For baseline needs, see Minimum Network Requirements.
For locations where device security is a concern, we encourage phones be given their own sequestered network (VLAN and Subnet), behind a firewall and/or NAT, and have zero inbound ports configured. It is preferred, to ensure phones are able to react to upstream changes via DNS, that they be allowed to talk to the internet largely unfettered. But we are aware that in some environments, such freedom isn't possible.
We provide the tables below with these caveats:
Security rules should allow the following outbound connections from each phone:
RTC Voice Cloud (Required for SIP Communication)
Yealink YMCS Phone Manager (Required for ZTP and Orchestration)
Direction | Destination | Protocol / Port | Purpose |
|---|---|---|---|
Outbound |
| TCP 443 | YMCS resource/API access |
Outbound |
| TCP 443 | Firmware update checks |
Outbound |
| TCP 8110 | Device Management (DM) protocol |
Outbound |
| TCP 443, 5061 | Redirection Provisioning Service (RPS) — zero-touch provisioning |
Outbound | 20.242.144.2 (no published hostname) | TCP/UDP 9701, 9713–9736 | Remote Control / diagnostics (optional) |
Receiving Configuration Updates
Receiving Software Updates
Receiving Calls
Initiating Calls