Voice Logica

Edge Connector — Network Requirements

Pre-installation guide for the IT or network administrator

The Voice Logica Edge connector runs on a small machine on your local network and links your on-premise phone system to the Voice Logica platform over an encrypted tunnel. It only makes outbound connections — nothing on the internet ever connects to it, so no port forwarding or inbound internet rules are required. It does need two outbound paths open, described below.

1. Firewall allowlist

Allow the following outbound traffic from the connector to our server. A single destination address covers everything.

PurposeProtocolDestination
Voice tunnel
WireGuard — carries the calls
UDP 51820 65.21.125.239 Required
Control and management
configuration, status, updates
TCP 443 calls.voicelogica.ai
(65.21.125.239)
Required
Domain name resolution
DNS filtering / web security allowlist
DNS calls.voicelogica.ai
voicelogica.ai
Required
Time synchronisation
standard NTP
UDP 123 any NTP server Recommended

Please allowlist the domain in your DNS filtering or web security product.

Corporate DNS security products routinely block domains they classify as new or uncategorised, and .ai addresses are frequently caught by this. When that happens the connector cannot resolve our address at all, and the internal resolver reports Non-existent domain even though other external sites resolve normally. Please allowlist calls.voicelogica.ai and voicelogica.ai, resolving to 65.21.125.239.

The tunnel is UDP, and this is the single most important item.

Many firewalls allow outbound TCP such as port 443 but silently block all outbound UDP. If UDP 51820 is blocked, the connector still powers on and shows as online in our dashboard, because that status runs over TCP — but no calls will work, since voice travels only through the UDP tunnel. Please confirm outbound UDP 51820 is explicitly permitted, not just TCP.

2. What is not required

3. Placement on the local network

ConnectionWired Ethernet is strongly preferred over Wi-Fi, as it is steadier for real-time voice.
Reaching the PBXThe connector must reach the phone system directly — either the same subnet, or a routed subnet with no filtering between them.
SIP portNote the exact SIP port your phone system listens on. It is commonly 5060, but 5059 and 5061 are also used. This is set during configuration.
PowerThe machine should remain on at all times. Sleep and hibernation are disabled automatically.

If Wi-Fi is the only option, ensure the access point does not use client or AP isolation — the connector must exchange voice packets with the phone system, and with its media or DSP unit, which may be a second address on the network.

4. Verifying the installation

Two checks confirm a healthy installation before the engineer leaves site.

5. Common issues and their causes

The connector is online, but calls have no audio

There are two distinct causes, and they are easy to confuse. Check both.

a. Outbound UDP 51820 is blocked at the site firewall. The control channel over TCP 443 is open, so the connector looks connected, but the voice tunnel never establishes. Allow outbound UDP 51820 to 65.21.125.239.

b. A local firewall on the connector machine is blocking inbound UDP. Signalling still works, because the connector starts that conversation itself and the replies are treated as an established connection. The audio is different: it arrives as a new inbound stream on ports that change every call, so a default-deny firewall drops it. The call then connects and both parties hear silence. On Windows, the installer adds the necessary rule; on Linux, allow inbound traffic on the tunnel interface. The ready-made connector appliance handles this itself.

The connector reports that our address cannot be found

Symptom: the connector log repeats getaddrinfo ENOTFOUND calls.voicelogica.ai, and nslookup calls.voicelogica.ai on the machine returns Non-existent domain — while other sites such as google.com resolve normally through the same DNS server.

That combination means DNS filtering is blocking our domain specifically, rather than the network being down. Allowlist calls.voicelogica.ai and voicelogica.ai in your DNS security or web filtering product. To confirm the diagnosis before raising it, compare an internal lookup with a public one: nslookup calls.voicelogica.ai 8.8.8.8 will succeed while the internal resolver fails.

Registration succeeds but incoming calls fail

Usually the phone system's SIP port does not match what was configured, or Wi-Fi client isolation is blocking the media. Confirm the SIP port and use a wired connection on the phone system's network.

Audio works in one direction only

Voice needs UDP flowing both ways between the connector and the phone system. A rule covering only port 5060 is not enough, because the audio itself never uses port 5060 — it uses a range of higher, changing ports. Allow all UDP in both directions between those two addresses. If the firewall offers SIP ALG, sometimes called SIP transformations or SIP inspection, switch it off.

The firewall only allows one protocol per rule

Create two rules: one for UDP 51820 and one for TCP 443, both outbound to 65.21.125.239. The UDP rule is the critical one.

6. Pre-installation checklist