> For a complete page index, fetch https://docs.synthflow.ai/llms.txt. For full documentation content, fetch https://docs.synthflow.ai/llms-full.txt.

# IP Allow Lists

> Firewall rules for Synthflow by region (Global, US, EU), covering SIP signaling and RTP media for SIP trunks, LATAM media for US workspaces, and egress IPs for webhooks, custom actions, and MCP servers.

If your firewall restricts traffic, allow the Synthflow addresses for your workspace's region. A SIP trunk needs outbound signaling to Synthflow and RTP media in both directions. Synthflow's own requests, such as webhooks, arrive from the egress addresses. Allow only your own region's addresses.

* **[Ports](#ports)** lists the SIP signaling and RTP media ports for SIP trunks.
* **[Region addresses](#region-addresses)** lists the SIP hostnames, signaling IPs, and media IPs for each region.
* **[LATAM media](#latam-media)** lists the extra media IPs that US workspaces need.
* **[Egress addresses](#egress-addresses)** lists the IPs Synthflow uses to reach your webhooks, custom actions, and MCP servers.

To find your region, select **Admin** → **Workspace Settings** → **Preferences** and check **Customer Region**.

## Ports

Allow these ports when you [connect over SIP](/connect-over-sip). Point your trunk at your region's SIP hostname rather than its IPs, so failover and maintenance work automatically.

| Traffic       | Protocol | Port          | Purpose                                                     |
| ------------- | -------- | ------------- | ----------------------------------------------------------- |
| SIP signaling | UDP, TCP | `32681`       | SIP over UDP or TCP                                         |
| SIP signaling | TLS      | `32682`       | SIP over TLS                                                |
| Media (RTP)   | UDP      | `10000-60000` | RTP and RTCP between your network and Synthflow media nodes |

## Region addresses

Allow signaling to the signaling IPs, and the media UDP range to **every** media IP for your region.

#### Global

**Signaling**

| SIP hostname       | Signaling IPs                                                         | UDP   | TCP   | TLS   |
| ------------------ | --------------------------------------------------------------------- | ----- | ----- | ----- |
| `sip.synthflow.ai` | `34.138.86.8/32, 34.75.151.191/32, 34.23.45.239/32, 35.231.28.238/32` | 32681 | 32681 | 32682 |

**Media** (UDP `10000-60000`)

| Media IP        |
| --------------- |
| `34.73.190.14`  |
| `35.237.117.4`  |
| `34.148.74.207` |
| `34.139.134.58` |
| `34.73.14.16`   |
| `34.139.114.28` |

#### US

**Signaling**

| SIP hostname          | Signaling IPs                                       | UDP   | TCP   | TLS   |
| --------------------- | --------------------------------------------------- | ----- | ----- | ----- |
| `sip.us.synthflow.ai` | `35.237.42.43/32, 34.139.4.161/32, 4.138.180.50/32` | 32681 | 32681 | 32682 |

**Media** (UDP `10000-60000`)

| Media IP         |
| ---------------- |
| `34.74.219.233`  |
| `34.73.16.58`    |
| `34.74.102.178`  |
| `34.139.255.196` |
| `34.138.230.237` |
| `34.75.0.163`    |

US workspaces must also allow the [LATAM media](#latam-media) addresses.

#### EU

**Signaling**

| SIP hostname          | Signaling IPs                                           | UDP   | TCP   | TLS   |
| --------------------- | ------------------------------------------------------- | ----- | ----- | ----- |
| `sip.eu.synthflow.ai` | `34.185.212.150/32, 34.89.186.33/32, 35.242.217.198/32` | 32681 | 32681 | 32682 |

**Media** (UDP `10000-60000`)

| Media IP         |
| ---------------- |
| `34.89.251.213`  |
| `35.198.108.150` |
| `34.141.20.211`  |
| `34.141.63.192`  |
| `35.234.97.154`  |
| `34.141.91.77`   |

## LATAM media

US workspaces send and receive RTP through Synthflow's Latin America media nodes too. If your workspace is in the US region, allow UDP `10000-60000` to these addresses as well as the US media IPs. Global and EU workspaces do not need them.

| Media IP      |
| ------------- |
| `34.51.27.23` |
| `34.51.92.73` |

## Egress addresses

Synthflow sends webhooks, custom action requests, MCP server calls, and other outbound HTTP requests from these addresses. If your servers only accept traffic from known IPs, allow the addresses for your region. They do not cover SIP or media traffic, which use the [region addresses](#region-addresses).

#### Global

| Egress IP        |
| ---------------- |
| `34.75.13.71`    |
| `34.74.126.13`   |
| `34.139.172.104` |
| `34.139.35.82`   |
| `34.23.52.21`    |
| `35.243.188.164` |
| `104.196.154.68` |
| `34.75.98.89`    |
| `34.75.163.76`   |
| `34.75.64.8`     |
| `34.73.214.36`   |
| `34.139.44.238`  |
| `34.138.49.101`  |
| `34.138.46.87`   |
| `34.73.237.242`  |
| `34.73.234.92`   |
| `34.73.106.37`   |
| `34.139.173.176` |
| `34.73.34.138`   |
| `34.26.71.171`   |
| `34.148.30.10`   |
| `34.138.149.224` |
| `34.139.16.79`   |
| `34.23.185.86`   |

#### US

| Egress IP       |
| --------------- |
| `34.148.104.15` |
| `35.237.175.49` |
| `34.74.174.224` |
| `35.237.85.233` |
| `34.24.254.160` |
| `34.148.30.108` |
| `34.23.150.25`  |
| `35.227.123.45` |

#### EU

| Egress IP        |
| ---------------- |
| `34.107.80.188`  |
| `34.185.227.34`  |
| `35.198.187.133` |
| `34.141.17.220`  |
| `34.159.51.71`   |
| `35.246.192.2`   |
| `34.40.10.8`     |
| `35.246.135.16`  |