For developers and network administrators configuring Vivox on restricted, proxied, or firewalled networks. Answers which destination IP ranges, TCP and UDP ports must be allowed. Also covers FQDN rules, HTTP/HTTPS proxies, and SSL/TLS inspection exceptions for *.vivox.com.
FQDN List
Vivox does not publish a fixed per-project FQDN allowlist, and we do not recommend allowlisting by FQDN alone. The backend has multiple components whose IPs can change, and the UDP voice media does not route through named hosts, so FQDN rules cannot cover it.
IP Subnets
The following list is current as of July 28, 2026.
85.236.96.0/21 85.236.104.0/23
Note: A single environment has multiple backend components that could change IPs without warning.
Port Ranges
All communications start as outbound communications from the client.
- TCP: 443 - for web server (HTTPS)
- UDP: 12000 - 52000 - for voice media (RTP)
Note: Because all communication starts as outbound from the client, a standard stateful firewall does not need any inbound UDP rules. It only needs to allow the return traffic on the same UDP port the client used to egress.
HTTP/HTTPS Proxy Environments
Vivox voice media is RTP sent over UDP, which does not pass through an HTTP/HTTPS proxy. There is no TCP fallback for voice media. When using a HTTP/HTTPS proxy, direct outbound UDP connections must be allowed to the Vivox IP/port ranges above, bypassing the proxy, for voice media to work.
SSL/TLS Inspection
This can cause firewall-related failures with Vivox. The control channel uses standard HTTPS on TCP 443. Proxies or firewalls that perform SSL/TLS inspection can cause connection or certificate errors (for example status code 10077, HTTP Invalid Certificate). SSL/TLS inspection should be disabled or excepted for *.vivox.com so the control traffic is not modified.