IP Allow Lists
If your firewall restricts traffic, allow the Synthflow addresses for your workspace’s region. A SIP trunk needs outbound signaling to Synthflow and RTP media in both directions. Synthflow’s own requests, such as webhooks, arrive from the egress addresses. Allow only your own region’s addresses.
- Ports lists the SIP signaling and RTP media ports for SIP trunks.
- Region addresses lists the SIP hostnames, signaling IPs, and media IPs for each region.
- LATAM media lists the extra media IPs that US workspaces need.
- Egress addresses lists the IPs Synthflow uses to reach your webhooks, custom actions, and MCP servers.
To find your region, select Admin → Workspace Settings → Preferences and check Customer Region.
Ports
Allow these ports when you connect over SIP. Point your trunk at your region’s SIP hostname rather than its IPs, so failover and maintenance work automatically.
Region addresses
Allow signaling to the signaling IPs, and the media UDP range to every media IP for your region.
Global
US
EU
Signaling
Media (UDP 10000-60000)
LATAM media
US workspaces send and receive RTP through Synthflow’s Latin America media nodes too. If your workspace is in the US region, allow UDP 10000-60000 to these addresses as well as the US media IPs. Global and EU workspaces do not need them.
Egress addresses
Synthflow sends webhooks, custom action requests, MCP server calls, and other outbound HTTP requests from these addresses. If your servers only accept traffic from known IPs, allow the addresses for your region. They do not cover SIP or media traffic, which use the region addresses.