Set up voice settings for Webex Contact Center](https://help.webex.com/en-us/article/gsmsaeb/Set-up-voice-settings-for-Webex-Contact-Center), section Default Outdial ANI. Checked 2026-09-24.
[^102]: Outdial ANI lists are created in Control Hub under Services > Contact Center > Desktop Experience > Outdial ANI, by clicking Create Outdial ANI. Source: [Manage Outdial ANI](https://help.webex.com/en-us/article/nb8hvk3/Manage-Outdial-ANI), Manage Outdial ANI > Create an outdial ANI, step 1. Checked 2026-09-30.
[^103]: Numbers in an outdial ANI list must be dial numbers assigned to entry points; the contact number drop-down shows only dial numbers mapped to entry points. Source: [Manage Outdial ANI](https://help.webex.com/en-us/article/nb8hvk3/Manage-Outdial-ANI), Manage Outdial ANI > Create an outdial ANI > Contact Number. Checked 2026-09-30.
[^104]: Desktop profiles are created in Control Hub under Services > Contact Center > Desktop experience > Desktop profiles, by clicking Create desktop profile. Source: [Manage desktop profiles](https://help.webex.com/en-us/article/nvaf71f/Manage-desktop-profiles), Manage desktop profiles > Create a desktop profile. Checked 2026-09-30.
[^105]: The desktop profile's Outdial ANI field selects the outdial ANI list of phone numbers the agent can use as caller ID for outdial calls. Source: [Manage desktop profiles](https://help.webex.com/en-us/article/nvaf71f/Manage-desktop-profiles), Manage desktop profiles > Voice settings > Outdial ANI. Checked 2026-09-30.
[^106]: A dial number must be mapped to an entry point to be available as the default outdial ANI, and the Default Outdial ANI field shows Not Configured when the number is not mapped. Source: [Set up voice settings for Webex Contact Center](https://help.webex.com/en-us/article/gsmsaeb/Set-up-voice-settings-for-Webex-Contact-Center), Call Settings > Default Outdial ANI. Checked 2026-09-30.
[^107]: Webex Contact Center PSTN requirements specify RFC 2833 DTMF and a 20 ms packetization time in the SDP. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb/Set-Up-Voice-Channel-for-Webex-Contact-Center), PSTN Media and Signaling Requirements > DTMF; Packetization Timer in SIP SDP. Checked 2026-09-30.
[^108]: Agents can make outdial calls from the Available or Idle state but cannot start an outdial call while on an active inbound voice call. Source: [Make an outdial call](https://help.webex.com/en-us/article/nvxpcaf/Make-an-outdial-call), Make an outdial call > Before you begin / notes. Checked 2026-09-30.
[^109]: Outdial numbers are limited to a maximum of 18 digits. Source: [Make an outdial call](https://help.webex.com/en-us/article/nvxpcaf/Make-an-outdial-call), Make an outdial call > notes on number format. Checked 2026-09-30.
[^110]: Agents cannot outdial to extension numbers or to entry point numbers. Source: [Make an outdial call](https://help.webex.com/en-us/article/nvxpcaf/Make-an-outdial-call), Make an outdial call > notes on number format. Checked 2026-09-30.
[^111]: If an agent does not select a specific outdial ANI for an outdial call, the customer's caller ID shows the default outdial ANI dial number. Source: [Set up voice settings for Webex Contact Center](https://help.webex.com/en-us/article/gsmsaeb/Set-up-voice-settings-for-Webex-Contact-Center), Set up voice settings > Default Outdial ANI. Checked 2026-09-30.
[^112]: Calls reaching the Webex Contact Center media edge must use G.711uLaw or G.711aLaw. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb), PSTN Media and Signaling Requirements for Webex Contact Center. Checked 2026-09-16.
[^113]: Control Hub's Webex Calling call troubleshooting view shows calls from the past 21 days and includes PSTN legs through Cloud Connected PSTN and Local Gateway with trunk and route group details. Source: [Troubleshoot Webex Calling calls in Control Hub](https://help.webex.com/en-us/article/frj1efb/Troubleshoot-Webex-Calling-Media-Quality-in-Control-Hub), Troubleshoot calls > search and call legs. Checked 2026-09-30.
[^114]: A Webex Calling Local Gateway lets a customer retain their current on-premises PSTN carrier while providing access in over 140 markets globally, with third-party session border controllers supported alongside Cisco CUBE. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb), Connect to Webex Calling Services - PSTN Services - Webex Calling Local Gateway. Checked 2026-09-16.
[^115]: The Set up a channel article states that Webex Contact Center supports mapping only PSTN numbers in globalized +E.164 format to entry points and that extensions are not supported for this mapping (disputed). Source: [Set up a channel](https://help.webex.com/en-us/article/ewuay1/Set-up-a-channel), Set up a channel > inbound telephony entry point > Support Number step. Checked 2026-09-30.
[^116]: The Webex Calling based voice channel setup article states that an inbound entry point requires a Webex Calling location and a PSTN region, and can be populated with a PSTN number, an extension number, or both (disputed). Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb/Set-Up-Voice-Channel-for-Webex-Contact-Center), Configuration of Inbound Entry Points to Webex Contact Center. Checked 2026-09-30.
[^117]: Cisco Calling Plan is supported with Webex Contact Center only in regions where Webex Calling supports service numbers and for Webex Contact Center trials, with Cisco operating as the PSTN carrier in a single bill. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb), Connect to Webex Calling Services - PSTN Services - Cisco Webex Calling Plan. Checked 2026-09-16.
[^118]: SIP Delayed Offer is supported toward Webex Contact Center while SIP Early Offer and SIP Early Media are not supported and are described as roadmap items. Source: [Set up voice channels for Webex Contact Center](https://help.webex.com/en-us/article/nhy3codb), PSTN Media and Signaling Requirements for Webex Contact Center. Checked 2026-09-16.
