Troubleshooting Zoom Phone
Verified 2026-09-25 · 60 sources · tier 2
Troubleshooting Zoom Phone involves validating network firewall traversal, diagnosing desk phone provisioning, verifying Session Border Controller (SBC) peering, and monitoring emergency service routing 30461040. Administrators manage these issues across the web portal using quality dashboards, call history logs, and dedicated client diagnostic views 511359.
Network and Firewall Configuration
Zoom's firewall rules for Zoom Phone require outbound TCP 443 from all Zoom clients and the user's web browser to Zoom's published IPv4 and IPv6 ranges 30. The client rules also list TCP 5091 to specified Zoom IP blocks, TCP 390 for company directory search, and UDP 3478 for Traversal Using Relays around NAT (TURN) support 312932. Client media requires outbound access to UDP destination ports 20000-64000 across designated Zoom IP ranges 33.
Account owners and admins can configure a specific media source port range using the "Override Default Source Port" setting under Account Management > Account Settings > Zoom Phone tab > General 58. This overridden source port range must fall between 9000 and 9999 and include at least 50 ports 56. The override applies strictly at the account level, requires a restart of the Zoom app to take effect, and does not apply when peer-to-peer media is enabled 5755.
Quality of Service and Diagnostics
Admins access the quality of service (QoS) dashboard via Admin Center > Dashboard > Phone tab > Quality of Service tab, which provides Overall, Calls, and Extensions views 51. The dashboard evaluates call quality on a 1-5 Mean Opinion Score (MOS) scale, treating 3.5 or higher as good and scores below 3.5 as poor 54. MOS details and QoS metrics for a call appear on the dashboard approximately 20 seconds after the call concludes 52. QoS dashboard filters include site, department or cost center, device type (IP phone, native application, VDI), direction, call duration, ISP, route group and SBC, and survey results 53.
To implement network priority, admins configure media and signaling Differentiated Services Code Point (DSCP) values under Account Settings > Zoom Phone > Enable QoS with DSCP marking 17. The Zoom app applies these portal values directly on mobile, macOS, and Linux, and the portal pushes DSCP markings down to certified desk phones 1715. On Windows, the app must run with administrator privileges, or the markings must be applied via PowerShell or Group Policy 18. Zoom notes that DSCP markings are typically not preserved once network traffic exits the customer network onto the internet 16.
During an active Zoom Phone call, desktop users can open Settings > Statistics > Phone tab to inspect live call metrics, which list the Register ID, register server IP and port, network switch, local network interface, local and remote IP/port, and codec 5960. For synthetic testing, the web portal provides a simulation tool under Phone > Network Diagnostics that evaluates latency, packet loss, jitter, and codec behavior 37. The "Web-based Network Diagnostic Tool" must be enabled on the account by contacting Zoom Support before VoIP simulations can run 36.
Admins review past call behavior at Admin Center > Product configuration > Phone system > Logs > Calls tab 13. The call path detail provides participants, extensions, call ID, start and end times, events with wait times, device type, result, talking duration, and either GPS coordinates or an IP address 11. Logs can be filtered by direction, call result, events, number type, and site, and exported via Export to CSV 12.
Desk Phone Provisioning
Desk phones provision through either zero-touch provisioning (ZTP) or assisted provisioning via the phone's web interface when ZTP fails or is unsupported 46. A desk phone must be added to the Zoom web portal by its MAC address before it is powered on for the first time or factory reset 42. During ZTP, the device contacts its manufacturer redirect service, which validates the device and redirects it to the Zoom provisioning server, causing the phone to reboot several times 4850.
Zoom outlines distinct provisioning URLs for supported desk phone hardware manufacturers 45:
| Manufacturer | Provisioning Mechanism |
|---|---|
| AudioCodes | ZTP URL 45 |
| Avaya | ZTP URL 45 |
| Cisco | ZTP URL 45 |
| Grandstream | ZTP URL 45 |
| Mitel | ZTP URL 45 |
| Poly | ZTP URL 45 |
| Ubiquiti | ZTP URL 45 |
| Yealink | ZTP URL 45 |
Desk phone onboarding failures commonly stem from outdated firmware, competing provisioning servers reaching the device, or an incorrect provisioning URL during assisted provisioning 43. DHCP options remaining from prior phone deployments can also block ZTP and must be cleared 44. Misconfigured firewalls, blocked ports, unstable DNS, inconsistent NTP time sources, SIP ALG interference, incorrect VLAN assignments, and DHCP misconfigurations cause registration failures, unexpected reboots, or one-way audio 4749.
BYOC-Premises Trunk Troubleshooting
Bring Your Own Carrier - Premises Peering (BYOC-P) and BYOP-P route groups enforce TLS transport exclusively; this protocol setting cannot be altered 10. The customer SBC requires bidirectional connectivity with Zoom 1. Signaling uses TCP 5061 in both directions across all Zoom clusters, while media uses bidirectional UDP ports 10000-64000 95. WarmTransfer's reading of the sources is that because firewall rules for Zoom clients (UDP 20000-64000) differ from SBC rules (UDP 10000-64000 and bidirectional TCP 5061), applying client firewall rules to an SBC leaves inbound signaling and part of the media port range blocked 31339534.
Inbound INVITE requests from the SBC to Zoom must contain the SDP offer (early offer) 4. Preferred codecs for BYOC-P/BYOP-P SBCs include OPUS, G.722, G.711 A-law, G.711 mu-law, and G.729 2. BYOC-P route groups mandate calling and called numbers in E.164 format, whereas BYOP-P accommodates localized or E.164 numbers up to 24 digits 3.
Trunk health relies on SIP OPTIONS keepalive messages sent by Zoom every 30 seconds 6. Zoom marks a trunk down after 4 consecutive failed responses, which occurs within a 90-120 second window 6. WarmTransfer's reading of the sources is that because BYOC-P requires TLS and judges trunk health via OPTIONS responses, an SBC certificate or TLS negotiation failure will surface as missed keepalives and a downed trunk rather than an explicit error 10635. When an SBC returns SIP failure response codes 403, 408, 480, 488, 500, 502, 503, 504, or 606, Zoom automatically reroutes the call to a backup SBC 7.
Emergency Services Configuration
Admins configure emergency addresses under Product configuration > Phone system > Company Info > Emergency Services, and addresses can be created for any country or region, including regions where Zoom lacks native direct numbers 2021. For BYOC lines, carrier confirmation is handled using Address Change Notification or Batch Address Confirmation via CSV upload 22. For US and Canada BYOC numbers, emergency calls can route through either Zoom or the BYOC carrier; BYOC numbers in all other countries must route through the carrier 23.
Nomadic emergency services resolve location in priority order: network switch MAC and port, BSSID, private/public IP subnet, public IP, personal location IP match, GPS (US/Canada only), then default address or Unknown 40.
The Zoom mobile app bypasses nomadic emergency services entirely and places emergency calls over the device's native carrier network 39. On desktop, when "Allow personal location" is active, the Zoom Workplace app prompts users in an undefined location and alerts them that a default address is being used 41. When placing an emergency call, the caller ID transmitted to the Public Safety Answering Point (PSAP) can be a direct number or a temporary number drawn from an account or local emergency pool 27. Admins can configure automated email notifications when emergency numbers are dialed, which transmit the caller's name, email, time zone, extension, and assigned numbers 26. The Emergency Services dashboard (Admin Center > Dashboard > Phone > Emergency Services) tracks IP phones and users in company, personal, or unknown locations and provides CSV exports, though recently updated data can take several hours to appear 2425.
Applicability
Applies to: Zoom Phone and Zoom Workplace desktop app. Deployments: cloud, multi-tenant, and byoc-premises. Sources checked 2026-09-25. Zoom states that call logs are retained for up to 2 years to meet compliance mandates in countries where Zoom provides native service 14.
What remains uncertain
How Zoom reports BYOC-P TLS or certificate failures to admins via call log result codes or trunk status is not covered by the sources below. Zoom Phone Local Survivability firewall requirements (KB0058005) are not covered by the sources below. An official Zoom support-article statement on disabling SIP ALG for Zoom Phone is not covered by the sources below. The Zoom certified SBC list and firmware versions for BYOC-P are not covered by the sources below. Mapping Kari's Law and RAY BAUM'S Act dispatchable location duties onto Zoom nomadic emergency features is not covered by the sources below. Troubleshooting BYOC-C cloud peering and Provider Exchange numbers is not covered by the sources below. Confirmation of the current admin menu path for BYOC route group IPs (Number Management > BYOC Configuration vs Company Info > Route Groups) is not covered by the sources below. Whether Zoom Phone supports address-verification test calls is not covered by the sources below.
See also
Related to
- E911 test calls and validation — Zoom Phone emergency address; nomadic location detection and emergency call routing claims here feed platform-specific E911 testing; this packet does not cover 933 test calls.
- SIP TLS handshake failures on trunks — Zoom BYOC-P/BYOP-P trunks are TLS-only on TCP/5061; so SBC TLS handshake failures present as BYOC trunk-down issues.
Referenced by
- E911 test calls and validation — Zoom Phone 933 behaviour is not yet established from a first-party source in this packet
Sources
- 1BYOC-P SBCs require bi-directional connectivity with Zoom.Bring Your Own Carrier - Premises Peering (BYOC-P) | Zoom Technical Library · BYOC-P overview section · Checked 2026-09-25
- 2Zoom lists OPUS, G.722, G.711 A-law/mu-law and G.729 as preferred codecs for BYOC-P/BYOP-P SBCs.BYOC-P or BYOP-P call processing · SBC requirements / codecs section · Checked 2026-09-25
- 3For BYOC-P route groups, calling and called numbers must be in E.164 format; BYOP-P allows localized or E.164 numbers up to 24 digits.BYOC-P or BYOP-P call processing · outgoing calls section, Request-URI format · Checked 2026-09-25
- 4Inbound calls from the SBC to Zoom on BYOC-P/BYOP-P must send an INVITE containing the SDP offer (early offer).BYOC-P or BYOP-P call processing · incoming calls section · Checked 2026-09-25
- 5BYOC-P/BYOP-P media between the SBC and Zoom uses UDP ports 10000-64000 in both directions.BYOC-P or BYOP-P infrastructure requirements · per-cluster firewall tables, media rows · Checked 2026-09-25
- 6Zoom sends SIP OPTIONS keepalives to a BYOC-P SBC every 30 seconds and marks the trunk down after four consecutive failed responses, within 90-120 seconds.BYOC-P or BYOP-P call processing · section 'Options Keepalive' · Checked 2026-09-25
- 7Zoom reroutes a BYOC-P call to a backup SBC when the SBC returns 403, 408, 480, 488, 500, 502, 503, 504 or 606.BYOC-P or BYOP-P call processing · failover / rerouting section · Checked 2026-09-25
- 8Zoom directs admins to Number Management > BYOC Configuration > Route Groups in the admin portal to confirm the account's cluster and the IPs and FQDNs to permit for the SBC.BYOC-P or BYOP-P infrastructure requirements · introductory note before the cluster tables · Checked 2026-09-25
- 9BYOC-P/BYOP-P signaling between the SBC and Zoom uses TCP/5061 in both directions for all listed Zoom clusters.BYOC-P or BYOP-P infrastructure requirements · per-cluster firewall tables (US01, UK01, EU01/EU02, CA01, SA01), signaling rows · Checked 2026-09-25
- 10BYOC-P and BYOP-P route groups support only TLS transport, and the transport cannot be changed.BYOC-P or BYOP-P configuration guide · route group configuration section, transport protocol field · Checked 2026-09-25
- 11A call log entry's call path shows participants and extensions, GPS coordinates or IP address, call ID, start and end times, events with waiting times, result, talking duration and device type.Viewing Zoom Phone call history logs (New View) · call path details section · Checked 2026-09-25
- 12Call history logs can be filtered (direction, call result, events, number type, site and others) and exported with Export to CSV.Viewing Zoom Phone call history logs (New View) · filters and export sections · Checked 2026-09-25
- 13Admins view Zoom Phone call history logs (New View) at Admin Center > Product configuration > Phone system > Logs > Calls tab.Viewing Zoom Phone call history logs (New View) · section on viewing call logs (numbered steps) · Checked 2026-09-25
- 14Zoom states that call logs are retained for up to 2 years to meet in-country compliance obligations in countries where Zoom Phone provides native service.Viewing Zoom Phone call history logs (New View) · retention note · Checked 2026-09-25
- 15Portal-configured DSCP markings are pushed down to certified desk phones.Implementing Quality of Service for Zoom Phone · section 'How to implement QoS policies', desk phones · Checked 2026-09-25
- 16Zoom notes that DSCP markings are typically not preserved once traffic leaves the customer network and enters the internet.Implementing Quality of Service for Zoom Phone · section 'How to plan for a successful QoS implementation' · Checked 2026-09-25
- 17Admins set Zoom Phone media and signaling DSCP values under Account Settings > Zoom Phone > Enable QoS with DSCP marking, and the app on mobile, macOS and Linux applies those portal values.Implementing Quality of Service for Zoom Phone · section 'How to implement QoS policies' · Checked 2026-09-25
- 18For the Windows app to apply portal-configured DSCP values, the app must run with administrator privileges or the markings must be applied through PowerShell or Group Policy.Implementing Quality of Service for Zoom Phone · section 'How to implement QoS policies', Windows subsection · Checked 2026-09-25
- 19The Zoom Workplace app on Windows marks Zoom Phone media with DSCP 56 and signaling with DSCP 40 by default.Implementing Quality of Service for Zoom Phone · section 'How to implement QoS policies', Windows subsection · Checked 2026-09-25
- 20Admins add or update emergency addresses under Product configuration > Phone system > Company Info > Emergency Services.Setting up emergency addresses · section on adding emergency addresses (steps) · Checked 2026-09-25
- 21Zoom allows an emergency address to be set in any country or region, even one where Zoom Phone does not offer direct numbers.Setting up emergency addresses · country/region note · Checked 2026-09-25
- 22For BYOC numbers, admins can have the carrier confirm emergency addresses through Batch Address Confirmation (CSV upload) or Address Change Notification.Setting up emergency addresses · BYOC emergency address section · Checked 2026-09-25
- 23For US and Canada BYOC numbers, admins can route emergency calls via the BYOC carrier or via Zoom; BYOC numbers outside the US and Canada must use the BYOC carrier.Routing emergency calls · BYOC emergency calling section · Checked 2026-09-25
- 24The Emergency Services dashboard (Admin Center > Dashboard > Phone > Emergency Services) shows users and IP phones detected in company, personal or unknown locations and location-sharing opt-in status, with CSV export.Viewing the Zoom Phone Emergency Services dashboard · dashboard overview and navigation steps · Checked 2026-09-25
- 25Zoom warns that recently updated data may not show immediately on the Emergency Services dashboard and can take several hours to appear.Viewing the Zoom Phone Emergency Services dashboard · note at end of article · Checked 2026-09-25
- 26Admins can enable email notifications whenever a phone user calls the emergency number; the email includes the caller's name, email, time zone, extension and assigned numbers.Routing emergency calls · email notifications section · Checked 2026-09-25
- 27The caller ID presented to the PSAP on a Zoom Phone emergency call can be a temporary number from a local or account emergency pool or a dedicated direct number.Routing emergency calls · PSAP routing section · Checked 2026-09-25
- 28Zoom's Zoom Phone firewall rules include IPv6 destination ranges (for example 2620:123:2000::/40 and 2407:c280::/32) alongside IPv4 ranges such as 144.195.0.0/16.Zoom network firewall or proxy server settings · section 'Firewall rules for Zoom Phone', destination columns · Checked 2026-09-25
- 29Zoom's firewall rules for Zoom Phone list outbound TCP 390 from Zoom clients for company directory search.Zoom network firewall or proxy server settings · section 'Firewall rules for Zoom Phone', TCP 390 row · Checked 2026-09-25
- 30Zoom's firewall rules for Zoom Phone require outbound TCP 443 from all Zoom clients and the user's web browser to Zoom's published IPv4 and IPv6 ranges.Zoom network firewall or proxy server settings · section 'Firewall rules for Zoom Phone', TCP 443 row · Checked 2026-09-25
- 31Zoom's firewall rules for Zoom Phone list TCP 5091 from all Zoom clients to specified Zoom IP blocks.Zoom network firewall or proxy server settings · section 'Firewall rules for Zoom Phone', TCP 5091 row · Checked 2026-09-25
- 32Zoom's firewall rules for Zoom Phone list UDP 3478 from all Zoom clients for TURN (Traversal Using Relays around NAT) support.Zoom network firewall or proxy server settings · section 'Firewall rules for Zoom Phone', UDP 3478 row · Checked 2026-09-25
- 33Zoom's firewall rules for Zoom Phone list UDP destination ports 20000-64000 from all Zoom clients to designated Zoom IP ranges.Zoom network firewall or proxy server settings · section 'Firewall rules for Zoom Phone', UDP 20000-64000 row · Checked 2026-09-25
- 34Firewall rules for Zoom Phone clients (UDP 20000-64000) and for BYOC-P SBCs (UDP 10000-64000, TCP/5061 bidirectional) are different sets, so reusing the client rule for an SBC would leave part of the SBC media range and inbound signaling closed.inferredBYOC-P or BYOP-P infrastructure requirements · media and signaling rows, compared with KB0060548 Zoom Phone section · Checked 2026-09-25
- 35Because BYOC-P is TLS-only and health is judged by OPTIONS responses, an SBC TLS or certificate failure would likely surface as failed keepalives and a trunk marked down rather than as a distinct error.inferredBYOC-P or BYOP-P call processing · section 'Options Keepalive', read with KB0083637 transport field · Checked 2026-09-25
- 36The 'Web-based Network Diagnostic Tool' feature must be enabled on the account by contacting Zoom Support before the VoIP simulation is available.Simulating VoIP calls using the network tool · prerequisites section · Checked 2026-09-25
- 37The web-based network tool simulates a VoIP call between the Zoom client and Zoom from the web portal Phone > Network Diagnostics tab and reports latency, codec, packet loss and jitter.Simulating VoIP calls using the network tool · section on running the simulation (numbered steps) · Checked 2026-09-25
- 38Nomadic emergency services accept up to 1000 BSSID entries, with wildcard characters allowed.Setting up nomadic emergency services · BSSID configuration section · Checked 2026-09-25
- 39The Zoom mobile app does not use nomadic emergency services; it places emergency calls through the phone's native carrier.Setting up nomadic emergency services · limitations note · Checked 2026-09-25
- 40Nomadic emergency services resolve location in priority order: network switch MAC and port, BSSID, private/public IP subnet, public IP, personal location IP match, GPS (US/Canada only), then default address or Unknown.Setting up nomadic emergency services · location detection priority list · Checked 2026-09-25
- 41With 'Allow personal location' enabled, the Zoom Workplace app prompts users in an undefined location and tells them a default address is in use.Setting up nomadic emergency services · user experience section · Checked 2026-09-25
- 42A desk phone must be added to the Zoom web portal by MAC address before it is first powered on or factory reset for provisioning.Getting started with provisioning desk phones · prerequisites section · Checked 2026-09-25
- 43Outdated firmware, competing provisioning servers reaching the device, and a wrong provisioning URL in assisted provisioning are named causes of desk phone provisioning failure.Getting started with provisioning desk phones · troubleshooting notes in assisted provisioning section · Checked 2026-09-25
- 44DHCP options left over from a prior phone deployment can block zero-touch provisioning and should be removed.Desk Phone Provisioning & Customization Field Guide · ZTP prerequisites section · Checked 2026-09-25
- 45Zoom's provisioning article covers desk phones from AudioCodes, Avaya, Cisco, Grandstream, Mitel, Poly, Ubiquiti and Yealink, each with its own ZTP URL.Getting started with provisioning desk phones · supported manufacturers / ZTP URL list · Checked 2026-09-25
- 46Zoom Phone desk phones provision by zero-touch provisioning or, where ZTP is unsupported or fails, by assisted provisioning through the phone's web interface.Getting started with provisioning desk phones · provisioning methods section · Checked 2026-09-25
- 47Zoom's field guide names misconfigured firewalls, blocked ports, unstable DNS and inconsistent NTP time sources as causes of desk phone registration failures, one-way audio or unexpected reboots.Desk Phone Provisioning & Customization Field Guide · network readiness section · Checked 2026-09-25
- 48A phone reboots several times during zero-touch provisioning, and this is expected.Getting started with provisioning desk phones · zero-touch provisioning section · Checked 2026-09-25
- 49Zoom's field guide lists SIP ALG interference, incorrect VLAN assignment and DHCP misconfiguration among common desk phone connectivity problems.Desk Phone Provisioning & Customization Field Guide · common issues / troubleshooting section · Checked 2026-09-25
- 50In Zoom's description of ZTP, the phone contacts its manufacturer's cloud redirect service, which validates it and redirects it to Zoom's provisioning server.Desk Phone Provisioning & Customization Field Guide · zero-touch provisioning section · Checked 2026-09-25
- 51The Zoom Phone quality of service dashboard is reached in the web portal via Admin Center > Dashboard > Phone tab > Quality of Service tab, with Overall, Calls and Extensions views.Viewing the Zoom Phone quality of service dashboard · section on accessing the QoS dashboard (numbered steps) · Checked 2026-09-25
- 52QoS and MOS details for a call become visible on the dashboard about 20 seconds after the call occurs.Viewing the Zoom Phone quality of service dashboard · data availability note · Checked 2026-09-25
- 53QoS dashboard filters include site, department or cost center, device type (IP phone, native application, VDI), direction, call duration, ISP, route group and SBC, and survey results.Viewing the Zoom Phone quality of service dashboard · filters section · Checked 2026-09-25
- 54The Zoom Phone QoS dashboard rates call quality by MOS on a 1-5 scale and treats MOS of 3.5 or higher as good and below 3.5 as poor.Viewing the Zoom Phone quality of service dashboard · MOS explanation paragraph near top of article · Checked 2026-09-25
- 55The source port override does not apply when peer-to-peer media is enabled.Selecting source ports to use during a Zoom Phone call · notes/limitations section · Checked 2026-09-25
- 56The overridden Zoom Phone source port range must fall between 9000 and 9999 and include at least 50 ports.Selecting source ports to use during a Zoom Phone call · section on configuring source ports, range note · Checked 2026-09-25
- 57The source port override applies at the account level only, and the Zoom app must restart for a change to take effect.Selecting source ports to use during a Zoom Phone call · notes/limitations section · Checked 2026-09-25
- 58Account owners and admins can set the Zoom Phone media source port range with the 'Override Default Source Port' setting under Account Management > Account Settings > Zoom Phone tab > General.Selecting source ports to use during a Zoom Phone call · section on configuring source ports (web portal steps) · Checked 2026-09-25
- 59During an active Zoom Phone call, users can open desktop app Settings > Statistics > Phone tab to see live call statistics.Accessing meeting and phone statistics · Zoom Phone statistics section (steps) · Checked 2026-09-25
- 60The Phone statistics tab shows a Register ID and the register server IP and port, plus network switch, local network interface, local and remote IP/port, and codec.Accessing meeting and phone statistics · Zoom Phone statistics section, Phone tab field list · Checked 2026-09-25
Documents
Accessing meeting and phone statistics
Bring Your Own Carrier - Premises Peering (BYOC-P) | Zoom Technical Library
BYOC-P or BYOP-P call processing
BYOC-P or BYOP-P configuration guide
BYOC-P or BYOP-P infrastructure requirements
Desk Phone Provisioning & Customization Field Guide
Getting started with provisioning desk phones
Implementing Quality of Service for Zoom Phone
Routing emergency calls
Selecting source ports to use during a Zoom Phone call
Setting up emergency addresses
Setting up nomadic emergency services
Simulating VoIP calls using the network tool
Viewing the Zoom Phone Emergency Services dashboard
Viewing the Zoom Phone quality of service dashboard
Viewing Zoom Phone call history logs (New View)
Zoom network firewall or proxy server settings
Cite this page
APA
WarmTransfer. (2026, September 25). Troubleshooting Zoom Phone. WarmTransfer. https://warmtransfer.net/knowledge/zoom-phone-troubleshooting
BibTeX
@misc{warmtransfer-zoom-phone-troubleshooting,
title = {Troubleshooting Zoom Phone},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/zoom-phone-troubleshooting},
note = {Verified 2026-09-25}
}