Skip to content

Networking

Allow these inbound on the host and on any cloud firewall in front of it:

PortProtocolServiceUsed for
80TCPTraefikHTTP. Redirects to HTTPS and answers Let’s Encrypt HTTP-01 challenges.
443TCPTraefikHTTPS: the web app and the API.
5060UDP and TCPSBCSIP signalling with your SIP trunk.
5063TCPSBCSIP over secure WebSocket for the browser dialer. Change with SIP_WSS_PORT.
19000–19100UDPFreeSWITCHRTP media (call audio).

No other service publishes a port. Postgres, Redis, RabbitMQ, the API server and the voice bot are reachable only on the internal Docker network.

Comcent needs to know the host’s public IPv4 so that SIP and media are sent to the right address. The installer detects it and writes it to PUBLIC_IP in .env; the SBC uses it in its SIP headers and FreeSWITCH advertises it for SIP and RTP. If detection failed, or the host’s public address changes, set PUBLIC_IP by hand and run docker compose up -d.

On your SIP trunk provider, allow this IP (as <YOUR_IP>/32), for example in Twilio’s IP Access Control Lists on an Elastic SIP Trunk. See SIP trunks and numbers.

Create a DNS A record for your chosen hostname (for example voice.yourdomain.com) pointing at the host’s public IPv4, and set that hostname as COMCENT_DOMAIN. Check it before starting the stack:

Terminal window
dig +short voice.yourdomain.com

The one hostname serves everything:

URLServed by
https://<COMCENT_DOMAIN>/Web app
https://<COMCENT_DOMAIN>/api/…, /ws, /healthAPI server
wss://<COMCENT_DOMAIN>:5063/sip-wsSBC (browser dialer)
sip:<COMCENT_DOMAIN> on port 5060SBC (SIP trunk)

Traefik obtains a Let’s Encrypt certificate for COMCENT_DOMAIN automatically, using the HTTP-01 challenge on port 80, about a minute after the first start. It renews the certificate automatically.

The SBC serves the browser dialer’s secure WebSocket itself (not through Traefik), using the same certificate: the cert-dumper service copies it from Traefik’s storage into a volume the SBC reads, and the SBC picks up renewed certificates within about five minutes.

To confirm the WebSocket port presents a valid certificate:

Terminal window
echo | openssl s_client -connect voice.yourdomain.com:5063 -servername voice.yourdomain.com 2>/dev/null \
| openssl x509 -noout -subject -issuer -dates