Skip to content

Bring Your Own Carrier (BYOC)

Purpose and Audience

Bring Your Own Carrier lets you keep your existing PSTN provider, numbers, and rates while running Zoom Phone as your cloud PBX. There are two ways to connect, and the security responsibilities differ substantially between them.

This document is written for the network or security team evaluating or implementing BYOC. Read it alongside Network & Firewall Requirements — the outbound-only rules in that document cover Zoom Phone endpoints, not a BYOC session border controller (SBC).

The Two BYOC Models

BYOC-C — Cloud Peering

Your chosen carrier peers directly with Zoom's data centers, with no on-premises hardware — no SBC for you to buy, host, or maintain. You keep full Zoom Phone functionality (call queues, auto receptionists, number assignment) while the carrier handles the telephony side.

The carrier must be certified through Zoom's Provider Exchange, and you will receive a separate bill from that provider in addition to Zoom.

RX3 recommends: BYOC-C where your carrier supports it

This is the simpler path for most organizations. There is no SBC to procure, harden, patch, or monitor, and no inbound firewall exposure on your network — the interconnect, certificates, and firewall posture are the carrier's responsibility.

BYOC-P — Premises Peering

Functionally the same service, except you provide and maintain your own supported SBC that peers with Zoom's data centers instead of the carrier doing it. Choose BYOC-P when:

  • Your carrier is not Provider Exchange certified.
  • You need to keep legacy PBX or analog equipment in the call path.
  • Routing, survivability, or regulatory requirements demand local call control.

Where the security boundary sits

Area BYOC-C BYOC-P
On-premises SBC None Yours to supply and maintain
Interconnect to Zoom Carrier's responsibility Yours
TLS certificates Carrier's responsibility Yours
Inbound firewall openings None required Required — see below
Carrier requirement Must be Provider Exchange certified Any carrier

The rest of this document applies to BYOC-P only

In BYOC-C, the interconnect, certificates, and firewall posture belong to your carrier. In BYOC-P they belong to you.

BYOC-P Security Requirements

Your SBC is the security boundary. It sits between your carrier's SIP trunks and Zoom's cloud, facing the public internet. It should be hardened, patched, rate-limited, and monitored accordingly.

Inbound firewall openings are required

This is not an outbound-only, firewall-friendly integration. Unlike Zoom Phone endpoints, which always initiate connections outbound into Zoom, BYOC-P SBCs require bi-directional connectivity.

Protocol Port(s) Purpose Direction
TCP 5061 SIP signaling over TLS Inbound and outbound
UDP 10000–64000 Voice media (RTP/SRTP) Inbound and outbound

Scope these rules tightly

Source the inbound rules from Zoom's published regional IP addresses for your region, and pair them with matching outbound rules. Never open these ports broadly — an SBC reachable from the whole internet on 5061 will be scanned and dialled within hours.

A publicly trusted TLS certificate is mandatory

Zoom validates the SBC's certificate during setup, and TLS negotiation fails without a valid one. It must:

  • Be issued by a certificate authority on Zoom's approved list.
  • Carry the Server Authentication key usage.
  • Include the SBC's FQDN in the Common Name or SAN — a wildcard covering the domain is acceptable.
  • Be presented as a complete chain including intermediates. An incomplete chain fails the handshake.

Your SBC also needs the DigiCert root certificates installed so that it trusts Zoom's side of the connection.

Plan for certificate lifecycle

An expired certificate takes the trunk down

Every call goes with it. Certificate renewal needs a named owner and expiry monitoring well ahead of the date — not a calendar reminder on the day.

Encryption in transit

TLS 1.2 for signaling, SRTP for media, with your SBC configured to support at least one cipher from each of Zoom's published signaling and media cipher lists. Topology hiding is also required so that internal addressing is not exposed in SIP headers.

Mutual TLS — optional

Zoom publishes regional FQDNs you can use for peer-name verification on your SBC. Note that Zoom's side does not validate the Common Name or SAN of your SBC certificate.

References

For the approved certificate authorities, root certificate fingerprints, cipher priorities, and the complete per-region IP and port tables, work from Zoom's official article rather than the summary above:

  • Zoom — BYOC-P SBC security and certificate requirements: KB0079203

Port, protocol, and certificate requirements in this document reflect Zoom's published guidance as of the date above. Verify against the live Zoom documentation before implementation.