Source record · tier 2 current vendor documentation
BYOC-P or BYOP-P infrastructure requirements
- Publisher
- Zoom Communications
- URL
- https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0079203
- Published
- unknown
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Zoom proprietary; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- Zoom maintains a separate list of certified SBC vendors and models that have passed interoperability testing for BYOC-P/BYOP-P; the infrastructure requirements page links to it rather than listing them. in context
- BYOC-P and BYOP-P connections over the internet are protected with TLS 1.2 signalling and SRTP media. in context
- The SBC must present a certificate from one of Zoom's listed certificate authorities, with the SBC FQDN in the CN or SAN, the Server Authentication key usage, and the complete chain including intermediates. in context
- Zoom lists Opus, G.722, G.711 µ-law, G.711 A-law and G.729 as the codecs for BYOC-P/BYOP-P SBCs. in context
- BYOC-P/BYOP-P signalling uses TCP 5061 and media uses UDP 10000 to 64000, both bidirectional between the SBC and Zoom. in context
- Zoom requires a BYOC-P/BYOP-P SBC to support SIP per RFC 3261, DTMF per RFC 2833, topology hiding per RFC 5853, and early offer on INVITEs sent to Zoom. in context
- Zoom does not accept SDP offers or media streams that specify an SRTP Master Key Identifier (MKI). in context
- A BYOC SBC must present its complete certificate chain including intermediates and the certificate must have Server Authentication key usage. in context
- The public certificate on a BYOC SBC must carry the SBC FQDN in the certificate common name or subject alternative name. in context
- Zoom directs BYOC-P customers to use an SBC vendor and model from its certified SBC list which have undergone interoperability testing with Zoom. in context
- Zoom BYOC-P and BYOP-P support the Opus G.722 G.711 u-law G.711 A-law and G.729 audio codecs. in context
- Zoom requires DigiCert Global Root G2 and DigiCert X9 Financial PKI RSA 4096 Root to be installed in the BYOC SBC trust store. in context
- SIP Early Offer is mandatory for INVITEs that a BYOC-P or BYOP-P SBC sends to Zoom. in context
- Internet Security Research Group (Let's Encrypt) is on Zoom's list of supported certificate authorities for BYOC SBC certificates alongside DigiCert Sectigo GlobalSign and others. in context
- Zoom's highest-priority SRTP crypto suite for BYOC-P media is AEAD_AES_256_GCM followed by AES_256_CM_HMAC_SHA1_80 then AES_CM_128_HMAC_SHA1_80 then AES_CM_128_HMAC_SHA1_32. in context
- The media port range for Zoom BYOC-P and BYOP-P is UDP 10000-64000 which Zoom notes differs from its standard client range. in context
- Zoom does not accept SDP offers or media streams from a BYOC SBC that specify an SRTP Master Key Identifier (MKI). in context
- Zoom's highest-priority TLS cipher for BYOC-P signaling is TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384. in context
- Zoom BYOC-P and BYOP-P SIP signaling between Zoom and the customer SBC uses TCP port 5061. in context
- Zoom lists SIP per RFC 3261 and DTMF per RFC 2833 and topology hiding per RFC 5853 among BYOC-P SBC requirements. in context
- TLS 1.2 and SRTP are required for BYOC-P and BYOP-P when peering with Zoom over the Internet. in context
- BYOC-P signalling uses TCP/5061 and media uses UDP/10000-64000, a range that differs from standard Zoom client port ranges. in context
- Zoom's BYOC-P infrastructure article organises peering IPs by regional clusters including US01, UK01, EU01/EU02, CA01 and SA01. in context
- The BYOC-P SBC certificate must carry the SBC FQDN in the CN or SAN, come from an approved CA with Server Authentication key usage, and be presented with its full chain including intermediates. in context
- Zoom maintains a list of certified SBC vendors and models that have undergone interoperability testing for BYOC-P/BYOP-P. in context
- Zoom requires BYOC-P SBCs to support SIP (RFC 3261), DTMF per RFC 2833, topology hiding (RFC 5853) and SIP Early Offer on INVITEs sent to Zoom. in context
- Zoom's BYOC-P infrastructure requirements list Opus, G.722, G.711 mu-law, G.711 A-law and G.729 as required SBC codecs. in context
- Zoom's BYOC-P infrastructure presents DigiCert-issued certificates. in context
- BYOC-P/BYOP-P media between the SBC and Zoom uses UDP ports 10000-64000 in both directions. in context
- Zoom directs admins to Number Management > BYOC Configuration > Route Groups in the admin portal to confirm the account's cluster and the IPs and FQDNs to permit for the SBC. in context
- BYOC-P/BYOP-P signaling between the SBC and Zoom uses TCP/5061 in both directions for all listed Zoom clusters. in context
- Firewall rules for Zoom Phone clients (UDP 20000-64000) and for BYOC-P SBCs (UDP 10000-64000, TCP/5061 bidirectional) are different sets, so reusing the client rule for an SBC would leave part of the SBC media range and inbound signaling closed. inferred in context
Cite this source record
APA
WarmTransfer. (2026, September 24). BYOC-P or BYOP-P infrastructure requirements. WarmTransfer. https://warmtransfer.net/knowledge/sources/zoom-kb0079203-byoc-p-infrastructure-reqs
BibTeX
@misc{warmtransfer-zoom-kb0079203-byoc-p-infrastructure-reqs,
title = {BYOC-P or BYOP-P infrastructure requirements},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/zoom-kb0079203-byoc-p-infrastructure-reqs},
note = {Zoom Communications, accessed 2026-09-24}
}