Video: Network Requirements for Firewalls and Web-Filters

This article is aimed at Network Managers and is only applicable if teachers will attend video calls using the school's internet connection.

Bandwidth Requirements

Video calling should adapt to the available bandwidth. The recommended bandwidth for video calls for popular video conferencing solutions tends to be around 1-3 Mbps in/out per call, and we would recommend considering this as a guide.

For example: with 50 simultaneous video calls being made on the school's network, you could expect to use 50-150 Mbps bandwidth in/out.

Endpoints to Whitelist

Last updated: October 5th, 2020

Please allow access outbound to all of the following hostnames/IP addresses, and ensure inbound traffic is allowed in response to the outbound connections.

TCP 443:

global.vss.twilio.com
sdkgw.us1.twilio.com

Ensure HTTPS inspection is bypassed for the above hostnames

TCP 443 + UDP 3478 + UDP 10,000 - 60,000:

13.210.2.128 - 13.210.2.159
54.252.254.64 - 54.252.254.127
3.25.42.128 - 3.25.42.255
18.231.105.32 - 18.231.105.63
177.71.206.192 - 177.71.206.255
18.230.125.0 - 18.230.125.127
52.59.186.0 - 52.59.186.31
18.195.48.224 - 18.195.48.255
18.156.18.128 - 18.156.18.255
52.215.253.0 - 52.215.253.63
54.171.127.192 - 54.171.127.255
52.215.127.0 - 52.215.127.255
3.249.63.128 - 3.249.63.255
52.66.193.96 - 52.66.193.127
52.66.194.0 - 52.66.194.63
3.7.35.128 - 3.7.35.255
13.115.244.0 - 13.115.244.31
54.65.63.192 - 54.65.63.255
18.180.220.128 - 18.180.220.255
13.229.255.0 - 13.229.255.31
54.169.127.128 - 54.169.127.191
18.141.157.128 - 18.141.157.255
34.203.254.0 - 34.203.254.255
54.172.60.0 - 54.172.61.255
34.203.250.0 - 34.203.251.255
3.235.111.128 - 3.235.111.255
34.216.110.128 - 34.216.110.159
54.244.51.0 - 54.244.51.255
44.234.69.0 - 44.234.69.127

Running a Test

Please access the following website to run a test, and allow access to your microphone/camera: https://networktest.twilio.com/
  • At least one (or more) of the following must pass:
    • NTS: TURN UDP Connectivity - this is recommended for optimal quality
    • NTS: TURN TCP Connectivity
    • NTS: TURN TLS Connectivity
  • This test must pass:
    • Video: Test Group Room with TURN

If any of the above tests fail, please verify the above endpoints have been whitelisted and there's no HTTPS inspection enabled on the two hostnames before attempting the test again.

If you find the test stalls on "Voice" and never proceeds to the rest, temporarily whitelist *.twilio.com and ensure HTTPS inspection is off for *.twilio.com, then retry the test. If you then see a successful test result as per the above required passing tests, you can safely remove the whitelist and HTTPS inspection bypass for *.twilio.com, assuming the two specific hostnames have been whitelisted and are bypassed for HTTPS inspection.

Points of Note

As media traffic flows over UDP, we STRONGLY RECOMMEND that you ensure any policies which would drop UDP packets, such as UDP flood prevention, are turned off. Any network device which drops UDP packets would cause the video and/or audio to stutter.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.

Still need help? Contact Us Contact Us