> For the complete documentation index, see [llms.txt](https://docs.pascom.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.pascom.net/en/reference/port-overview.md).

# Port Overview | Firewall Configuration

Here you will find an overview of the necessary port clearances in your firewall.

## Configure your firewall

Many companies have **no restricted Internet access** and can therefore use the **PASCOM server** immediately, without any adjustment to the firewall.

However, if you specify exactly which Internet services your company network may access, please activate the following ports in your firewall to allow smooth operation of the [PASCOM cloud phone system](https://www.pascom.net/en/)

![Port Overview Cloud](https://2713225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVIw0BpSv358R2Pr2HflD%2Fuploads%2Fgit-blob-ff42f737aa8a70d2dc76384c31a5fac412035056%2Fport_overview_cloud.png?alt=media)

| Port              | Function                                                               | Device              | Source       | Target                                                                                                           |
| ----------------- | ---------------------------------------------------------------------- | ------------------- | ------------ | ---------------------------------------------------------------------------------------------------------------- |
| 123/UDP/TCP       | Access to TimeServer (NTP)                                             | 🖥️ 📱 📞           | Your Network | pool.ntp.org                                                                                                     |
| 5061/TCP          | SIP-Connection                                                         | 🖥️ 📞 📱           | Your Network | pascom.cloud\*                                                                                                   |
| 30.000-35.000/UDP | RTP-Voice                                                              | 🖥️ 📞 📱           | Your Network | pascom.cloud\*                                                                                                   |
| 636/TCP           | LDAPS, Phonebook                                                       | 📞                  | Your Network | pascom.cloud\*                                                                                                   |
| 8884/TCP          | Phone Provisioning                                                     | 📞                  | Your Network | pascom.cloud\*                                                                                                   |
| 443/TCP           | Updates, Push, Fax, Voicemail, Recordings, Filetransfer, Web App, Chat | 🖥️ 📱 🎥           | Your Network | pascom.cloud\*                                                                                                   |
| 19302/UDP+TCP     | WebRTC / Google STUN                                                   | <p>🖥️ 📱<br>🎥</p> | Your Network | <p>pascom.cloud\*,<br>stun.l.google.com,<br>stun1.l.google.com,<br>stun2.l.google.com,<br>stun3.l.google.com</p> |
| 8885/TCP          | VPN Tunnel to PBX                                                      | 🗄️                 | Your Network | pascom.cloud\*                                                                                                   |

#### Legend

🗄️ = PASCOM Server\
🖥️ = Desktop App\
📱 = Mobile App\
📞 = IP-Phone\
🎥 = PASCOM Web App

\| \* = The pascom.cloud can target different IP addresses

## IP addresses of the pascom.cloud outgoing (Cloud phone system)

The IP address used by the outgoing cloud phone system is dynamic and can change at any time. For this reason, it is not advisable to use this in a firewall rule.

Therefore, please use the [PASCOM VPN Service](/en/setup/endpoints/vpn-connector.md) to connect LDAP servers, for example.

## IP addresses of the pascom.cloud incoming (pascom Apps)

Instead of a fixed IPv4 or IPv6 IP address, use the DNS entry **"ip.pascom.cloud "**. If you resolve it, you will get all IPv4 and IPv6 IP addresses that pascom.cloud is using at the moment.

In addition, PASCOM apps require access to **login.pascom.net** for user login.

### Resolve DNS record manually

Resolve it manually with tools like **"dig "** or **"nslookup "** to get the IP addresses:

```
# ipv4 with dig:
dig +short ip.pascom.cloud A

# ipv6 with dig:
dig +short ip.pascom.cloud AAAA

# ipv4 with nslookup
nslookup -q=A ip.pascom.cloud

# ipv6 with nslookup
nslookup -q=AAAA ip.pascom.cloud
```

### Set DNS entry directly in the firewall

Use the DNS record **"ip.pascom.cloud "** directly in your firewall as destination or source. This only works if your firewall can use or resolve DNS names instead of IP addresses and updates them regularly.

### QoS settings

pascom.cloud marks voice and signal packets. Many routers / switches take this into account as standard or can be configured accordingly.

| Package type | TOS      | COS | DSCP decimal |
| ------------ | -------- | --- | ------------ |
| Voice        | ef / 184 | 5   | 46           |
| Signaling    | cs3 / 96 | 3   | 24           |

All PASCOM clients also mark packages accordingly. Please note that group policies must be set for this under Windows. See [Windows QoS Settings](/en/operations/clients/windows-installation.md#windows-qos-settings-optional).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.pascom.net/en/reference/port-overview.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
