Source record · tier 2 current vendor documentation
Port Reference Information for Webex Calling
- Publisher
- Cisco Systems, Inc. (help.webex.com)
- URL
- https://help.webex.com/article/b2exve/port-reference-information-for-cisco-webex-calling
- Published
- 2026-09-08
- Updated
- unknown
- Accessed
- 2026-09-16
- HTTP status
- 200
- License
- Cisco proprietary documentation, all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- Cisco's Webex Calling port reference marks Webex App audio with DSCP Expedited Forwarding (46), video with AF41 (34) and SIP signalling with CS0 (0). in context
- The Webex Calling port reference states that TCP and TLS as transport protocols for media are not supported for Webex Calling in production environments, while the Webex network requirements article describes Webex apps and Cisco Video devices falling back from UDP to TCP and then to TLS, so the same organisation's calling traffic and meeting traffic answer a blocked UDP range differently. field report in context
- The word TURN occurs 0 times in the Webex Calling port reference article and 0 times in the Webex Calling media optimization article, so no Cisco source the corpus holds names a relay candidate or a TURN server for Webex Calling even though both describe a media relay in the cloud that ICE removes. field report in context
- The Webex App uses media ports 8500-8599 for audio and 8600-8699 for video on Webex Calling. in context
- Webex Calling marks audio from the Webex App and from devices as DSCP 46 (Expedited Forwarding). in context
- Webex Calling marks device signaling as CS3 (DSCP 24) and Webex App signaling as CS0 (DSCP 0). in context
- Webex Calling marks video from the Webex App and from devices as DSCP 34 (AF41). in context
- Filtering Webex Calling traffic by IP address alone is not supported because some Webex IP address pools are dynamic and can change at any time. in context
- Cisco says to keep the default MTU of 1500 bytes for all IP packets carrying Webex Calling and Webex Aware services. in context
- For Webex Calling, organizations must assign enough public IP addresses to NAT pools to prevent port exhaustion. in context
- When a proxy is configured, only Webex Calling HTTP/HTTPS signaling goes to the proxy; SIP signaling and media do not. in context
- Cisco recommends turning off SIP ALG on routers and firewalls carrying Webex Calling traffic because some implementations break firewall traversal. in context
- For Webex Calling, both the Webex App and Webex devices mark audio with DSCP EF (46). in context
- In Webex Calling, the Webex App marks signaling CS0 (0) and Webex devices mark signaling CS3 (24). in context
- For Webex Calling, both the Webex App and Webex devices mark video with AF41 (34). in context
- For Webex Calling, Webex App audio uses source ports UDP 8500-8599 marked Expedited Forwarding (DSCP 46), and MPP phones and Room Series devices use UDP 19560-19661 for media. in context
- Cisco advises disabling SIP ALG on firewalls and NAT devices in the Webex Calling path, because some SIP ALG implementations break firewall traversal. in context
- The Local Gateway media port range is configurable with rtp-port range, and Webex Calling media from the LGW uses SRTP over UDP. in context
- Webex Calling uses SIP TLS port 8934 for registration-based Local Gateway trunks and port 5062 for certificate-based trunks. in context
- Where NAT or stateful packet inspection sits in the Webex Calling path, Cisco recommends a connection timeout of at least 30 minutes, and NAT or PAT must map overlapping source ports from multiple devices to unique translated ports. in context
- Webex Calling marks Webex App audio EF (46) and video AF41 (34) with signalling CS0. Webex devices (MPP and Room) mark signalling CS3 (24). in context
- Cisco recommends turning off SIP ALG, or similar SIP-aware functions, on routers and firewalls carrying Webex Calling traffic, because some ALG implementations cause firewall traversal problems. in context
- For a certificate-based Local Gateway, a firewall that allows outbound media but not Webex-initiated inbound SRTP to the Local Gateway's port range is a plausible cause of one-way audio. inferred in context
- Media flows initiated from Webex Calling toward a customer-chosen Local Gateway port range (UDP SRTP from source ports 19560-65535) apply only to certificate-based Local Gateways. in context
- Outbound SIP-TLS signaling from a Local Gateway to Webex Calling uses TCP destination port 8934 for registration-based trunks and 5062 for certificate-based trunks. in context
- Cisco recommends turning off SIP ALG on firewalls and NAT devices in the Webex Calling path. in context
- Cisco states that browsers use an ephemeral source port for Webex Calling media that can be controlled by setting the WebRtcUdpPortRange policy in a mobile device management profile, and that the Webex Calling service behaves normally if no such service is set. in context
- Outbound SRTP media from Local Gateways devices and Webex App clients to the Webex Calling cloud uses destination ports 5004, 9000, 8500 to 8699 and 19560 to 65535 over UDP, and media from Webex Calling to a certificate-based Local Gateway uses 19560 to 65535. in context
- Cisco states that where STUN and ICE negotiation succeeds for a call within the organisation the media relay in the cloud is removed from the communication path and media flows directly between the apps and devices, with the Webex App sending directly on 8500 to 8699 and devices sending directly to one another on 19560 to 19661. in context
- Cisco states that UDP is its preferred transport protocol for Webex Calling media and recommends using only SRTP over UDP, and that TCP and TLS as transport protocols for media are not supported for Webex Calling in production environments because their connection-oriented nature affects media quality over network loss. in context
- Cisco states that Webex Calling devices sharing a public address through NAT or PAT may use the same SIP signalling source port within the 5060 to 5280 range, that the NAT device must be able to translate overlapping source ports to unique translated ports, and that strict source-port preservation configurations can cause device registration failures. in context
- Cisco instructs administrators to validate the NAT pool size required for app and device connectivity and to assign adequate public addresses to prevent port exhaustion, stating that port exhaustion contributes to internal users and devices being unable to connect to the Webex Calling and Webex Aware services. in context
- Cisco states that Cisco phones send a follow-up REGISTER refresh every 1 to 2 minutes and that a network implementing NAT or stateful packet inspection should set a connection timeout of at least 30 minutes, which it says allows reliable connectivity while reducing the battery consumption of mobile devices. in context
- Cisco states that for network topologies using firewalls within a customer premise the administrator must allow the media source and destination port ranges inside the network for the media to flow, and gives the Webex App example of allowing audio 8500 to 8599 and video 8600 to 8699 as both source and destination. in context
- The Webex Calling media source port ranges differ by device class: devices use 19560 to 19661, Room Series devices use 52050 to 52099 for audio and 52200 to 52299 for video, VG400 analog telephone adapters use 19560 to 19849, and the Webex App uses 8500 to 8599 for audio and 8600 to 8699 for video. in context
- Cisco recommends turning off the SIP Application Layer Gateway or similar function on any SIP aware router or firewall, stating that although all Webex Calling traffic is encrypted certain SIP ALG implementations can cause issues with firewall traversal. in context
- The Webex Calling port reference revision history records that on 7 September 2026 the phone's source port range was expanded from 5060 to 5080 into 5060 to 5280 to accommodate an updated Cisco feature enabling support for up to 130 lines. in context
Cite this source record
APA
WarmTransfer. (2026, September 8). Port Reference Information for Webex Calling. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-help-b2exve-port-reference
BibTeX
@misc{warmtransfer-cisco-help-b2exve-port-reference,
title = {Port Reference Information for Webex Calling},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-help-b2exve-port-reference},
note = {Cisco Systems, Inc. (help.webex.com), accessed 2026-09-16}
}