# Troubleshooting Webex Calling survivability failover

Canonical: https://warmtransfer.net/knowledge/webex-calling-survivability-troubleshooting

Last verified: 2026-09-30

Webex Calling endpoints normally operate in Active mode registered to the Webex cloud, switching automatically to Survivability mode on a local Survivability Gateway when the connection to Webex breaks[^2]. Registration and call control revert to the cloud once the network connection has resumed for at least 30 seconds[^22].

## How failover works

The Webex cloud provisions the Survivability Gateway IP address, hostname, and port directly into each endpoint's device configuration file, enabling the endpoint to locate the gateway during an outage[^44]. The gateway listens for incoming secure TLS connections from endpoints on port 8933 once `mode webex-sgw` is configured under `voice register global`[^46]. Call data, including user authentication records needed for endpoints to register securely in Survivability mode, syncs daily from the Webex cloud to the gateway[^14].

To enable registration, the gateway must use an IPv4 address, as IPv6 is not supported[^28]. In addition, configuring the `sip bind` command in `voice service voip` configuration mode causes endpoint registration to the gateway to fail[^40].

## Gateway requirements and certificate validation

* **Platform software:** Survivability Gateway features require Cisco IOS XE Dublin 17.12.3 or later[^34]. Webex Calling deprecated the RSAES-PKCS1-v1_5 encryption scheme on September 1, 2024, requiring gateways to upgrade to Dublin 17.12.3 before that date[^51].
* **Licensing:** Cisco ISR 4000 series routers require the `uck9` and `securityk9` technology licenses (`license boot level uck9` and `license boot level securityk9`)[^29]. Catalyst 8300 and 8200 series platforms require a DNA Network Advantage feature license or higher, along with a configured crypto throughput setting sized for call volume (such as `platform hardware throughput crypto 25M`)[^4].
* **Certificate requirements:** Gateway certificates must be signed by a publicly known certificate authority; private or enterprise CAs and wildcard certificates are not supported[^49][^43]. The certificate key requires an RSA private key of at least 2048 bits[^50]. The fully qualified domain name on the certificate must match the host name entered when assigning the survivability service in Control Hub[^25].
* **TLS parameters:** The documented `sip-ua` configuration sets `transport tcp tls v1.2` and `crypto signaling default trustpoint webex-sgw`, tying the TLS handshake with endpoints to the `webex-sgw` trustpoint[^59]. TLS 1.3 is not supported for Webex Survivability Gateway mode[^42]. Administrators can verify whether the required root CA is installed by executing `show crypto pki trustpool | include cn=`, and any root CA missing from the Cisco bundle must be imported manually[^60].

## Cloud connectivity and enrollment troubleshooting

Enrollment to the Webex cloud is a prerequisite for the Survivability Gateway service, but it cannot be used on Cisco 1100 Integrated Services Router platforms, gateways configured in High Availability mode, or gateways in Controller mode for SD-WAN[^20].

* **Network prerequisites:** Gateways require an NTP source and a public DNS server (`ip name-server`)[^19]. The connector IP address must reside in the same network as the external connectivity interface and requires outbound HTTPS over TLS 1.2 to `*.ucmgmt.cisco.com`, `*.webex.com`, and `*.wbx2.com`[^21]. Because IOS XE uses proxy ARP to route traffic to the guest shell hosting the connector, `no ip proxy-arp` must not be configured on the gateway[^47].
* **Credentials:** Special characters such as `$`, `!`, or `-` in gateway credential passwords can prevent sign-in to the connector interface and disrupt deployment[^12].
* **Connector alarms and states:** In Control Hub, the connector status displays as Online, Offline, or Paused[^13]. The local management connector web page (`https://<connector-ip-address>`) or the onboarding TCL script status option reports the running connector as Connected, Not Connected, Heartbeat Failed, or Enrollment Failed[^33]. A NETCONF connection failure alarm is resolved by ensuring NETCONF is enabled and reachable from the connector, while a NETCONF authentication failure indicates mismatched gateway credentials[^37].
* **Diagnostic logs:** Connector logs are gathered by running the onboarding TCL script, selecting the Collect Logs option, and retrieving the log file from `bootflash:/guest-share/`[^11].
* **Synchronization timing:** On-demand sync is initiated in Control Hub under Services > PSTN & Routing > Gateway configurations > Manage Gateways by selecting the gateway and clicking Sync[^58]. On-demand sync can take up to 10 minutes to run, while the status displayed in Control Hub may take up to 30 minutes to update; a delay does not indicate sync failure[^57][^56].

## Feature behavior and topology limits

| Feature / Limit | Survivability Mode Behavior |
| --- | --- |
| Intrasite extension calling | Routes automatically between registered endpoints without special routing configuration[^48] |
| Intersite and PSTN calling | Requires a local PSTN circuit or SIP trunk configured on the gateway[^48] |
| Dialing patterns | Can function differently than in Active mode[^15] |
| Hunt groups & Auto Attendant | Requires IOS XE 17.18.2 or later; limited to 100 hunt groups with 32 users per group, with no weighted routing[^26][^27] |
| Conferencing & softkeys | 3-way calling and conferencing are unsupported; Park, Unpark, Barge, Pickup, Group Pickup, Call Pull, and shared-line remote state monitoring are unsupported[^39][^41] |
| Multi-location campus | A single gateway can map to multiple campus locations (supported since October 22, 2025)[^36] |
| Latency recommendation | Cisco recommends keeping latency between the gateway and endpoints within a 50 millisecond threshold[^30] |
| Dual-connected devices | Devices on 4G or 5G (such as the Webex App) may stay registered to Webex Calling and fail to reach site numbers failed over to the gateway[^35] |

### Emergency calling (E911)

In Survivability mode, E911 calling requires a local PSTN circuit or SIP trunk[^16]. Calls present an Emergency Location Identification Number (ELIN) assigned to an Emergency Response Location defined on the gateway[^16]. If a Wi-Fi overlay does not align accurately with IP subnets, emergency calls from nomadic endpoints may receive an incorrect ELIN mapping during survivability[^17].

### Colocated and SRST deployments

* **Colocation with Local Gateway:** A router hosting both Local Gateway and Survivability Gateway must be provisioned in Control Hub as a Survivability Gateway service[^10]. In this setup, High Availability and Control Hub configuration validation are unsupported for the Local Gateway[^8], and Basic Automatic Call Distribution (B-ACD) cannot be used[^7]. Colocated call routing uses dial-peer preferences: preference 0 for local registered endpoints, preference 2 for Webex Calling, and preference 3 for the PSTN[^9]. Colocation configurations also require dedicated dial-peers for survivability emergency calls[^6]. Gateway capacity is set using `max-dn` and `max-pool` under `voice register global`[^31].
* **Colocation with Unified SRST:** When Webex Survivability and Cisco Unified SRST share a gateway, an isolated failure can leave one group of devices on the gateway and another on primary call control, requiring PSTN or SIP trunk routing between them[^52]. Diagnostic commands for SIP SRST include `show sip-ua status registrar`, `show voice register pool all`, and `show voice register dial-peers`[^53].
* **Dedicated Instance distinction:** Enhanced Survivability applies only to Webex Calling Dedicated Instance sites and is an entirely distinct feature from the multi-tenant Survivability Gateway[^18].

## See also

* [Webex Calling Site Survivability Gateway](https://warmtransfer.net/knowledge/webex-calling-survivability-gateway)
* [Webex Calling architecture and deployment models](https://warmtransfer.net/knowledge/webex-calling-architecture)
* [Webex Calling Dedicated Instance applicability](https://warmtransfer.net/knowledge/webex-calling-dedicated-instance)
* [Webex Calling PSTN options and selection](https://warmtransfer.net/knowledge/webex-calling-pstn-options)
* [Webex Calling locations and number management](https://warmtransfer.net/knowledge/webex-calling-locations-numbers)

## Applicability

Applies to: Cisco Webex Calling Site Survivability, Cisco Unified SRST on IOS XE, Cisco Webex Calling managed gateways, and Cisco Webex Calling Dedicated Instance. Deployments: multi-tenant, dedicated instance, and on-premises-gateway. Sources checked 2026-09-30. Survivability Gateway features require Cisco IOS XE Dublin 17.12.3 or later[^34]. Hunt groups, call forward, and auto attendant survivability functions require IOS XE 17.18.2 or later[^26]. E911 ELIN configuration applies to the United States region[^16][^17]. Enhanced Survivability applies specifically to Webex Calling Dedicated Instance rather than multi-tenant deployments[^18].

## What remains uncertain

The failover detection timer and the duration required for an endpoint to register on the Survivability Gateway are not covered by the sources below. Endpoint behavior and specific user-facing symptoms when a gateway certificate is expired or mismatched are not covered by the sources below. Gateway symptoms when technology licenses (such as `uck9` or `securityk9`) are missing or throughput limits are exceeded are not covered by the sources below. Vendor statements regarding call preservation during failover and failback are not covered by the sources below. How MPP phones and the Webex App indicate Survivability mode to end users is not covered by the sources below. The remainder of the Webex Managed Gateway Command Reference, including `webex-sgw` show and sync operational commands, is not covered by the sources below. Enhanced Survivability troubleshooting procedures for Webex Calling Dedicated Instance are not covered by the sources below. The minimum IOS XE release required for Local Gateway within the enrollment article is not covered by the sources below.

## Sources

[^1]: The supported endpoint list for Survivability mode names the Webex App on Windows and Mac (43.2 or later); mobile and tablet apps appear only in the limitation about 4G and 5G devices. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Supported features and components: supported endpoints table. Checked 2026-09-30.
[^2]: Endpoints normally run in Active mode registered to the Webex cloud; when the network connection to Webex breaks they switch automatically to Survivability mode and register with the local Survivability Gateway. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Overview: how it works. Checked 2026-09-30.
[^3]: A Verizon republication of the Site Survivability article says calls are not preserved during fallback to the Survivability Gateway but are preserved when connectivity to the cloud service is re-established (field report). Source: [Site Survivability for Webex Calling | Verizon](https://webexcallingtraining.verizon.com/site-survivability-for-webex-calling/), Limitations and restrictions (call preservation sentence). Checked 2026-09-30.
[^4]: On Catalyst 8300 and 8200 series platforms the prerequisites call for a DNA Network Advantage feature licence or better plus a crypto throughput setting sized for call volume (example: platform hardware throughput crypto 25M). Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Configure Survivability Gateway: licences step, Catalyst 8300/8200. Checked 2026-09-30.
[^5]: The article uses show crypto pki certificates webex-sgw | begin CA Cert to inspect the CA certificate held in the webex-sgw trustpoint. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Configure certificates (certificate verification step). Checked 2026-09-30.
[^6]: The colocation configuration includes a dedicated step for emergency-call dial-peers used in survivability mode, separate from the outbound PSTN dial-peer for regular calls. Source: [Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways](https://help.webex.com/en-us/article/w0qmeu/Colocation-of-Local-Gateway-and-Site-Survivability-on-Cisco-IOS-Managed-Gateways), Configuration steps: emergency call dial-peers for survivability mode. Checked 2026-09-30.
[^7]: Basic Automatic Call Distribution (B-ACD) is not supported when the Survivability Gateway is colocated with a Local Gateway. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Limitations and restrictions (B-ACD bullet). Checked 2026-09-30.
[^8]: In a colocated deployment, High Availability is not supported for the Local Gateway and Control Hub config validation is not supported for the Local Gateway. Source: [Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways](https://help.webex.com/en-us/article/w0qmeu/Colocation-of-Local-Gateway-and-Site-Survivability-on-Cisco-IOS-Managed-Gateways), Limitations / considerations list. Checked 2026-09-30.
[^9]: The colocation configuration relies on dial-peer preference to order routing: default preference 0 for locally registered endpoints, preference 2 for the Webex Calling trunk, and preference 3 for the PSTN trunk. Source: [Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways](https://help.webex.com/en-us/article/w0qmeu/Colocation-of-Local-Gateway-and-Site-Survivability-on-Cisco-IOS-Managed-Gateways), Configuration: call routing / dial-peer preference explanation. Checked 2026-09-30.
[^10]: When Local Gateway and Survivability Gateway are colocated on one Cisco IOS gateway, the gateway must be provisioned in Control Hub as a Survivability Gateway service. Source: [Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways](https://help.webex.com/en-us/article/w0qmeu/Colocation-of-Local-Gateway-and-Site-Survivability-on-Cisco-IOS-Managed-Gateways), Limitations / considerations list. Checked 2026-09-30.
[^11]: Connector logs are collected by running the onboarding TCL script and choosing the Collect Logs option; the log file is written under bootflash:/guest-share/ for upload to a support case. Source: [Enroll Cisco IOS managed gateways to Webex Cloud](https://help.webex.com/en-us/article/xftgfc/Enroll-Cisco-IOS-Managed-Gateways-to-Webex-Cloud), Collect logs. Checked 2026-09-30.
[^12]: Special characters such as $, ! or - in the gateway credential password can prevent sign-in to the connector interface and successful deployment, so the enrollment article says not to use them. Source: [Enroll Cisco IOS managed gateways to Webex Cloud](https://help.webex.com/en-us/article/xftgfc/Enroll-Cisco-IOS-Managed-Gateways-to-Webex-Cloud), Limitations (password note). Checked 2026-09-30.
[^13]: Control Hub shows a managed gateway's connector as Online (connected to the Webex cloud), Offline (not connected) or Paused (connected but paused temporarily). Source: [Enroll Cisco IOS managed gateways to Webex Cloud](https://help.webex.com/en-us/article/xftgfc/Enroll-Cisco-IOS-Managed-Gateways-to-Webex-Cloud), Connector status in Control Hub. Checked 2026-09-30.
[^14]: The Survivability Gateway syncs call data from the Webex cloud daily, and that sync includes the authentication information for registered users which lets endpoints register securely in Survivability mode. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Overview: how it works (daily call data sync paragraph). Checked 2026-09-30.
[^15]: Dialing patterns can work differently in Survivability mode than in Active mode. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Limitations and restrictions (dialing patterns bullet). Checked 2026-09-30.
[^16]: E911 calling in Survivability mode requires a PSTN circuit or SIP trunk, and outbound emergency calls present an Emergency Location Identification Number registered for a defined Emergency Response Location configured on the gateway. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Supported features and components: E911 Calling. Checked 2026-09-30.
[^17]: Where the Wi-Fi overlay does not match IP subnets accurately, emergency calls from nomadic devices in Survivability mode may not get a correct ELIN mapping. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Configure emergency calls (caveat on Wi-Fi overlay). Checked 2026-09-30.
[^18]: Enhanced Survivability is a different feature that covers Webex Calling Dedicated Instance sites; it is not the Survivability Gateway used by Webex Calling multi-tenant. Source: [Get Started with Enhanced Survivability](https://help.webex.com/en-us/article/ggaigh/Get-Started-with-Enhanced-Survivability), Overview (defining sentence). Checked 2026-09-30.
[^19]: Enrollment requires the gateway to have a DNS server that resolves public domain names (ip name-server) and an NTP source for its clock, and the Site Survivability article likewise configures primary and secondary NTP servers. Source: [Enroll Cisco IOS managed gateways to Webex Cloud](https://help.webex.com/en-us/article/xftgfc/Enroll-Cisco-IOS-Managed-Gateways-to-Webex-Cloud), Prerequisites (network configuration). Checked 2026-09-30.
[^20]: Managed gateway enrollment, a prerequisite for the Survivability Gateway service, cannot be used on Cisco 1100 Integrated Services Router platforms, on gateways in High Availability mode, or on gateways in Controller mode for SD-WAN. Source: [Enroll Cisco IOS managed gateways to Webex Cloud](https://help.webex.com/en-us/article/xftgfc/Enroll-Cisco-IOS-Managed-Gateways-to-Webex-Cloud), Prerequisites (unsupported platforms and modes). Checked 2026-09-30.
[^21]: The connector needs HTTPS reach over TLS 1.2 to *.ucmgmt.cisco.com, *.webex.com and *.wbx2.com, and its IP address must be in the same network as the interface chosen for external connectivity. Source: [Enroll Cisco IOS managed gateways to Webex Cloud](https://help.webex.com/en-us/article/xftgfc/Enroll-Cisco-IOS-Managed-Gateways-to-Webex-Cloud), Prerequisites (network configuration). Checked 2026-09-30.
[^22]: Registrations and call control revert to the Webex cloud once the Webex network connection has resumed for at least 30 seconds. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Overview: how it works (failback sentence). Checked 2026-09-30.
[^23]: A Verizon republication of the Site Survivability article says that when an outage occurs it could take a few minutes for devices to register successfully to the Survivability Gateway (field report). Source: [Site Survivability for Webex Calling | Verizon](https://webexcallingtraining.verizon.com/site-survivability-for-webex-calling/), Limitations and restrictions (sentence on outage registration time). Checked 2026-09-30.
[^24]: As read on 2026-09-30, the Cisco Site Survivability article gives no figure for how long endpoints take to fail over to the Survivability Gateway after the Webex connection is lost, and names no detection timer. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Whole article; absence confirmed by two targeted queries. Checked 2026-09-30.
[^25]: The fully qualified domain name in the gateway certificate must be the same value that was entered as the host name when the survivability service was assigned to the gateway in Control Hub. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Import certificates along with keypairs. Checked 2026-09-30.
[^26]: Hunt group, call forward and auto attendant features in Survivability mode are available only from IOS XE 17.18.2 and later. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Supported features and components. Checked 2026-09-30.
[^27]: Survivability mode supports at most 100 hunt groups with 32 users per group, and weighted call routing for hunt groups is not supported. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Limitations and restrictions (hunt group bullets). Checked 2026-09-30.
[^28]: The Survivability Gateway must use an IPv4 address; IPv6 is not supported. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Limitations and restrictions (IPv4 bullet). Checked 2026-09-30.
[^29]: On Cisco ISR 4000 series routers the Survivability Gateway prerequisites call for the uck9 and securityk9 technology licences (license boot level uck9 and license boot level securityk9). Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Configure Survivability Gateway: licences step, ISR 4000 series. Checked 2026-09-30.
[^30]: For a gateway serving endpoints across locations within a LAN, Cisco recommends keeping latency between the Survivability Gateway and endpoints within a 50 millisecond threshold. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Multi-location deployment considerations (latency recommendation). Checked 2026-09-30.
[^31]: The gateway configuration sets max-dn and max-pool under voice register global alongside mode webex-sgw; the colocation article's example uses max-dn 50 and max-pool 50. Source: [Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways](https://help.webex.com/en-us/article/w0qmeu/Colocation-of-Local-Gateway-and-Site-Survivability-on-Cisco-IOS-Managed-Gateways), Configuration: Survivability Gateway specific settings (voice register global). Checked 2026-09-30.
[^32]: The port reference for Site Survivability lists call media between endpoints and the Survivability Gateway as SRTP over UDP ports 8000-14198. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Port reference table, call media row. Checked 2026-09-30.
[^33]: The management connector page reports a Running connector as Connected, Not Connected, Heartbeat Failed or Enrollment Failed; it is reached at https://<connector-ip-address> or through the onboarding TCL script's status option. Source: [Enroll Cisco IOS managed gateways to Webex Cloud](https://help.webex.com/en-us/article/xftgfc/Enroll-Cisco-IOS-Managed-Gateways-to-Webex-Cloud), Management connector states table; connector sign-in. Checked 2026-09-30.
[^34]: Webex Calling Survivability Gateway features require Cisco IOS XE Dublin 17.12.3 or a later release. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Supported features and components. Checked 2026-09-30.
[^35]: Devices with 4G or 5G connectivity, such as the Webex App on mobile or tablet, may remain registered to Webex Calling during a site outage and so may be unable to call numbers at the same site that have moved to the Survivability Gateway. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Limitations and restrictions (4G and 5G bullet). Checked 2026-09-30.
[^36]: Since an entry dated October 22, 2025, a single Survivability Gateway can be mapped to multiple Webex Calling locations within a campus; the assignment step lets the administrator select several locations. Source: [What's new in Webex Calling](https://help.webex.com/en-us/article/rdmb0/What's-new-in-Webex-Calling), October 2025: October 22, 2025 entry, Site Survivability support for multiple locations per gateway. Checked 2026-09-30.
[^37]: A critical NETCONF connection failure alarm on a managed gateway is addressed by verifying that NETCONF is enabled on the gateway and reachable from the connector; a NETCONF authentication failure by verifying the username and password configured on the gateway. Source: [Enroll Cisco IOS managed gateways to Webex Cloud](https://help.webex.com/en-us/article/xftgfc/Enroll-Cisco-IOS-Managed-Gateways-to-Webex-Cloud), Alarms table: NETCONF connection failure; NETCONF authentication failure. Checked 2026-09-30.
[^38]: Users or devices added or changed since the last successful sync may be unable to register to the Survivability Gateway during an outage, because their authentication information reaches the gateway only through the daily or on-demand sync (inferred). Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Overview: how it works (daily call data sync paragraph); Complete on-demand sync. Checked 2026-09-30.
[^39]: Three-way calling and conferencing are not supported in Survivability mode. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Limitations and restrictions (Survivability mode limitations). Checked 2026-09-30.
[^40]: Configuring the SIP bind command in voice service voip configuration mode on the Survivability Gateway causes endpoint registration to the gateway to fail. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Limitations and restrictions (SIP bind bullet). Checked 2026-09-30.
[^41]: The Park, Unpark, Barge, Pickup, Group Pickup and Call Pull softkeys are not supported in Survivability mode, and shared lines lose remote line state monitoring. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Limitations and restrictions (Survivability mode limitations). Checked 2026-09-30.
[^42]: TLS version 1.3 is not supported for the Webex Survivability Gateway operating mode. Source: [Cisco Unified SRST Administration Guide (All Versions) - Cisco Unified SRST Feature Overview](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cusrst/admin/sccp_sip_srst/configuration/guide/SCCP_and_SIP_SRST_Admin_Guide/srst_overview.html), Secure SRST (note on TLS 1.3). Checked 2026-09-30.
[^43]: The Survivability Gateway platform does not support a wildcard certificate. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Prerequisites / Configure certificates (wildcard sentence). Checked 2026-09-30.
[^44]: The Webex cloud places the Survivability Gateway IP address, hostname and port in each endpoint's device configuration file, and that is how an endpoint knows where to register when the connection to Webex breaks. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Overview: how it works (paragraph on the device configuration file). Checked 2026-09-30.
[^45]: Maximum endpoint registrations are set per platform, ranging in the published table from 50 on an ISR 4321 to 2,500 on the Catalyst Edge 8300 series. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Supported platforms table (maximum endpoint registrations). Checked 2026-09-30.
[^46]: Once mode webex-sgw is configured under voice register global, the Survivability Gateway listens on port 8933 for incoming secure (TLS) connections from endpoints. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Configure Survivability Gateway: voice register global, mode webex-sgw explanation; Port reference table. Checked 2026-09-30.
[^47]: IOS XE uses proxy ARP to route traffic to the guest shell that hosts the connector, so no ip proxy-arp must not be configured on the gateway. Source: [Enroll Cisco IOS managed gateways to Webex Cloud](https://help.webex.com/en-us/article/xftgfc/Enroll-Cisco-IOS-Managed-Gateways-to-Webex-Cloud), Limitations (proxy ARP note). Checked 2026-09-30.
[^48]: External calls in Survivability mode, inbound and outbound, depend on a local PSTN circuit or a SIP trunk configured on the Survivability Gateway; intrasite extension calls between registered endpoints route automatically without specific routing configuration. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Supported features and components: Intrasite Extension Calling; Intersite and PSTN Calling. Checked 2026-09-30.
[^49]: The Survivability Gateway certificate must be signed by a publicly known certificate authority; private or enterprise CA certificates cannot be used. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Prerequisites / Configure certificates (certificate authority requirement). Checked 2026-09-30.
[^50]: The prerequisites call for an RSA private key of at least 2048 bits for the Survivability Gateway certificate. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Prerequisites / Configure certificates (key size). Checked 2026-09-30.
[^51]: The colocation article states that Webex Calling deprecates the RSAES-PKCS1-v1_5 encryption scheme on September 1, 2024 and that Site Survivability Gateways must be upgraded to Cisco IOS XE Dublin 17.12.3 before that date. Source: [Colocation of Local Gateway and Site Survivability on Cisco IOS Managed Gateways](https://help.webex.com/en-us/article/w0qmeu/Colocation-of-Local-Gateway-and-Site-Survivability-on-Cisco-IOS-Managed-Gateways), Prerequisites / certificates note on RSAES-PKCS1-v1_5. Checked 2026-09-30.
[^52]: On a gateway colocating Webex Survivability and Unified SRST, one call-control connection can fail while the other stays up, leaving one set of endpoints on the gateway and another on primary call control; calls between the two sets then need routing over a SIP trunk or PSTN circuit. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Colocation with Unified SRST: call routing considerations. Checked 2026-09-30.
[^53]: The Unified SRST administration guide documents show sip-ua status registrar (SIP registrar clients), show voice register pool all (SIP phone pool detail) and show voice register dial-peers (SIP-SRST created dial peers) as monitoring commands for SIP SRST. Source: [Cisco Unified SRST Administration Guide (All Versions) - Monitoring and Maintaining Cisco Unified SRST](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cusrst/admin/sccp_sip_srst/configuration/guide/SCCP_and_SIP_SRST_Admin_Guide/srst_monitoring_and_maintaining.html), Command table: show sip-ua status registrar; show voice register pool all; show voice register dial-peers. Checked 2026-09-30.
[^54]: Because webex-sgw is an operating mode of voice register global, the generic SIP SRST show commands for registrar clients, register pools and register dial-peers are likely usable to check which Webex Calling endpoints have registered to a Survivability Gateway (inferred). Source: [Cisco Unified SRST Administration Guide (All Versions) - Cisco Unified SRST Feature Overview](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cusrst/admin/sccp_sip_srst/configuration/guide/SCCP_and_SIP_SRST_Admin_Guide/srst_overview.html), SRST operating modes: Webex Survivability Gateway Mode. Checked 2026-09-30.
[^55]: An endpoint that has not downloaded a device configuration file containing the Survivability Gateway details, for example one that last provisioned before the gateway was assigned to its location, has no gateway address to fail over to (inferred). Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Overview: how it works (paragraph on the device configuration file). Checked 2026-09-30.
[^56]: The on-demand sync status shown in Control Hub can take up to 30 minutes to update, so a stale status shortly after a sync is not by itself evidence of failure. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Limitations and restrictions (on-demand sync status bullet). Checked 2026-09-30.
[^57]: An on-demand sync triggered from Control Hub may take up to 10 minutes to complete. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Complete on-demand sync. Checked 2026-09-30.
[^58]: An on-demand sync is started in Control Hub under Services > PSTN & Routing > Gateway configurations > Manage Gateways by opening the Survivability Gateway and clicking Sync. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Complete on-demand sync. Checked 2026-09-30.
[^59]: The documented sip-ua configuration for the Survivability Gateway sets transport tcp tls v1.2 and crypto signaling default trustpoint webex-sgw, tying the TLS handshake with endpoints to the webex-sgw trustpoint. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Configure Survivability Gateway: sip-ua step. Checked 2026-09-30.
[^60]: To check whether the required root CA certificate is installed on the gateway, the article directs running show crypto pki trustpool | include cn= ; a root CA missing from the Cisco bundle has to be imported manually. Source: [Site survivability for Webex Calling](https://help.webex.com/en-us/article/d68vi1/Site-Survivability-for-Webex-Calling), Configure certificates (root CA check step). Checked 2026-09-30.
