Purpose Src. IP Src. ports Protocol Dest. IP Dst. Ports
Assent RTCP
(traversed
media)
SIPendpoint
(or its
firewall)
>=1024
Could be translated by
the firewall to port where
the media egressed,
rather than an endpoint
port
UDP Expressway-
E
36000-59999
Assent RTP
(traversed
media)
Expressway-
E
36000-59999 UDP SIPendpoint
(or its
firewall)
>=1024
Expressway waits until it
receives media, then sends
media to that source port
(which could be the port where
the media egressed the firewall,
not an endpoint port)
TURNcontrol Any
IPaddress
†
>=1024 (signaling port
from endpoint or the
firewall)
UDP
&TCP
Expressway-
E
3478 (Small/Medium)
3478-3483 (Large)
TURNmedia
Expressway-
E
24000-29999 UDP
&TCP
Any
IPaddress
>=1024
TURNmedia Any
IPaddress
‡
>=1024
Port of relevant
ICEcandidate:host
IPport, server reflexive
port (outside firewall
port), or TURNserver
port
UDP
&TCP
Expressway-
E
24000-29999
Table 9 SIPCalls Port Reference (continued)
† The request could be from any IPaddress, unknown to the TURNserver. Assume for example, that endpoint A and
endpoint C (TURNclients) in the diagram can use the Expressway-E TURNserver. The actual IPaddress from which
the TURNserver receives the request could be the endpoint's firewall egress address (NATed).
‡ The media could go to any of the candidate addresses. For example, before ICEnegotiation the TURNserver does
not know which of endpoint B's candidate addresses will be the highest priority.
Note:The endpoints A, B, and C in the diagram only show media connections to avoid unnecessary lines. They would
use the same signaling connections as shown for the other endpoints / bridges.
17
Cisco Expressway IP Port Usage Configuration Guide