# UC disaster recovery and business continuity

Canonical: https://warmtransfer.net/knowledge/uc-disaster-recovery

Last verified: 2026-09-25

Unified communications disaster recovery and business continuity strategies encompass on-premises survivability routers, cloud provider failover mechanisms, and backup restoration procedures[^53][^26][^4]. Across enterprise telephony architectures, contingency planning addresses service resilience during WAN disconnects, host failures, and carrier routing interruptions[^37][^32][^5].

## Webex Calling site survivability

Webex Calling Site Survivability uses a Cisco IOS XE router on the customer network, designated as the Survivability Gateway, to deliver fallback calling for on-site endpoints when connectivity to the Webex cloud fails[^53]. The Survivability Gateway takes over SIP registration for endpoints once connectivity to Webex has been interrupted for more than 30 seconds[^46]. Failback to the cloud occurs automatically after the connection has been restored for 30 seconds or more[^45].

The current Webex Calling Site Survivability documentation lists Cisco IOS XE Dublin 17.12.3 as the minimum release for a Survivability Gateway[^51]. WarmTransfer's reading of the sources is that because the IOS XE releases where the SRST guide states the Webex Survivability Gateway was introduced (17.9.x and 17.11.1a) sit below the 17.12.3 minimum in the current Webex help article, a new deployment should plan to the help article's floor rather than the introduction release[^47]. Hunt group, call forward, and auto attendant support on the Survivability Gateway requires IOS XE 17.18.2 or later[^48]. When active in survivability mode, hunt groups are limited to 100 groups with a maximum of 32 users per group[^49].

Supported Survivability Gateway platforms comprise the ISR 4000 series, Catalyst 8200 and 8300 Edge, and Catalyst 8000V, with endpoint capacities spanning 50 on an ISR 4321 up to 2,500 on a Catalyst 8300[^52]. The gateway supports IPv4 only, and Cisco recommends keeping latency across a multi-location LAN served by one gateway to no more than 50 ms[^50]. Survivability mode does not support three-way calling, conferencing, park, barge, pickup, remote line-state monitoring, or the calling dock[^54]. During survivability events, outbound emergency calls from endpoints use a registered ELIN for a defined ERL, and return calls to that ELIN route to the device that placed the emergency call most recently[^44].

A Local Gateway and a Survivability Gateway can be colocated on the same Cisco IOS XE device beginning in Dublin 17.12.3 using trusted CA certificates[^41]. High Availability is not supported for the Local Gateway when colocated with a Survivability Gateway, and colocation does not apply to third-party or partner-deployed Local Gateways[^42]. In normal operation on a colocated gateway, inbound PSTN calls route to Webex Calling, whereas in survivability mode inbound calls route directly to locally registered endpoints via dial-peers dynamically created from endpoint registrations[^43].

Webex Calling also provides a "forward calls if the network is disconnected" call forwarding setting that redirects calls when an office loses connectivity or a user is unreachable[^37]. Administrators configure this forwarding in Control Hub under Management > Users > (user) > Calling > Call handling > Call forwarding, and the option is also available for workspaces[^35]. Licensed Webex Calling users can also configure network-disconnected forwarding in User Hub under Settings > Calling > Call settings if enabled by an administrator[^38]. Destinations can be internal or external numbers, but the option to allow forwarded calls to leave voicemail can only be selected when targeting a valid internal number with voicemail[^39]. This forwarding behavior does not apply to the Webex App for mobile[^36]. WarmTransfer's reading of the sources is that network-disconnected forwarding and the Survivability Gateway address different failure scenarios: forwarding functions when a gateway or site is completely offline, whereas the Survivability Gateway requires an operable local router and LAN, meaning a complete site-loss plan relies on forwarding or carrier rerouting rather than survivability alone[^40].

## Cisco Unified SRST fallback

Under Cisco Unified SRST, IP phones that cease receiving keepalives from Unified CM register with the local SRST router, which activates automatically to build a local phone database[^8]. SRST fallback detection generally requires 3 times the keepalive period (which has a 30-second default), while phones that maintain a standby connection to SRST achieve fallback in roughly 10 to 20 seconds[^7].

While in SRST fallback, phones attempt reconnection to Unified CM periodically based on the Connection Monitor Duration default of 120 seconds, clearing their SRST registration automatically once the primary connection re-establishes[^10]. A phone actively engaged in a call during SRST fallback cannot re-establish its connection to the primary Unified CM until that call ends[^9]. Phone features including MeetMe, group pickup, park, and conference do not operate during SRST fallback, and SIP SRST excludes BLF speed-dial notification, call-forward-all synchronisation, directory services, and music on hold[^11].

## Microsoft Teams Direct Routing and SBA

Microsoft states that the core Teams service operates Active/Active across at least 2 geographically distant Azure regions per geography, dimensioned so a single region can sustain the full geography workload if an outage occurs[^29]. Microsoft states that it exercises failover operations regularly during load balancing and maintenance alongside incident recovery, with failover actions directed by the incident management team[^18].

For local site survivability, the Teams Survivable Branch Appliance (SBA) maintains PSTN calling for Direct Routing branches disconnected from the Microsoft cloud that retain network connectivity to their local SBC[^26]. Microsoft provides the SBA as distributable software to SBC vendors, who embed it into SBC firmware or supply it independently on hardware or VMs; the SBC requires a media bypass configuration[^28]. SBA mode supports only physical desktop installations of the Teams Windows and macOS clients and Teams Phones; VMs and web clients are unsupported[^21]. While operating in SBA mode, users can place and receive PSTN calls through the local SBC, hold, resume, perform blind transfers, forward calls to a single number or user, redirect auto attendant or call queue numbers to an alternative number or local agent, fall back from VoIP to PSTN, and place local VoIP calls[^25].

The presence of a UI banner is the only visual indication that a Teams client has transitioned into SBA mode; without the banner, the client has not engaged SBA mode and calling is unavailable[^19]. Clients re-engage standard cloud operation once internet connectivity returns and outgoing calls complete, prompting the SBA to upload collected call data records to the cloud[^24]. SBA deployments are configured strictly through PowerShell rather than the Teams admin center by defining the SBAs, building a branch survivability policy, assigning it to users, and registering a single Microsoft Entra ID application across all tenant SBAs[^22].

Operating constraints apply to SBA offline windows:
- Expired client tokens remain valid for up to 7 days, but clients restarting or requiring token renegotiation cannot connect, and clients must have connected to the target SBA within the preceding 24 hours to validate[^27].
- Tenants employing Continuous Access Evaluation (CAE) tokens experience SBA functionality for only around 30 minutes unless CAE is disabled tenant-wide[^20].
- While emergency calls can be made in SBA mode, caller location is not transmitted, and because the SBA bypasses Emergency Call Routing Policies and omits the plus sign from emergency dial strings, calls fail unless the standard voice routing policy includes an appropriate dial pattern[^23].
- Outside of SBA mode, Microsoft states that for Calling Plans users, offline Teams clients or devices lacking internet access cannot place emergency calls through Phone System[^17].

For cloud call routing, Teams Direct Routing voice routes permit designating SBCs as active or backup, diverting calls to backup SBCs if the active SBC fails[^13]. Listed SBCs within a single voice route are attempted in random order, as route priority controls the sequence between routes rather than individual SBCs within one route[^16]. If all SBCs across matching voice routes are unreachable, the call drops[^14]. In forwarded or transferred PSTN scenarios where the ingress SBC is also listed as an egress target, Teams bypasses priority rules to attempt that ingress SBC first[^15].

## Zoom Phone Local Survivability

Zoom Phone Local Survivability (ZPLS) is an on-premises virtual appliance running on VMware ESXi hosts that maintains calling between local site users when Zoom Phone data centers become unreachable[^58][^55]. ZPLS tracks cloud health using routine [SIP OPTIONS pings](https://warmtransfer.net/knowledge/sip-options-keepalive) and enters survivability mode only when both the ZPLS module and local client endpoints fail to reach the site's SIP zones[^59]. Endpoints register automatically to the appliance without requiring user or administrator intervention[^55].

Zoom estimates device failover to ZPLS at approximately 3 minutes based on device volume, with failback to standard cloud operation taking around 5 minutes after connectivity recovers[^56]. To retain external PSTN access during an outage, the deployment must integrate ZPLS with an SBC providing survivable PSTN access configured to route traffic to local ZPLS nodes rather than the cloud[^57]. Features unavailable during ZPLS survivability mode include voicemail, call pickup, Auto Receptionist, Call Queue, escalation to conferences with 4 or more parties, end-to-end encrypted calling, and nomadic e911[^60].

## Carrier and trunk failover mechanisms

Twilio Elastic SIP Trunking provides origination routing across up to 10 SIP URIs, selecting the lowest priority value first, failing over to higher values on session failure, and using weight values to distribute traffic across equal-priority URIs[^34]. When an origination target provides no SIP response, Twilio fails over to the subsequent URI after 4 seconds[^32]. If all listed origination URIs fail to accept a call, Twilio triggers the trunk's Disaster Recovery URL[^30]. The Disaster Recovery URL executes a TwiML application capable of playing announcements, recording voicemail, redirecting to secondary numbers, or running IVR functions, and redirected calls are billed under standard Twilio Voice rates[^30][^31]. For Programmable Voice fallback webhook URLs, Twilio recommends pointing destinations to an alternate cloud provider, region, or availability zone relative to the primary URL[^33].

## CUCM Disaster Recovery System

Cisco Unified Communications Manager (CUCM) includes the Disaster Recovery System (DRS) for scheduled, encrypted cluster-level backups written to SFTP servers, supporting up to 10 distinct backup schedules that Cisco recommends executing during off-peak windows[^3]. Cisco tests DRS against the SFTP implementation on Prime Collaboration Deployment (PCD)[^3]. Backups use encryption keys tied to the cluster security password, leading Cisco to recommend generating a new backup whenever that security password changes[^2].

Restoration requires strict environment matching:
- DRS restores exclusively to the identical software version as the backup archive, requiring every node in the cluster to run that target release[^4].
- DRS cannot restore onto differing hostnames, IP addresses, DNS parameters, or deployment models, and cannot execute data migrations across different platforms[^1].

See also [Unified CM backup and upgrade](https://warmtransfer.net/knowledge/cucm-backup-upgrade).

## Contingency planning frameworks

NIST SP 800-34 Rev. 1 gives guidelines for information system contingency plans, covering their relationship to security and emergency management plans, organizational resilience and the system development life cycle[^5]. The original May 2010 printing of NIST SP 800-34 Rev. 1 was withdrawn on 2010-11-11 and superseded by SP 800-34 Rev. 1 with updates through that date, which remains NIST's contingency planning guide for federal information systems[^6].

## See also

- [CUBE high availability](https://warmtransfer.net/knowledge/cube-high-availability)
- [SIP OPTIONS pings and trunk keepalives](https://warmtransfer.net/knowledge/sip-options-keepalive)
- [Unified CM backup and upgrade](https://warmtransfer.net/knowledge/cucm-backup-upgrade)

## Applicability

The current Webex Calling Site Survivability article lists Cisco IOS XE Dublin 17.12.3 as the minimum release for a Survivability Gateway, while hunt group, call forward, and auto attendant support requires IOS XE 17.18.2 or later[^51][^48]. Under Unified SRST, IP phones that stop receiving keepalives from Unified CM register with the local SRST router, which activates automatically and builds a local database of the phones[^8]. CUCM Disaster Recovery System restores only to the same software version as the backup, and all cluster nodes must run that version[^4]. The original May 2010 printing of NIST SP 800-34 Rev. 1 was withdrawn on 2010-11-11 and superseded by SP 800-34 Rev. 1 with updates through that date, which remains NIST's contingency planning guide for federal information systems[^6]. NIST SP 800-34 Rev. 1 gives guidelines for information system contingency plans, covering their relationship to security and emergency management plans, organizational resilience and the system development life cycle[^5].

## What remains uncertain

Hardware host failure recovery times for virtualized SBA appliances are not covered by the sources below. Disaster recovery procedures for Microsoft Teams Calling Plans when regional Azure outages occur are not covered by the sources below. Failover behavior for Zoom Phone endpoints when ESXi host hardware fails during an active survivability event is not covered by the sources below.

## Sources

[^1]: CUCM DRS does not restore across different hostnames, IP addresses, DNS configurations or deployment types, and cannot migrate data between platforms. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Restore the System](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_m_restore-the-system.html), Restore prerequisites; Restore overview. Checked 2026-09-25.
[^2]: Cisco recommends running a new CUCM DRS backup whenever the cluster security password changes, because backups are encrypted with a key tied to that password. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Back Up the System](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_m_back-up-the-system-14.html), Backup overview, encryption note. Checked 2026-09-25.
[^3]: CUCM DRS writes encrypted cluster-level backups to SFTP servers (Cisco tests the SFTP server on Prime Collaboration Deployment), supports up to 10 backup schedules, and Cisco advises scheduling them off-peak. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Back Up the System](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_m_back-up-the-system-14.html), Backup prerequisites; Configure scheduled backups. Checked 2026-09-25.
[^4]: CUCM Disaster Recovery System restores only to the same software version as the backup, and all cluster nodes must run that version. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Restore the System](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_m_restore-the-system.html), Restore prerequisites. Checked 2026-09-25.
[^5]: NIST SP 800-34 Rev. 1 gives guidelines for information system contingency plans, covering their relationship to security and emergency management plans, organizational resilience and the system development life cycle. Source: [Contingency Planning Guide for Federal Information Systems \[including updates through 11/11/2010\]](https://www.nist.gov/publications/contingency-planning-guide-federal-information-systems-including-updates-through), Abstract. Checked 2026-09-25.
[^6]: The original May 2010 printing of NIST SP 800-34 Rev. 1 was withdrawn on 2010-11-11 and superseded by SP 800-34 Rev. 1 with updates through that date, which remains NIST's contingency planning guide for federal information systems. Source: [NIST SP 800-34 Rev. 1 (Withdrawn), Contingency Planning Guide for Federal Information Systems](https://csrc.nist.gov/pubs/sp/800/34/r1/final), CSRC publication record, status and superseded-by fields. Checked 2026-09-25.
[^7]: SRST fallback detection typically takes three times the keepalive period (30-second default), while phones holding a standby connection to SRST fall back in about 10 to 20 seconds. Source: [Cisco Unified SRST Administration Guide (All Versions) - Cisco Unified SRST Feature Overview](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cusrst/admin/sccp_sip_srst/configuration/guide/SCCP_and_SIP_SRST_Admin_Guide/srst_overview.html), Feature overview, fallback timing. Checked 2026-09-25.
[^8]: Under Unified SRST, IP phones that stop receiving keepalives from Unified CM register with the local SRST router, which activates automatically and builds a local database of the phones. Source: [Cisco Unified SRST Administration Guide (All Versions) - Cisco Unified SRST Feature Overview](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cusrst/admin/sccp_sip_srst/configuration/guide/SCCP_and_SIP_SRST_Admin_Guide/srst_overview.html), Feature overview, how SRST works. Checked 2026-09-25.
[^9]: A phone in SRST fallback cannot re-establish its connection to the primary Unified CM while it is on an active call. Source: [Cisco Unified SRST Administration Guide (All Versions) - Cisco Unified SRST Feature Overview](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cusrst/admin/sccp_sip_srst/configuration/guide/SCCP_and_SIP_SRST_Admin_Guide/srst_overview.html), Feature overview, returning to Unified CM. Checked 2026-09-25.
[^10]: In SRST mode, phones periodically try to reconnect to Unified CM, by default every 120 seconds (Connection Monitor Duration), and cancel their SRST registration automatically once reconnected. Source: [Cisco Unified SRST Administration Guide (All Versions) - Cisco Unified SRST Feature Overview](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cusrst/admin/sccp_sip_srst/configuration/guide/SCCP_and_SIP_SRST_Admin_Guide/srst_overview.html), Feature overview, returning to Unified CM. Checked 2026-09-25.
[^11]: In SRST fallback, MeetMe, group pickup, park and conference are unavailable on the phone, and SIP SRST does not support BLF speed-dial notification, call-forward-all synchronisation, directory services or music on hold. Source: [Cisco Unified SRST Administration Guide (All Versions) - Cisco Unified SRST Feature Overview](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cusrst/admin/sccp_sip_srst/configuration/guide/SCCP_and_SIP_SRST_Admin_Guide/srst_overview.html), Feature overview, restrictions and phone functions in SRST. Checked 2026-09-25.
[^12]: The Unified SRST feature roadmap places Webex Survivability Gateway support in SRST 14.3, introduced in IOS XE Cupertino 17.9.1a and Dublin 17.11.1a (disputed). Source: [Cisco Unified SRST Administration Guide (All Versions) - Cisco Unified Survivable Remote Site Telephony Feature Roadmap](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cusrst/admin/sccp_sip_srst/configuration/guide/SCCP_and_SIP_SRST_Admin_Guide/srst_roadmap.html), Feature roadmap table, row 'Webex Survivability Gateway'. Checked 2026-09-25.
[^13]: Teams Direct Routing voice routes can designate SBCs as active and backup; when the active SBC is unavailable for a route the call goes to a backup SBC. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Call routing overview. Checked 2026-09-25.
[^14]: If no SBC in any matching Direct Routing voice route is available, the call is dropped, unless the user also has a Calling Plan licence, which applies automatically as the last route. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 1 call flows and following Note. Checked 2026-09-25.
[^15]: For a forwarded or transferred inbound PSTN call, if the ingress SBC is also a candidate egress SBC, Teams ignores its priority and tries it first. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 1, Note following the summary table. Checked 2026-09-25.
[^16]: Within one Direct Routing voice route, the listed SBCs are tried in random order; route priority orders routes, not SBCs within a route. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 1: Voice routing with one PSTN usage. Checked 2026-09-25.
[^17]: Microsoft states that when a user's Teams client is offline or the device cannot reach the internet, for example in a network or power outage, emergency calls through Phone System are not supported and are not expected to work. Source: [Emergency calling terms and conditions - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/emergency-calling-terms-and-conditions), IMPORTANT INFORMATION, item (ii). Checked 2026-09-25.
[^18]: Microsoft says it uses Teams failover operations routinely for load balancing and maintenance as well as incident recovery, so the procedures are exercised regularly, with failover decisions made by the incident management team. Source: [Service resilience in Microsoft Teams - Microsoft Service Assurance](https://learn.microsoft.com/en-us/compliance/assurance/assurance-service-resilience-microsoft-teams), Failover. Checked 2026-09-25.
[^19]: The only UI sign that a Teams client has switched to SBA (Appliance) mode is a banner; if the banner is absent the user is not in SBA mode and calling will not work. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), How it works, Connection to the SBA on the Teams Client Side. Checked 2026-09-25.
[^20]: If the tenant uses Continuous Access Evaluation tokens, the SBA works for only about 30 minutes; Microsoft suggests disabling CAE for the tenant as an alternative. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), Known issues and considerations. Checked 2026-09-25.
[^21]: SBA mode works only on the Teams Windows and macOS desktop clients on physical machines and on Teams Phones; VMs and web clients are not supported. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), Supported Teams clients; How it works. Checked 2026-09-25.
[^22]: SBA configuration is PowerShell-only (not in the Teams admin center): create the SBAs, create a branch survivability policy, assign it to users, and register one Microsoft Entra ID application for all the tenant's SBAs. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), Configuration. Checked 2026-09-25.
[^23]: In SBA mode, emergency calls can be placed but location is not shared, and the SBA ignores Emergency Call Routing Policies and sends emergency dial strings without a plus sign, so emergency calls fail unless the regular voice routing policy has a matching pattern. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), Known issues and considerations, 'In SBA mode, the following user actions aren't supported'. Checked 2026-09-25.
[^24]: A Teams client returns from SBA mode to normal operation once it detects the internet is back and any outgoing calls have finished, and the SBA then uploads collected call data records to the cloud. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), How it works. Checked 2026-09-25.
[^25]: In SBA mode Teams clients can make and receive PSTN calls through the local SBC, hold and resume, blind transfer, forward to a single number or Teams user, redirect call queue or auto attendant numbers to a local agent or alternative number, use VoIP fallback to PSTN, and call local users over VoIP. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), How it works (offline-mode functionality list). Checked 2026-09-25.
[^26]: The Teams Survivable Branch Appliance keeps PSTN calling working at a Direct Routing branch that has lost connectivity to the Microsoft cloud but can still reach its SBC over the local network. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), Introduction. Checked 2026-09-25.
[^27]: In SBA mode, expired client tokens are accepted for up to 7 days, but a client that restarts or has to negotiate a new token cannot connect, and a client cannot validate against an SBA it has not connected to in the last 24 hours. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), Known issues and considerations. Checked 2026-09-25.
[^28]: Microsoft supplies the SBA as distributable code to SBC vendors, who embed it in SBC firmware or ship it separately to run on a VM or hardware; the SBC must be configured for media bypass. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), Prerequisites. Checked 2026-09-25.
[^29]: Microsoft states that the Teams service runs Active/Active across at least two geographically distant Azure regions per geography, sized so that one region can carry the geography's full load if the other is unavailable. Source: [Service resilience in Microsoft Teams - Microsoft Service Assurance](https://learn.microsoft.com/en-us/compliance/assurance/assurance-service-resilience-microsoft-teams), Service configuration. Checked 2026-09-25.
[^30]: When a call cannot be delivered to any origination SIP URI, Twilio invokes the trunk's Disaster Recovery URL, a TwiML application that can play a message, take voicemail, redirect to another number or replicate PBX functions such as an IVR. Source: [Elastic SIP Trunking](https://www.twilio.com/docs/sip-trunking), Origination settings, Disaster Recovery URL. Checked 2026-09-25.
[^31]: Calls redirected to a Twilio Elastic SIP Trunking Disaster Recovery URL are billed at normal Twilio Voice rates. Source: [Elastic SIP Trunking](https://www.twilio.com/docs/sip-trunking), Origination settings, Disaster Recovery URL. Checked 2026-09-25.
[^32]: If an origination SIP server gives no SIP response, Twilio fails over to the next URI after 4 seconds. Source: [Elastic SIP Trunking](https://www.twilio.com/docs/sip-trunking), Origination settings. Checked 2026-09-25.
[^33]: Twilio recommends that a voice fallback webhook URL point to a different availability zone, region or cloud provider from the primary URL. Source: [Programmable Voice Failover Best Practices](https://www.twilio.com/docs/voice/twilio-voice-failover-best-practices), Fallback URL section. Checked 2026-09-25.
[^34]: A Twilio Elastic SIP Trunk can have up to 10 origination SIP URIs; Twilio uses the lowest priority value first, falls back to higher values if the session fails, and uses weight to share load among URIs of equal priority. Source: [Elastic SIP Trunking](https://www.twilio.com/docs/sip-trunking), Origination settings. Checked 2026-09-25.
[^35]: Administrators configure network-disconnected forwarding in Control Hub under Management > Users > (user) > Calling > Call handling > Call forwarding; it is also available for workspaces. Source: [Configure call forwarding for users and workspaces](https://help.webex.com/en-us/article/nkw9o41/Configure-call-forwarding-for-users-and-workspaces), Configure call forwarding (procedure steps). Checked 2026-09-25.
[^36]: Webex Calling network-disconnected forwarding does not apply to the Webex App for mobile. Source: [Configure call forwarding for users and workspaces](https://help.webex.com/en-us/article/nkw9o41/Configure-call-forwarding-for-users-and-workspaces), Forward calls if the network is disconnected, note. Checked 2026-09-25.
[^37]: Webex Calling call forwarding has a 'forward calls if the network is disconnected' option that forwards calls when the user is unreachable or the office loses connectivity. Source: [Configure call forwarding for users and workspaces](https://help.webex.com/en-us/article/nkw9o41/Configure-call-forwarding-for-users-and-workspaces), Call forwarding options, 'Forward calls if the network is disconnected'. Checked 2026-09-25.
[^38]: Users with a Webex Calling licence can set network-disconnected forwarding themselves in User Hub under Settings > Calling > Call settings, once an administrator has enabled the feature. Source: [Forward your phone calls](https://help.webex.com/en-US/article/ned5dhu/Calling-User-Portal-%7C-Set-Up-Your-Business-Continuity-Phone-Number), Call forwarding section, network disconnected option. Checked 2026-09-25.
[^39]: Network-disconnected forwarding can target an internal or external number, and 'allow forwarded calls to leave voicemail' is selectable only when the target is a valid internal number with voicemail. Source: [Configure call forwarding for users and workspaces](https://help.webex.com/en-us/article/nkw9o41/Configure-call-forwarding-for-users-and-workspaces), Forward calls if the network is disconnected, voicemail option. Checked 2026-09-25.
[^40]: Network-disconnected forwarding and the Survivability Gateway address different failures: forwarding helps when the whole site or its gateway is down, while the Survivability Gateway needs a working local router and LAN, so a site-loss runbook needs forwarding or carrier rerouting rather than survivability alone (inferred). Source: [Configure call forwarding for users and workspaces](https://help.webex.com/en-us/article/nkw9o41/Configure-call-forwarding-for-users-and-workspaces), Forward calls if the network is disconnected; read with Site Survivability Introduction. Checked 2026-09-25.
[^41]: Webex Calling allows a Local Gateway and a Survivability Gateway to run on the same Cisco IOS XE device from Dublin 17.12.3, using certificates from a trusted CA. Source: [Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways](https://help.webex.com/en-us/article/w0qmeu/Colocation-of-Local-Gateway-and-Site-Survivability-on-Cisco-IOS-Managed-Gateways), Prerequisites. Checked 2026-09-25.
[^42]: High Availability is not supported for the Local Gateway when it is colocated with a Survivability Gateway, and colocation does not apply to third-party or partner-deployed Local Gateways. Source: [Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways](https://help.webex.com/en-us/article/w0qmeu/Colocation-of-Local-Gateway-and-Site-Survivability-on-Cisco-IOS-Managed-Gateways), Limitations and restrictions. Checked 2026-09-25.
[^43]: On a colocated gateway, inbound PSTN calls route to Webex Calling in normal mode, and in survivability mode they route to locally registered endpoints through dial-peers created dynamically from endpoint registrations. Source: [Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways](https://help.webex.com/en-us/article/w0qmeu/Colocation-of-Local-Gateway-and-Site-Survivability-on-Cisco-IOS-Managed-Gateways), Call routing considerations for colocation. Checked 2026-09-25.
[^44]: During survivability, outbound emergency calls from Webex Calling endpoints use a registered ELIN for a defined ERL, and callbacks to that ELIN are directed to the last device that called the emergency number. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Feature Configuration (emergency calling). Checked 2026-09-25.
[^45]: Failback from the Webex Calling Survivability Gateway to the cloud is automatic once the Webex connection has been restored for 30 seconds or more. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), User Experience During Failover. Checked 2026-09-25.
[^46]: The Webex Calling Survivability Gateway takes over SIP registration for endpoints when the connection to Webex has been broken for more than 30 seconds. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Introduction; User Experience During Failover. Checked 2026-09-25.
[^47]: The IOS XE releases where the SRST guide says the Webex Survivability Gateway was introduced (17.9.x and 17.11.1a) sit below the 17.12.3 minimum in the current Webex help article, so a new deployment should plan to the help article's floor rather than the introduction release (inferred). Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Deployment Considerations, compared with SRST roadmap row 'Webex Survivability Gateway'. Checked 2026-09-25.
[^48]: Hunt group, call forward and auto attendant support on the Webex Calling Survivability Gateway requires IOS XE 17.18.2 or later. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Deployment Considerations (supported software). Checked 2026-09-25.
[^49]: In Webex Calling survivability mode, hunt groups are limited to 100 groups with at most 32 users per group. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Limitations and Restrictions. Checked 2026-09-25.
[^50]: The Webex Calling Survivability Gateway supports IPv4 only, and Cisco recommends no more than 50 ms latency across a multi-location LAN served by one gateway. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Limitations and Restrictions. Checked 2026-09-25.
[^51]: The current Webex Calling Site Survivability article lists Cisco IOS XE Dublin 17.12.3 as the minimum release for a Survivability Gateway. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Deployment Considerations (supported software). Checked 2026-09-25.
[^52]: Supported Survivability Gateway platforms are ISR 4000 series, Catalyst 8200 and 8300 Edge and Catalyst 8000V; endpoint capacity ranges from 50 on an ISR 4321 to 2,500 on a Catalyst 8300. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Deployment Considerations (supported platforms and scale table). Checked 2026-09-25.
[^53]: Webex Calling Site Survivability uses a Cisco IOS XE router on the customer network, called the Survivability Gateway, to provide fallback calling to on-site endpoints when connectivity to the Webex cloud is lost. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Introduction and Deployment Considerations. Checked 2026-09-25.
[^54]: Webex Calling survivability mode does not support three-way calling, conferencing, park, barge, pickup, remote line-state monitoring or the calling dock. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Supported Features and Components; Limitations and Restrictions. Checked 2026-09-25.
[^55]: ZPLS is a Linux-based appliance deployed on VMware ESXi hosts, and clients register to it automatically without administrator or user action when the data centers are unreachable. Source: [Getting started with Zoom Phone Local Survivability service](https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0058798), Overview. Checked 2026-09-25.
[^56]: Zoom puts device failover to a ZPLS module at about three minutes, depending on device count, and the return to normal operation at about five minutes after cloud connectivity is restored. Source: [Zoom Phone Local Survivability Field Guide - Overview](https://library.zoom.com/zoom-workplace/zoom-phone/zoom-phone-local-survivability-field-guide/overview), Overview, failover timeline. Checked 2026-09-25.
[^57]: For PSTN calling during a ZPLS survivability event, the customer must integrate ZPLS with an SBC that has survivable PSTN connectivity and routes calls locally to the ZPLS nodes instead of the cloud. Source: [Getting started with Zoom Phone Local Survivability service](https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0058798), Supported features, Inbound / Outbound PSTN. Checked 2026-09-25.
[^58]: Zoom Phone Local Survivability (ZPLS) is an on-premises virtual appliance that supports calls between users at a common site when Zoom Phone data centers are unreachable. Source: [Zoom Phone Local Survivability Field Guide - Overview](https://library.zoom.com/zoom-workplace/zoom-phone/zoom-phone-local-survivability-field-guide/overview), Overview. Checked 2026-09-25.
[^59]: ZPLS monitors cloud availability with routine SIP OPTIONS pings and enters survivability mode only when both the module and the client devices cannot reach the site's SIP zones. Source: [Zoom Phone Local Survivability Field Guide - Overview](https://library.zoom.com/zoom-workplace/zoom-phone/zoom-phone-local-survivability-field-guide/overview), Overview, survivability mode triggers. Checked 2026-09-25.
[^60]: The ZPLS field guide lists voicemail, call pickup, Auto Receptionist, Call Queue, escalation to a 4+ party conference, end-to-end encrypted calling and nomadic e911 as unavailable in survivability mode. Source: [Zoom Phone Local Survivability Field Guide - Overview](https://library.zoom.com/zoom-workplace/zoom-phone/zoom-phone-local-survivability-field-guide/overview), Overview, unsupported features. Checked 2026-09-25.
