3CX V20 · Technical guide

3CX firewall ports:
the complete port list

Which ports really have to be opened for a 3CX system? A clean answer is nowhere to be found online. Here it is: five network diagrams with every inbound and outbound rule – from on-premises and SBC through to VLAN segmentation.

Five scenarios, five rule sets

Which ports actually have to be opened for a 3CX system? A clean answer is nowhere to be found online – the details are scattered across manuals and forums and do not cover special cases such as VLAN segmentation at all. So we compiled the port rules for 3CX V20 in full: five network diagrams with every inbound and outbound rule, including the rules between VLANs.

inbound outbound between VLANs / local LAN not needed / not possible warning / pitfall

Based on 3CX V20 · example VLANs: 1 = data/clients, 2 = server/SBC, 3 = telephony, M = management · directions from the viewpoint of the device the rule applies to

1

Self-hosted PBX (on-premises), flat network

The 3CX PBX sits on your own network and is reachable from the internet. The classic case – and the only one in which inbound port openings are strictly required.

INTERNETCOMPANY NETWORK (LAN)PERIMETER-FIREWALLSIP trunk / VoIP providerTrunk linesRemote apps & SBCHome office, smartphone, branch siteVideo conference participantsBrowser, external3CX cloud servicesActivation, updates, push, mailDNS · NTP · SMTP if usedInfrastructureINBOUND5060 UDP · 5060–5061 TCP9000–10999 UDP (RTP)INBOUND443 TCP (alt. 5001)5090 TCP + UDP (tunnel)INBOUND443 TCP · 80 TCP (certificate)OUTBOUND443 TCP · 3478 UDP2197 + 5223 TCP (Apple Push)48000–65535 UDPOUTBOUND53 UDP/TCP · 123 UDP5060 + 9000–10999 (provider)■ 3CX PBXOn-premises server · Debian 12☎ IP desk phonesLOCAL – NO FIREWALL RULE5060 UDP/TCP · 5061 TLS9000–10999 UDP (RTP)443 TCP (provisioning)224.0.1.75:5060 (Plug & Play)▭ Workstations · web client / desktop appLOCAL – NO FIREWALL RULE443 TCP (alt. 5001)9000–10999 UDP (WebRTC)!Disable SIP ALG. HTTPS (443) and the tunnel port (5090) must remain reachablefrom ANY – home office, hotel, on the road.Colour code: ▬ inbound (blue) ▬ outbound (orange) ▬ local LAN (teal)
DirectionPort(s)PurposeWhen / what to watch
inbound 5060 UDP · 5060–5061 TCP SIP signalling from the trunk Always with a SIP trunk. Restrict to the provider’s IP ranges.
inbound 9000–10999 UDP RTP – the actual voice data Always. 2 ports per simultaneous call.
inbound 443 TCP (alt. 5001) Web client, console, presence, provisioning, WebRTC Always. Must remain reachable from ANY – home office, hotel, on the road.
inbound 5090 TCP + UDP 3CX tunnel for SBC, apps, router phones As soon as an SBC or remote apps are used. TCP AND UDP – TCP alone gives one-way audio.
inbound 80 TCP Let’s Encrypt validation, redirect to HTTPS For automatic certificate renewal. Not officially documented.
outbound 443 TCP 3CX cloud: activation, updates, RPS, mail, push, WebMeeting Always – details in diagram 5.
outbound 2197 + 5223 TCP Apple APNs push Only when iOS apps are used.
outbound 48000–65535 UDP Video conference media stream Only when using 3CX Meet.
outbound 3478 UDP · 53 · 123 STUN, DNS, NTP Always. DNS and NTP are technically essential but not documented by 3CX.
2

3CX-hosted PBX + SBC on site

The PBX lives in the 3CX cloud and an SBC sits on site. The big advantage: the site firewall needs no inbound openings at all.

3CX-CLOUD / INTERNETSITE (LAN)PERIMETER-FIREWALL☁ 3CX PBXhosted by 3CXpbx.firma.3cx.deDNS · NTP · vendor RPSInfrastructureOUTBOUND · PHONES443 TCP (provisioning, firmware)123 UDP · 53 UDP/TCPOUTBOUND · SBC5090 TCP + UDP (tunnel)443 TCP (alt. 5001)OUTBOUND · APPS443 TCP5090 TCP + UDP if used☎ IP desk phones⇄ 3CX SBC · single NIC, belongs in the phone network▭ Workstations · web client / desktop appLOCAL, SAME NETWORK5060 UDP (SIP to the SBC)RTP – no documented port range224.0.1.75:5060 (Plug & Play)INBOUND: NO port openings, no port forwardingThe SBC only ever connects outwards – that is its whole purpose.!The SBC is NOT a provisioning server: the phones fetch their configuration directlyvia 443/TCP from the cloud PBX. The phone network therefore needs internet access.Colour code: ▬ outbound (orange) ▬ local LAN (teal) ▬ not needed (grey)
DirectionPort(s)PurposeWhen / what to watch
none / not needed inbound: NONE No port forwarding, no inbound rule Always applies – the SBC only ever connects outwards.
outbound 5090 TCP + UDP 3CX tunnel: SIP and RTP bundled to the cloud PBX Always. Open TCP AND UDP.
outbound 443 TCP (alt. 5001) HTTPS to the PBX: provisioning, auth, firmware Always – for SBC, phones and apps.
outbound 123 UDP · 53 UDP/TCP NTP and DNS for SBC and phones Always. Without correct time, TLS validation fails during provisioning.
outbound 80 / 443 TCP Phone vendor RPS Only for the first provisioning of factory-new or reset phones.
local / LAN 5060 UDP + RTP SIP and media between phone and SBC Uncritical on the same network. With VLAN separation see diagram 3.
local / LAN 224.0.1.75 : 5060 UDP Plug & Play (SIP multicast, NOT mDNS/5353) Works only within the same layer-2 segment.
none / not needed 5060/5061 · 9000–10999 · 3478 Deliberately keep closed when using an SBC SIP and RTP travel encapsulated in the tunnel – which reduces the attack surface considerably.
3

Cloud PBX + SBC with VLAN segmentation

SBC in VLAN 2, phones in VLAN 3, workstations in VLAN 1. In addition to the perimeter firewall, ports now have to be opened in the layer-3 switch or the internal firewall as well.

☁ 3CX PBX in the 3CX cloudpbx.firma.3cx.dePERIMETER FIREWALL · inbound: NO openingsVLAN 3 · TELEFONIE☎ IP desk phonesVLAN 2 · SERVER⇄ 3CX SBCVLAN 1 · DATEN▭ Workstations / clients◀ L3-SWITCH ▶◀ L3-SWITCH ▶internal rules:OUTBOUND · PHONES443 TCP (provisioning)123 UDP · 53 UDP/TCPOUTBOUND · SBC5090 TCP + UDP443 TCPOUTBOUND · APPS443 TCPVLAN 3 → VLAN 25060 UDP (SIP to the SBC)RTP – no documented range,in practice dyn. UDP to the SBC IPVLAN 2 → VLAN 35060 + ephemere UDP(only with static ACLs)VLAN 1 → VLAN 2 : KEINEApps go straight to the cloud –the SBC is not needed.VLAN 1 → VLAN 380 TCP – legacy CTI (phone control). NOT needed with uaCSTA (V18/V20).!Plug & Play (SIP-Multicast 224.0.1.75:5060) istNOT routable and not supported by 3CX acrossVLAN boundaries. Substitute: DHCP option 66, vendor RPSor the SBC in the phone VLAN.!3CX support: the SBC should sit in the same network as thephones. This separation works, but isnot supported.iAlso needed: DHCP relay (ip helper-address) into thephone VLAN for option 66 / 132.Colour code: ▬ outbound (orange) ▬ between VLANs (teal) ▬ not needed / not possible (grey)
DirectionPort(s)PurposeWhen / what to watch
between VLANs 5060 UDP (ggf. TCP) VLAN 3 → VLAN 2: SIP to the SBC as outbound proxy Always. By default the SBC listens on 5060/UDP for local endpoints.
between VLANs no documented range – in practice dyn. UDP VLAN 3 → VLAN 2: RTP/media to the SBC 3CX publishes NO RTP range for the SBC. 9000–10999 applies to the PBX media server, not the SBC. In practice, open the dynamic UDP range specifically towards the SBC IP.
between VLANs 5060 + ephemere UDP VLAN 2 → VLAN 3: return direction SIP/RTP Covered by the forward rule on stateful firewalls; explicitly needed with static ACLs.
none / not needed 224.0.1.75 : 5060 UDP Plug & Play – not routable Multicast does not cross VLAN boundaries. 3CX states PnP across VLANs is unsupported. An mDNS repeater does NOT help (it only reflects 224.0.0.251:5353).
outbound 443 TCP VLAN 3 → internet: provisioning and firmware Mandatory. The SBC is not a provisioning server – the phones fetch their config directly from the cloud.
between VLANs 67 / 68 UDP (DHCP-Relay) VLAN 3 → DHCP: option 66 or 132/133 The recommended substitute for PnP. Note: Option 66 overrides PnP – do not run both in parallel.
between VLANs 80 TCP VLAN 1 → VLAN 3: legacy CTI (phone control) Only in the old CTI mode. Not needed with modern uaCSTA.
none / not needed VLAN 1 → VLAN 2: none Apps do not need to reach the SBC The 3CX apps register directly with the cloud PBX.
4

Internally hosted PBX with VLAN segmentation

The 3CX PBX sits in the server VLAN, phones and workstations in their own VLANs. The return direction server → phones matters most here – and is easily forgotten.

SIP trunk / VoIP provider3CX cloud servicesActivation · updates · pushRemote apps / home officePERIMETER-FIREWALLVLAN 3 · TELEFONIE☎ IP desk phonesVLAN 2 · SERVER■ 3CX PBX (on-premises)VLAN 1 · DATEN▭ Workstations / clientsVLAN M · MANAGEMENT⚙ Admin workstations◀ L3-SWITCH ▶◀ L3-SWITCH ▶◀ L3-SWITCH ▶internal rules:PERIMETERein: 5060/5061 · 9000–10999 · 443 · 5090out: 443 (cloud) · 3478 · 53 · 123VLAN 3 → VLAN 25060 UDP + TCP · 5061 TLS9000–10999 UDP (RTP)443 TCP (provisioning)VLAN 2 → VLAN 3 ⚠ OFT VERGESSEN5060 UDP/TCP – SIP NOTIFY:check-sync, BLF, Voicemail-LED+ RTP return path to the phoneVLAN 1 → VLAN 2443 TCP (alt. 5001)9000–10999 UDP (WebRTC)5090 TCP+UDP (optional)VLAN M → VLAN 2443 TCP (Konsole)22 TCP (SSH, Debian)5015 TCP (setup only)VLAN 1 → VLAN 380 TCP – legacy CTI. Not needed with uaCSTA (V18/V20).!Split DNS is mandatory for V20on-premises: the FQDN must resolve in EVERYVLAN to the internal server IP– otherwise NAT hairpinning andeinseitiges Audio.!Plug & Play (224.0.1.75:5060) istnot routable. Substitute: DHCP option66 + DHCP-Relay.Colour code: ▬ inbound (blue) ▬ outbound (orange) ▬ between VLANs (teal)
DirectionPort(s)PurposeWhen / what to watch
between VLANs 5060 UDP + TCP · 5061 TLS VLAN 3 → VLAN 2: SIP registration and signalling Always. TLS only with SIP/TLS and SRTP.
between VLANs 9000–10999 UDP VLAN 3 ↔ VLAN 2: RTP to the media server Always. 3CX has only ONE media server range – internal and external alike, not configurable. Calls between two phones in the same VLAN do not cross the boundary.
between VLANs 443 TCP (alt. 5001) VLAN 3 → VLAN 2: provisioning, firmware, phone book Always. There is no separate provisioning port – it is the PBX web server port.
between VLANs 5060 UDP/TCP ⚠ VLAN 2 → VLAN 3: SIP NOTIFY (check-sync, BLF, voicemail LED) Always – and the most common mistake. Without this rule calls still work, but reprovisioning, BLF keys and the voicemail indicator do not.
between VLANs 443 TCP · 9000–10999 UDP VLAN 1 → VLAN 2: web client / desktop app incl. WebRTC Always when workstations sit in their own VLAN.
between VLANs 22 · 443 · 5015 TCP Management VLAN → VLAN 2: SSH, console, setup wizard V20 runs on Debian 12 only – RDP/3389 is gone. 5015 only temporarily during setup.
between VLANs 53 UDP/TCP ⚠ All VLANs → DNS: split DNS Mandatory for V20 on-premises. The FQDN must resolve to the internal server IP in EVERY VLAN, otherwise traffic hairpins through the firewall and you typically get one-way audio.
between VLANs 80 TCP VLAN 1 → VLAN 3: legacy CTI Only in the old CTI mode. ‘Same subnet’ is a simplification – routing plus a port rule is enough.
5

Outbound connections to the 3CX cloud services

Applies to every self-hosted PBX. All destinations use 443/TCP – but three of them must not pass through TLS inspection.

■ 3CX PBXOn-Premise oder eigener ServerFIREWALL – AUSGEHENDactivate.3cx.comLicence activation & verification443 TCP⚠ allow without SSL inspectiondiscoverv4.3cx.comDiscovery / FQDN resolution443 TCP⚠ allow without SSL inspectionpbxservicespush.3cx.comPBX push service443 TCP⚠ allow without SSL inspectiondownloads-global.3cx.comUpdates, Service Packs, Firmware443 TCPrps.3cx.comRemote provisioning of the phones443 TCPmailproxy.3cx.comE-Mail-Versand (Voicemail u. a.)443 TCPwmr.3cx.netWebMeeting & Transkription443 TCPstun2.3cx.comSTUN – NAT-Erkennung3478 UDPApple APNsPush to iOS apps443 · 2197 · 5223 TCPGoogle FCMPush to Android apps443 TCP!All cloud services use 443/TCP.Three of them must NOT pass throughTLS-Inspection (Deep Packet Inspection)TLS inspection – or activation andPush fehl.
DirectionPort(s)PurposeWhen / what to watch
outbound activate.3cx.com : 443 Licence activation and verification Always. ⚠ Allow without SSL inspection.
outbound discoverv4.3cx.com : 443 Discovery / FQDN resolution Always. ⚠ Allow without SSL inspection.
outbound pbxservicespush.3cx.com : 443 Push service – wakes the smartphone apps When apps are used. ⚠ Allow without SSL inspection.
outbound downloads-global.3cx.com : 443 Updates, service packs, phone firmware Always.
outbound rps.3cx.com : 443 Remote provisioning of IP phones Only with RPS provisioning.
outbound mailproxy.3cx.com : 443 E-mail delivery (voicemail, system messages) Always when the 3CX mail proxy is used.
outbound wmr.3cx.net : 443 WebMeeting and transcription Only for video conferencing. The transcription return channel comes from wmr-in.3cx.net (34.40.92.110).
outbound stun2.3cx.com : 3478 UDP STUN – NAT detection, Firewall Checker When operating behind NAT.
outbound Apple APNs : 443 · 2197 · 5223 Push to iOS apps Only with iPhone/iPad apps.
outbound Google FCM : 443 Push to Android apps Only with Android apps.
6

The complete port list in one table

All 79 rules from the five scenarios in one piece – grouped by use case, with purpose, condition, endpoint and bindingness. For looking things up and ticking them off during firewall configuration.

Port(s)ProtocolDirectionPurpose & notesEndpoint / targetStatus
A · INBOUND to the 3CX PBX (self-hosted / on-premises / own cloud server)
5060UDPinboundSIP signalling: registration, call set-up and tear-down (default port, unencrypted).Whenever a SIP trunk or external phones talk to the PBX directly (without tunnel/SBC). Recommendation: restrict to the SIP provider’s IP ranges to avoid scans and attacks.SIP provider / external phonesRequired
5060–5061TCPinboundSIP over TCP (5060) or SIP over TLS = encrypted signalling (5061).Only if the trunk or the endpoints use SIP over TCP or SIP-TLS instead of UDP. Not needed with a pure UDP trunk.SIP provider / external phonesConditional
9000–10999UDPinboundRTP – the actual voice and video stream (the call audio). Each simultaneous call occupies 2 ports.Always for external voice traffic without the 3CX tunnel. The range can be reduced for few lines, but must hold at least 2× the number of simultaneous calls.SIP provider / external phonesRequired
5090TCP AND UDPinbound3CX tunnel protocol: encapsulates SIP + RTP in a single connection. Endpoint for 3CX SBCs, apps and 'router phones'.Whenever a 3CX SBC, remote apps (desktop/smartphone) or remote phones are used. IMPORTANT: open TCP AND UDP – TCP alone leads to one-way audio.3CX SBC / apps (any IP)Required for SBC/apps
443 (alternatively 5001)TCPinboundHTTPS: web client, management console, presence, endpoint provisioning, WebRTC.Always for access from outside. 443 is the default from V20, 5001 the alternative/older HTTPS port. Must be reachable from 'ANY' (home office, hotel, on the road) – do not restrict to fixed IPs.Any clients (internet)Required
443TCPinboundVideo conferencing: external participants connect to the PBX through their browser.Only when using 3CX Meet / video conferencing. Identical to the HTTPS port above – no extra rule if 443 is already open.Conference participants (internet)Conditional
443TCPinboundReturn channel of the 3CX transcription service to the PBX.Only if call recording with transcription is used. Source can be restricted to wmr-in.3cx.net (34.40.92.110).wmr-in.3cx.net (34.40.92.110)Optional
80TCPinboundHTTP: validation of the Let's Encrypt certificate (ACME HTTP-01) and redirect to HTTPS.Practical recommendation for automatic certificate renewal. Not explicitly documented by 3CX as a firewall requirement, but regularly needed in practice.Let's Encrypt / internetRecommended
5000TCPinboundAlternative HTTP port of the PBX (older default).Only with a deviating port configuration. Per 3CX: never assign 443 to HTTP or 80 to HTTPS – firewalls will not work correctly otherwise.Any clientsSpecial case only
5062 (5061 in rare cases)TCPinboundSIP signalling for Microsoft Teams Direct Routing.Only with Teams Direct Routing. Also required: a public DNS A record to a static IP and a certificate from a Microsoft-recognised CA.Microsoft Teams / MS cloudSpecial case only
5015TCPinboundWeb configuration wizard during the initial installation of the PBX.Only during initial set-up; close again afterwards. Documented only in community sources, not in the official firewall docs.Admin workstationSet-up only
B · OUTBOUND from the 3CX PBX (self-hosted – destination: 3CX cloud & provider)
443TCPoutboundLicence activation and periodic licence verification.Always. CAUTION: allow without SSL/TLS inspection (uninspected) – otherwise activation fails.activate.3cx.comRequired
443TCPoutbound3CX discovery service (FQDN/instance resolution).Always. Likewise allow without SSL inspection.discoverv4.3cx.comRequired
443TCPoutboundDownload of updates, service packs and phone firmware.Always, so the PBX can update itself.downloads-global.3cx.comRequired
443TCPoutboundRPS – Remote Provisioning Service: remote configuration of IP phones through the vendor cloud.Only if phones are provisioned via RPS outside the LAN.rps.3cx.comConditional
443TCPoutboundE-mail delivery (voicemail notifications, system messages, conference invitations) via the 3CX mail proxy.Always when the 3CX mail server is used instead of your own SMTP server.mailproxy.3cx.comRequired (default)
443TCPoutboundPBX push service – wakes the smartphone apps on incoming calls.Always when smartphone apps are used. Allow without SSL inspection.pbxservicespush.3cx.comRequired for apps
443TCPoutboundWebMeeting/video conferencing service and transcription in the 3CX cloud.Only when using video conferencing or transcription.wmr.3cx.netConditional
443TCPoutboundPush notifications to Android apps via Google Firebase (FCM).Only when Android apps are used.Google FCMConditional
443, 2197, 5223TCPoutboundPush notifications to iOS apps via Apple APNs.Only when iPhone/iPad apps are used. Open all three ports.Apple APNsConditional
48000–65535UDPoutboundMedia stream (audio/video) of the video conference between PBX/participants and the 3CX cloud.Only when using 3CX Meet / video conferencing.3CX WebMeeting cloudConditional
5060 (or 5061 TLS)UDP / TCPoutboundSIP signalling to the VoIP provider (return direction of the inbound trunk).Always with a SIP trunk. Usually covered by the inbound rule on stateful firewalls; explicitly needed with a restrictive outbound rule set.SIP providerRequired
9000–10999UDPoutboundRTP voice data to the VoIP provider.Always for external voice traffic; open explicitly with a restrictive outbound rule set.SIP providerRequired
3478UDPoutboundSTUN – determines the public IP / NAT type; used among others by the 3CX Firewall Checker.When operating behind NAT and for the firewall check. Default STUN server: stun2.3cx.com.stun2.3cx.comRecommended
53UDP / TCPoutboundDNS – resolution of the PBX's own FQDN, the 3CX cloud services and the provider.Always. Technically essential, but not documented by 3CX as a separate firewall requirement.DNS serverRequired (technical)
123UDPoutboundNTP – time synchronisation. A wrong system time breaks TLS certificates and licence verification.Always. Technically essential, not documented by 3CX as a separate firewall requirement.NTP serverRequired (technical)
25 / 587 / 465TCPoutboundSMTP directly to your own mail server (instead of via mailproxy.3cx.com).Only if your own SMTP server is configured. The port depends on the mail server (25 = plain, 587 = STARTTLS, 465 = SMTPS).Own SMTP serverOptional
2528TCPoutboundOld 3CX SMTP relay port for mail delivery.Legacy systems up to V18 only. From V20, mail goes via mailproxy.3cx.com on port 443 – then no longer needed.3CX SMTP relayLegacy only
C · SITE WITH 3CX SBC / DESK PHONES (rules in the site firewall)
NONEinboundAt a site with an SBC, NO inbound port openings and NO port forwarding are needed.Always applies: the SBC connects exclusively outwards to the PBX. That is the main advantage of the SBC over directly registered phones.Note
5090TCP AND UDPoutbound3CX tunnel from the SBC to the PBX – carries SIP signalling AND RTP voice data bundled.Whenever an SBC is used. Open TCP AND UDP – TCP alone leads to one-way audio.FQDN of the 3CX PBXRequired
443 (or 5001)TCPoutboundHTTPS to the PBX: provisioning of the SBC and the phones, authentication, firmware updates.Always. Which port applies depends on the instance – 443 for 3CX-hosted, often 5001 for older self-hosted installations. Visible in the management console URL.FQDN of the 3CX PBXRequired
53UDP / TCPoutboundDNS – resolution of the 3CX PBX FQDN.Always.DNS serverRequired
123UDPoutboundNTP – time synchronisation for SBC and phones.Recommended. Phones can alternatively obtain the time via a DHCP option.NTP serverRecommended
80 / 443TCPoutboundThe phone vendor’s RPS (Yealink, Fanvil, Snom …) at the very first provisioning.Only for first provisioning of factory-new or factory-reset phones. Not needed in normal operation.Vendor's RPS serverFirst set-up only
5060UDP (TCP if used)LAN-internal onlySIP between phone and SBC on the local network. The phone uses the SBC LAN IP as its outbound proxy.Always with an SBC. With an SBC on Windows, the local Windows firewall must allow this port.Phone → SBC (LAN)LAN-internal
224.0.1.75 : 5060UDP (multicast)LAN-internal onlyPlug & Play / autodiscovery: the phone sends a SIP SUBSCRIBE to multicast address 224.0.1.75, the SBC reports the find to the PBX. 3CX does NOT use mDNS/5353 for PnP.Only for Plug & Play. Works exclusively within the same layer-2 segment – not across VLAN/subnet boundaries (see sections F/G). The switch must flood unknown multicast or have IGMP snooping configured accordingly.Phone → 224.0.1.75 (LAN)LAN-internal
no fixed rangeUDPLAN-internal onlyRTP/media between phone and SBC – the SBC relays the voice data into the tunnel.Always during calls. CAUTION: 3CX publishes NO port range for the SBC towards local phones (9000–10999 is the range of the PBX media server, not the SBC). Uncritical within one segment – relevant only with VLAN separation (section F).Phone ↔ SBC (LAN)LAN-internal
80TCPLAN-internal onlyCTI / phone control: the 3CX client controls the desk phone (legacy CTI via HTTP command directly to the phone IP).Only in the old CTI mode. Modern uaCSTA (V18/V20) controls the phone through the existing SIP registration from the PBX – then no client→phone rule is needed.Client → phone (LAN)LAN-internal
D · 3CX-HOSTED INSTANCE (3CX-hosted / StartUP – rules in the customer firewall)
NONEinboundWith 3CX-hosted instances, NO inbound rules are needed in the customer firewall.Always applies – all connections are opened outwards from the customer network. Note: the 'inbound' column of the 3CX docs refers to the server; in the hosted model it corresponds to OUTBOUND rules at the customer.Note
5090TCP AND UDPoutbound3CX tunnel to the hosted PBX – for SBC, apps and router phones.Whenever an SBC or apps are in use.FQDN of the hosted PBXRequired
443TCPoutboundHTTPS: web client, provisioning, WebRTC, video conferencing.Always.FQDN of the hosted PBXRequired
9000–10999UDPoutboundRTP voice data between endpoints/web client and the hosted PBX.Always when phones or the web client talk to the PBX directly (without tunnel).FQDN/IP of the hosted PBXRequired
5060 (or 5061 TLS)UDP / TCPoutboundSIP signalling when phones register directly with the hosted PBX.Only if NO SBC/tunnel is used. With an SBC everything runs over 5090.FQDN/IP of the hosted PBXConditional
48000–65535UDPoutboundVideo conference media stream from the workstation to the 3CX WebMeeting cloud.Only when video conferencing is used from the customer network.3CX WebMeeting cloudConditional
E · NOT NEEDED when using the 3CX SBC / tunnel (deliberately keep closed)
5060 / 5061UDP / TCPinboundSIP – with an SBC it travels encapsulated in the tunnel (port 5090).Do not open if only the SBC/tunnel is used. Reduces the attack surface considerably.Not needed
9000–10999UDPinboundRTP – likewise travels in the tunnel when an SBC is used.Do not open if only the SBC/tunnel is used.Not needed
3478UDPoutboundSTUN – no NAT traversal detection needed at the SBC site, as only outbound connections are made.Not needed at the SBC site (though possibly at the PBX itself).Not needed
F · VLAN SEGMENTATION with CLOUD PBX + SBC on site (rules in the layer-3 switch / internal firewall)
5060UDP (TCP if used)inter-VLANSIP registration and signalling: the phone uses the SBC LAN IP as its outbound proxy.Always when phones and SBC sit in separate VLANs. By default the SBC listens on 5060/UDP for local SIP endpoints.VLAN 3 (phones) → VLAN 2 (SBC)Required
no documented range – in practice UDP 1024–65535UDPinter-VLANRTP/media between phone and SBC. The SBC accepts the phone’s voice data and forwards it through the tunnel to the cloud PBX.Always during calls. CAUTION: 3CX publishes NO RTP port range for the SBC towards local phones – the well-known 9000–10999 applies to the PBX media server, not the on-site SBC process. In practice, open the dynamic UDP range specifically towards the SBC IP.VLAN 3 (phones) → VLAN 2 (SBC)Required
5060 + ephemeral UDP portsUDPinter-VLANReturn direction of SIP and RTP from the SBC to the phone.Covered by the forward rule on stateful firewalls. Open explicitly only with purely static ACLs (e.g. on a layer-3 switch without session tracking).VLAN 2 (SBC) → VLAN 3 (phones)Conditional
224.0.1.75 : 5060UDP (multicast)inter-VLANPlug & Play / autodiscovery of the phones by the SBC (SIP multicast, NOT mDNS/5353).DOES NOT WORK across VLAN boundaries. Multicast is not routable without multicast routing, and an mDNS repeater/reflector does not help (it only reflects 224.0.0.251:5353). 3CX explicitly states PnP across VLANs is unsupported. Solution: put the SBC in the phone VLAN OR use DHCP option 66 / RPS / a manual provisioning URL.VLAN 3 → VLAN 2 (not routable)Not possible
443 (old: 5001)TCPinter-VLAN / outboundProvisioning and firmware: the phones fetch their configuration DIRECTLY from the cloud PBX – the SBC is not a provisioning server and has no web GUI.Always. The phone VLAN strictly needs outbound internet access on 443/TCP to the PBX FQDN – otherwise no phone provisions. With 3CX hosting, HTTP+IP is not possible, only HTTPS+FQDN.VLAN 3 (phones) → internet / PBX FQDNRequired
53UDP / TCPinter-VLANDNS – resolution of the PBX FQDN by the phones (mandatory with HTTPS provisioning; an IP is not enough).Always. Allow towards the internal resolver or the internet.VLAN 3 → DNS resolverRequired
123UDPinter-VLAN / outboundNTP – time synchronisation of the phones. 3CX provisions pool.ntp.org by default.Always. Without correct time, the TLS/certificate check fails during provisioning.VLAN 3 → NTP server / internetRequired
67 / 68 (DHCP relay)UDPinter-VLANDHCP relay ('ip helper-address') in the phone VLAN: address assignment and delivery of option 66 (provisioning URL) or options 132/133 (VLAN ID/priority).Always when the DHCP server is not in the phone VLAN. Option 66 is the recommended PnP substitute with VLAN separation. Note: option 66 overrides PnP – do not run both in parallel.VLAN 3 → DHCP serverRequired
80TCPinter-VLANLegacy CTI: the 3CX client on the workstation sends HTTP commands directly to the desk phone IP.Only in the old CTI mode. Works routed across VLANs (routing + port rule are enough), even though 3CX writes 'same network'. NOT needed with modern uaCSTA (V18/V20) – there the PBX controls the phone through the SIP registration.VLAN 1 (clients) → VLAN 3 (phones)Conditional
NONEinter-VLANThe 3CX desktop/web apps do NOT need to reach the SBC – they register directly with the cloud PBX.Always applies. The SBC is intended exclusively for IP desk phones. No clients → SBC rule needed.VLAN 1 (clients) → VLAN 2 (SBC)Not needed
80 / 443TCPinter-VLANWeb interface of the phones for administrative access.Optional, only if admins should reach the phone web interfaces from the data/management VLAN.Management VLAN → VLAN 3 (phones)Optional
443 / 80TCPoutboundThe phone vendor’s RPS (Yealink/Fanvil/Snom) at the first boot of factory-new devices.Only with RPS provisioning. Often the most practical route with VLAN separation, since PnP is unavailable. The vendors’ destination addresses are not documented by 3CX.VLAN 3 (phones) → internetFirst set-up only
G · VLAN SEGMENTATION with INTERNALLY HOSTED 3CX PBX (rules in the layer-3 switch / internal firewall)
5060UDP + TCPinter-VLANSIP registration and signalling of the desk phones to the PBX.Always. UDP is the default transport; TCP additionally if phones are configured for SIP/TCP.VLAN 3 (phones) → VLAN 2 (3CX)Required
5061TCPinter-VLANSIP over TLS – encrypted signalling.Only if SIP/TLS and SRTP are in use.VLAN 3 (phones) → VLAN 2 (3CX)Conditional
9000–10999UDPinter-VLANRTP/audio between phone and the PBX media server. 2 ports per call.Always. IMPORTANT: 3CX has only ONE media server range – it applies internally and externally and is not officially configurable. Calls between two phones in the same VLAN run endpoint-to-endpoint and do not cross the boundary.VLAN 3 (phones) ↔ VLAN 2 (3CX)Required
443 (old: 5001)TCPinter-VLANHTTPS: phone provisioning, firmware, phone book. There is NO separate provisioning port – it is the PBX web server port.Always. Which port applies was set during installation (443 recommended, 5001 as the alternative).VLAN 3 (phones) → VLAN 2 (3CX)Required
80 (old: 5000)TCPinter-VLANHTTP provisioning via the PBX IP address.Only if an HTTP provisioning URL is used. Permitted by 3CX exclusively for local phones in RFC1918 networks – remote phones must use HTTPS+FQDN.VLAN 3 (phones) → VLAN 2 (3CX)Conditional
5060 (the phone's SIP port)UDP / TCPinter-VLANReturn direction: the PBX sends SIP NOTIFY to the phones – 'check-sync' (restart/reprovisioning), 'ua-profile', BLF status updates and MWI (voicemail lamp).Always. Often forgotten – the symptom is that reprovisioning, BLF keys and the voicemail indicator stop working. The server does not push configuration – the phone fetches it itself after the NOTIFY.VLAN 2 (3CX) → VLAN 3 (phones)Required
the phone's RTP range (vendor-specific)UDPinter-VLANReturn direction of the RTP stream: the PBX sends from 9000–10999 to the phone’s RTP port (e.g. Yealink ~11780–11800, Snom from 49152).Covered by the forward rule on stateful firewalls. With purely static ACLs, look up the RTP range of the deployed phones in the manual and open it.VLAN 2 (3CX) → VLAN 3 (phones)Conditional
443 (old: 5001)TCPinter-VLANWeb client and desktop app: HTTPS + WebSocket, sign-in, presence, client updates.Always when workstations sit in their own VLAN.VLAN 1 (clients) → VLAN 2 (3CX)Required
9000–10999UDPinter-VLANWebRTC media of the softphone in the web client / desktop app.Always when clients phone in softphone mode. (In practice the WebRTC share sits in the sub-range 10500–10999 – not officially documented, do not use as a filter criterion.)VLAN 1 (clients) → VLAN 2 (3CX)Required
5090TCP + UDPinter-VLAN3CX tunnel – normally not needed internally, as the web client uses WebRTC over 443.Optional. 3CX does not state whether 5090 is needed internally. The rule is harmless and saves troubleshooting if a client falls back to tunnel mode.VLAN 1 (clients) → VLAN 2 (3CX)Optional
80TCPinter-VLANLegacy CTI: the 3CX client sends HTTP commands directly to the desk phone IP.Only in the old CTI mode. Works routed across VLANs. Not needed with modern uaCSTA – there control runs through the SIP registration from the PBX.VLAN 1 (clients) → VLAN 3 (phones)Conditional
224.0.1.75 : 5060UDP (multicast)inter-VLANPlug & Play / autodiscovery of the phones by the PBX (SIP multicast, NOT mDNS/5353).DOES NOT WORK across VLAN boundaries – 3CX names 'phone and PBX in the same local subnet' as a PnP prerequisite and explicitly advises against PnP across VLANs. Substitutes: DHCP option 66, a manual provisioning URL, RPS, or an SBC in the phone VLAN.VLAN 3 → VLAN 2 (not routable)Not possible
53UDP / TCPinter-VLANDNS – strictly with SPLIT DNS: the PBX FQDN must resolve to the internal server IP in EVERY VLAN.Always. If a VLAN resolves the FQDN to the public IP, the PBX writes the public IP into the SDP and voice traffic hairpins through the firewall – typical result: one-way audio. 3CX V20 strictly requires split DNS on-premises.All VLANs → DNS resolverRequired
123UDPinter-VLANNTP – time synchronisation of phones and clients.Always. Wrong time leads to certificate errors and wrong call times.VLAN 1 + VLAN 3 → NTP serverRequired
67 / 68 (DHCP relay)UDPinter-VLANDHCP relay ('ip helper-address') in the phone VLAN – address assignment and option 66 (provisioning URL) or 132/133 (VLAN ID/priority).Always when the DHCP server is not in the phone VLAN. Option 66 is the recommended PnP substitute with VLAN separation.VLAN 3 → DHCP serverRequired
443 (old: 5001)TCPinter-VLANAccess to the PBX management console.Always when administration happens from a management VLAN.Management VLAN → VLAN 2 (3CX)Required
22TCPinter-VLANSSH – administration of the Debian operating system (V20 runs exclusively on Debian 12; RDP/3389 is gone, Windows is no longer supported).Optional, for OS administration. Not documented in any 3CX port list. Restrict access to the management VLAN where possible.Management VLAN → VLAN 2 (3CX)Optional
5015TCPinter-VLANWeb configuration wizard during initial installation.Only temporarily during first set-up, block again afterwards.Management VLAN → VLAN 2 (3CX)Set-up only
80 / 443TCPinter-VLANWeb interface of the phones for administrative access. The PBX itself does NOT access it – the link opens in the admin’s browser.Optional, only for administrative access from the management/data VLAN.Management VLAN → VLAN 3 (phones)Optional
443TCPoutboundOutbound connections of the PBX to the 3CX cloud services (see section B) – from the server VLAN to the internet.Always. In segmented networks, remember that the server VLAN also needs a route to the internet.VLAN 2 (3CX) → internetRequired

Pitfalls & best practice

Disable SIP ALG

The „SIP helper“ in routers and firewalls manipulates SIP packets and is the most common cause of one-way audio and dropped calls. Switch it off in every scenario.

Port 5090 always TCP and UDP

Only TCP opened? The tunnel comes up, but audio flows in one direction only. Always open both protocols.

Exempt from SSL inspection

activate.3cx.com, discoverv4.3cx.com and pbxservicespush.3cx.com must pass uninspected – breaking TLS makes activation and push fail.

Keep 443 and 5090 reachable from ANY

Staff connect from home offices, hotels and mobile networks. Only the SIP ports (5060/5061) can sensibly be restricted to the provider’s IPs.

Size the RTP range correctly

Each simultaneous call occupies 2 UDP ports. The default range 9000–10999 covers up to 1,000 calls.

An SBC saves port openings

With a 3CX SBC on site, all inbound rules disappear: SIP and RTP travel encapsulated through the outbound tunnel on port 5090.

Think differently for hosted instances

The 3CX docs list ports from the server’s point of view. With a 3CX-hosted PBX these become outbound rules in your firewall – nothing inbound is needed.

Use the Firewall Checker

After configuration, run the 3CX Firewall Checker: it tests the PBX side and reports missing rules and active SIP ALG.

Plug & Play ends at the VLAN boundary

3CX uses SIP multicast (224.0.1.75:5060) for phone discovery – not mDNS. Multicast is not routable: with VLAN separation, provision via DHCP option 66 or RPS instead.

No appetite for firewall rules?

Understandable. We configure firewall and PBX in one pass – including a SIP-ALG check, a Firewall Checker run and clean documentation of the rules. As a WatchGuard and 3CX partner we know both sides. Talk to us.

3CX ports & firewall – answered briefly

Which ports have to be opened for a 3CX system?

For a self-hosted PBX, inbound: 5060/UDP (SIP), 5061/TCP (SIP-TLS), 9000–10999/UDP (RTP voice data), 5090/TCP+UDP (3CX tunnel for apps and SBC) and 443/TCP (HTTPS, web client, provisioning). Outbound rules to the 3CX cloud services come on top. The complete list by scenario is above in the technical section.

Which ports does the 3CX SBC need on site?

Outbound only: 5090/TCP+UDP (tunnel to the PBX), 443/TCP (provisioning) plus DNS and NTP. No inbound rules or port forwarding are needed at the SBC site – the SBC opens all connections outwards itself.

Which ports have to be opened for a 3CX-hosted instance?

In the customer firewall, outbound rules only: 5090/TCP+UDP, 443/TCP, 9000–10999/UDP and – without an SBC – 5060/UDP to the PBX FQDN. Nothing needs to be opened inbound.

Why can’t the other party hear me (one-way audio)?

The two most common causes: SIP ALG is still active in the router or firewall, or port 5090 was opened for TCP only instead of TCP and UDP. Then run the 3CX Firewall Checker.

Does 3CX Plug & Play work across VLAN boundaries?

No. Phone discovery uses SIP multicast on 224.0.1.75:5060, and multicast is not routable without multicast routing. In segmented networks, provision via DHCP option 66 or the phone vendor’s RPS instead – or put the SBC in the phone VLAN.

Did the port list change with 3CX V20?

No. No firewall port changes are documented between V18 and V20; the RTP range remains 9000–10999/UDP. The only novelty is that 443 has replaced 5001 as the default HTTPS port.

3CX from the partner who knows both sides

As a 3CX and WatchGuard partner we configure PBX and firewall in one pass – cleanly documented and verified with the Firewall Checker.