Firewall Settings

Note: The firewall configurations mentioned in this topic must be done on both IPv4 and IPv6 networks.

The Mitel One web application uses services provided by the CloudLink platform and the PBX for chat, authorization, authentication, audio functionality, and dialing into meetings from the PSTN. It also uses the services provided by Amazon Web Services (AWS) Chime SDK for audio, video, and screen sharing requirements in Mitel One Meetings. To support these services, Mitel One web application uses the hosts and ports described in this topic. If inbound or outbound traffic is blocked, the application’s ability to use various services, including audio, and messages might be affected on both IPv4 and IPv6 networks.

Note: Both inbound and outbound ports must be open in order to allow the application to function. You can also use wildcards to further identify the inbound and outbound traffic to allow or disallow packets accordingly. However, wildcards are not mandatory as some firewalls do not allow wildcards to be configured.

To use the Mitel One web application, a system administrator must also be aware of the URLs the web app uses and ensure that the IP network ports required by the overall solution are open.

Hosts

  • *.mitel.io
  • *.amazonaws.com
  • *.bugsnag.com
  • *.gstatic.com
  • cdnjs.cloudflare.com
  • *.chime.aws
  • firebaseinstallations.googleapis.com
  • fcmregistrations.googleapis.com
  • api.ipify.org
  • maps.googleapis.com
  • login.microsoftonline.com
  • 99.77.128.0/18

Ports

  • 7443 – TLS
  • 16384 – 32768 UDP (RTP/SRTP)
  • ICMP
  • 443 – TCP
  • 3478 – UDP
Note: The Mitel One web application uses WebRTC. By default, the CS0 is set the same as DSCO value.

Web sockets used in the Mitel One web application also require an entry in the allowed list for *.amazonaws.com for the ports defined in https://docs.aws.amazon.com/iot/latest/developerguide/protocols.html.

If you are using a proxy, ensure that it proxies WebSockets and HTTPS.

Check using Amazon Chime Readiness Checker whether your firewall rules require updating.

Note: