Firewall configuration

Firewall configuration

Overview

About this page

  • You must read this entire section to ensure that you configure your firewall correctly.

  • Inbound and outbound traffic terminology:

    • Inbound describes traffic from VCC.

    • Outbound describes traffic to VCC.

We recommend adding the appropriate URLs and IP addresses to any firewall rules that restrict employee access, and we request that you treat Vonage Contact Center as a business-critical application. By this, we mean optimizing and prioritizing IP traffic to Vonage Contact Center over other non-critical traffic. This is to ensure real-time responses to agent requests are processed in a timely and efficient manner (call steering buttons, call transfers, hold requests, and so on).

You should also review any IP packet inspection or local caching policies to optimize the user experience.

Ports

Outbound

All outbound traffic requires TCP port 443 (HTTPS). Responses are sent to a range of ephemeral ports. This requirement applies to:

  • VCC traffic, regardless of whether you use URL or IP allowlisting

  • VCC APIs

  • WebRTC traffic (see WebRTC sections later in this page for information about other ports required for WebRTC traffic)

  • All other third-party traffic (Adobe Analytics and Cloudfront)

Inbound

All inbound traffic requires access to destination TCP port 443 (HTTPS) on our servers to establish a connection. Responses are sent to a range of ephemeral ports.

Virtual private network (VPN)

We recommend using a split tunnel configuration to ensure that traffic - especially voice traffic - to Vonage services is routed directly from the end user to our platform and not through a VPN. We do not recommend tunneling voice connectivity through a VPN tunnel due to the potential adverse effect on voice quality.

Using URL allowlisting (recommended)

Depending on whether you will use wildcard or fully qualified domain names, add the following URLs to your allowlist:

  • Using wildcard domains:

    • *.vonage.com

    • *.vonagenetworks.net

    • *.cc.vonage.com

    • *.api.cc.vonage.com

    • *.newvoicemedia.com

    • *.api.newvoicemedia.com

    • *.contact-world.net

    • *.nexmo.com

    • *.adobedtm.com 

    • recaptcha.net

    • gstatic.com

  • Using fully qualified domain names (FQDN):

Region

URL

  • WalkMe traffic

Vonage Contact Center uses a third party tool - WalkMe - to inform supervisors and administrators about new features and guide them when using the portal. To benefit from this functionality, you must add the following domains to your allowlist:

Critical domains

Domain

Purpose of Domain

If Access is Blocked

Domain

Purpose of Domain

If Access is Blocked

*.walkme.com

Load the WalkMe product

WalkMe will not function

s3.walkmeusercontent.com

Images in WalkMe Solutions hosted by WalkMe’s AWS

Images in WalkMe Solutions that are hosted by WalkMe’s AWS will not appear

Recommended

Domain

Purpose of Domain

If Access is Blocked

Domain

Purpose of Domain

If Access is Blocked

clients2.google.com/service/update2/crx

Update Chrome extensions

WalkMe Chrome extensions (Player and Editor) will not be able to update

safari-extensions.apple.com/details/

Update Safari extensions

WalkMe Safari extension (Player and Editor) will not be able to update

For more information, see https://support.walkme.com/knowledge-base/access-requirements-for-walkme/ .

You must also add the IP addresses specified in the following sections to your allowlist.

Screen recording traffic

The Screen Recording client communicates with Vonage servers to authenticate and maintain a WebSocket connection that provides updates about the interaction state.

To allow communication between the app and our servers:

  1. The screen-recording-client application needs to be allowlisted on the traffic and application monitoring apps

  2. Add the following URLs to your allowlist:

Region

URL

APAC

  • HTTPS traffic:

    • https://apac.newvoicemedia.com/*

    • https://apac.api.newvoicemedia.com/*

    • https://apac.cc.vonage.com/

    • https://apac.api.cc.vonage.com/

  • HTTPS

    • https://apac-message-relay.contact-world.net/*

  • WebSocket traffic

    • apac-message-relay.contact-world.net

  • S3 HTTPS traffic

    • https://prd-apac-sin-screen-recording-raw-chunks.s3.amazonaws.com/* 

    • https://prd-apac-syd-screen-recording-raw-chunks.s3.amazonaws.com/*

EMEA

  • HTTPS traffic:

    • https://emea.newvoicemedia.com/*

    • https://emea.api.newvoicemedia.com/*

    • https://emea.cc.vonage.com/

    • https://emea.api.cc.vonage.com/

  • HTTPS

    • https://emea-message-relay.contact-world.net/*

  •  WebSocket traffic

    • emea-message-relay.contact-world.net

  • S3 HTTPS traffic

    • https://prd-emea-fra-screen-recording-raw-chunks.s3.amazonaws.com/* 

    • https://prd-emea-lon-screen-recording-raw-chunks.s3.amazonaws.com/*

NAM

  • HTTPS traffic:

    • https://nam.newvoicemedia.com/*

    • https://nam.api.newvoicemedia.com/*

    • https://nam.cc.vonage.com/

    • https://nam.api.cc.vonage.com/

  • HTTPS

    • https://nam-message-relay.contact-world.net/*

  •  WebSocket traffic

    • nam-message-relay.contact-world.net

  • S3 HTTPS traffic

    • https://prd-nam-pdx-screen-recording-raw-chunks.s3.amazonaws.com/* 

    • https://prd-nam-ric-screen-recording-raw-chunks.s3.amazonaws.com/*

 

For the autoupdate feature, the following URL needs to be whitelisted:

  • https://cdn.newvoicemedia.com/screen-recording-client/*

Support and documentation feedback

For general assistance, please contact Customer Support.

For help using this documentation, please send an email to docs_feedback@vonage.com. We're happy to hear from you. Your contribution helps everyone at Vonage! Please include the name of the page in your email.