Networking
Ports to open
Section titled “Ports to open”Allow these inbound on the host and on any cloud firewall in front of it:
| Port | Protocol | Service | Used for |
|---|---|---|---|
| 80 | TCP | Traefik | HTTP. Redirects to HTTPS and answers Let’s Encrypt HTTP-01 challenges. |
| 443 | TCP | Traefik | HTTPS: the web app and the API. |
| 5060 | UDP and TCP | SBC | SIP signalling with your SIP trunk. |
| 5063 | TCP | SBC | SIP over secure WebSocket for the browser dialer. Change with SIP_WSS_PORT. |
| 19000–19100 | UDP | FreeSWITCH | RTP media (call audio). |
No other service publishes a port. Postgres, Redis, RabbitMQ, the API server and the voice bot are reachable only on the internal Docker network.
Public IP
Section titled “Public IP”Comcent needs to know the host’s public IPv4 so that SIP and media are sent to the right address. The installer detects it and writes it to PUBLIC_IP in .env; the SBC uses it in its SIP headers and FreeSWITCH advertises it for SIP and RTP. If detection failed, or the host’s public address changes, set PUBLIC_IP by hand and run docker compose up -d.
On your SIP trunk provider, allow this IP (as <YOUR_IP>/32), for example in Twilio’s IP Access Control Lists on an Elastic SIP Trunk. See SIP trunks and numbers.
Create a DNS A record for your chosen hostname (for example voice.yourdomain.com) pointing at the host’s public IPv4, and set that hostname as COMCENT_DOMAIN. Check it before starting the stack:
dig +short voice.yourdomain.comThe one hostname serves everything:
| URL | Served by |
|---|---|
https://<COMCENT_DOMAIN>/ | Web app |
https://<COMCENT_DOMAIN>/api/…, /ws, /health | API server |
wss://<COMCENT_DOMAIN>:5063/sip-ws | SBC (browser dialer) |
sip:<COMCENT_DOMAIN> on port 5060 | SBC (SIP trunk) |
Traefik obtains a Let’s Encrypt certificate for COMCENT_DOMAIN automatically, using the HTTP-01 challenge on port 80, about a minute after the first start. It renews the certificate automatically.
The SBC serves the browser dialer’s secure WebSocket itself (not through Traefik), using the same certificate: the cert-dumper service copies it from Traefik’s storage into a volume the SBC reads, and the SBC picks up renewed certificates within about five minutes.
To confirm the WebSocket port presents a valid certificate:
echo | openssl s_client -connect voice.yourdomain.com:5063 -servername voice.yourdomain.com 2>/dev/null \ | openssl x509 -noout -subject -issuer -dates