The Voice Logica Edge connector runs on a small machine on your local network and links your on-premise phone system to the Voice Logica platform over an encrypted tunnel. It only makes outbound connections — nothing on the internet ever connects to it, so no port forwarding or inbound internet rules are required. It does need two outbound paths open, described below.
Allow the following outbound traffic from the connector to our server. A single destination address covers everything.
| Purpose | Protocol | Destination | |
|---|---|---|---|
| Voice tunnel WireGuard — carries the calls |
UDP 51820 | 65.21.125.239 |
Required |
| Control and management configuration, status, updates |
TCP 443 | calls.voicelogica.ai( 65.21.125.239) |
Required |
| Domain name resolution DNS filtering / web security allowlist |
DNS | calls.voicelogica.aivoicelogica.ai |
Required |
| Time synchronisation standard NTP |
UDP 123 | any NTP server | Recommended |
Please allowlist the domain in your DNS filtering or web security product.
Corporate DNS security products routinely block domains they classify as new or uncategorised, and .ai addresses are frequently caught by this. When that happens the connector cannot resolve our address at all, and the internal resolver reports Non-existent domain even though other external sites resolve normally. Please allowlist calls.voicelogica.ai and voicelogica.ai, resolving to 65.21.125.239.
The tunnel is UDP, and this is the single most important item.
Many firewalls allow outbound TCP such as port 443 but silently block all outbound UDP. If UDP 51820 is blocked, the connector still powers on and shows as online in our dashboard, because that status runs over TCP — but no calls will work, since voice travels only through the UDP tunnel. Please confirm outbound UDP 51820 is explicitly permitted, not just TCP.
| Connection | Wired Ethernet is strongly preferred over Wi-Fi, as it is steadier for real-time voice. |
|---|---|
| Reaching the PBX | The connector must reach the phone system directly — either the same subnet, or a routed subnet with no filtering between them. |
| SIP port | Note the exact SIP port your phone system listens on. It is commonly 5060, but 5059 and 5061 are also used. This is set during configuration. |
| Power | The machine should remain on at all times. Sleep and hibernation are disabled automatically. |
If Wi-Fi is the only option, ensure the access point does not use client or AP isolation — the connector must exchange voice packets with the phone system, and with its media or DSP unit, which may be a second address on the network.
Two checks confirm a healthy installation before the engineer leaves site.
"C:\Program Files\WireGuard\wg.exe" showA working tunnel shows a
latest handshake line and a non-zero received figure. If it reports 0 B received with no handshake, outbound UDP 51820 is being blocked — see section 1.There are two distinct causes, and they are easy to confuse. Check both.
a. Outbound UDP 51820 is blocked at the site firewall. The control channel over TCP 443 is open, so the connector looks connected, but the voice tunnel never establishes. Allow outbound UDP 51820 to 65.21.125.239.
b. A local firewall on the connector machine is blocking inbound UDP. Signalling still works, because the connector starts that conversation itself and the replies are treated as an established connection. The audio is different: it arrives as a new inbound stream on ports that change every call, so a default-deny firewall drops it. The call then connects and both parties hear silence. On Windows, the installer adds the necessary rule; on Linux, allow inbound traffic on the tunnel interface. The ready-made connector appliance handles this itself.
Symptom: the connector log repeats getaddrinfo ENOTFOUND calls.voicelogica.ai, and nslookup calls.voicelogica.ai on the machine returns Non-existent domain — while other sites such as google.com resolve normally through the same DNS server.
That combination means DNS filtering is blocking our domain specifically, rather than the network being down. Allowlist calls.voicelogica.ai and voicelogica.ai in your DNS security or web filtering product. To confirm the diagnosis before raising it, compare an internal lookup with a public one: nslookup calls.voicelogica.ai 8.8.8.8 will succeed while the internal resolver fails.
Usually the phone system's SIP port does not match what was configured, or Wi-Fi client isolation is blocking the media. Confirm the SIP port and use a wired connection on the phone system's network.
Voice needs UDP flowing both ways between the connector and the phone system. A rule covering only port 5060 is not enough, because the audio itself never uses port 5060 — it uses a range of higher, changing ports. Allow all UDP in both directions between those two addresses. If the firewall offers SIP ALG, sometimes called SIP transformations or SIP inspection, switch it off.
Create two rules: one for UDP 51820 and one for TCP 443, both outbound to 65.21.125.239. The UDP rule is the critical one.
65.21.125.239 allowedcalls.voicelogica.ai allowed