Bring Your Own Carrier (BYOC)¶
Purpose and Audience¶
Bring Your Own Carrier lets you keep your existing PSTN provider, numbers, and rates while running Zoom Phone as your cloud PBX. There are two ways to connect, and the security responsibilities differ substantially between them.
This document is written for the network or security team evaluating or implementing BYOC. Read it alongside Network & Firewall Requirements — the outbound-only rules in that document cover Zoom Phone endpoints, not a BYOC session border controller (SBC).
The Two BYOC Models¶
BYOC-C — Cloud Peering¶
Your chosen carrier peers directly with Zoom's data centers, with no on-premises hardware — no SBC for you to buy, host, or maintain. You keep full Zoom Phone functionality (call queues, auto receptionists, number assignment) while the carrier handles the telephony side.
The carrier must be certified through Zoom's Provider Exchange, and you will receive a separate bill from that provider in addition to Zoom.
RX3 recommends: BYOC-C where your carrier supports it
This is the simpler path for most organizations. There is no SBC to procure, harden, patch, or monitor, and no inbound firewall exposure on your network — the interconnect, certificates, and firewall posture are the carrier's responsibility.
BYOC-P — Premises Peering¶
Functionally the same service, except you provide and maintain your own supported SBC that peers with Zoom's data centers instead of the carrier doing it. Choose BYOC-P when:
- Your carrier is not Provider Exchange certified.
- You need to keep legacy PBX or analog equipment in the call path.
- Routing, survivability, or regulatory requirements demand local call control.
Where the security boundary sits¶
| Area | BYOC-C | BYOC-P |
|---|---|---|
| On-premises SBC | None | Yours to supply and maintain |
| Interconnect to Zoom | Carrier's responsibility | Yours |
| TLS certificates | Carrier's responsibility | Yours |
| Inbound firewall openings | None required | Required — see below |
| Carrier requirement | Must be Provider Exchange certified | Any carrier |
The rest of this document applies to BYOC-P only
In BYOC-C, the interconnect, certificates, and firewall posture belong to your carrier. In BYOC-P they belong to you.
BYOC-P Security Requirements¶
Your SBC is the security boundary. It sits between your carrier's SIP trunks and Zoom's cloud, facing the public internet. It should be hardened, patched, rate-limited, and monitored accordingly.
Inbound firewall openings are required¶
This is not an outbound-only, firewall-friendly integration. Unlike Zoom Phone endpoints, which always initiate connections outbound into Zoom, BYOC-P SBCs require bi-directional connectivity.
| Protocol | Port(s) | Purpose | Direction |
|---|---|---|---|
| TCP | 5061 | SIP signaling over TLS | Inbound and outbound |
| UDP | 10000–64000 | Voice media (RTP/SRTP) | Inbound and outbound |
Scope these rules tightly
Source the inbound rules from Zoom's published regional IP addresses for your region, and pair them with matching outbound rules. Never open these ports broadly — an SBC reachable from the whole internet on 5061 will be scanned and dialled within hours.
A publicly trusted TLS certificate is mandatory¶
Zoom validates the SBC's certificate during setup, and TLS negotiation fails without a valid one. It must:
- Be issued by a certificate authority on Zoom's approved list.
- Carry the Server Authentication key usage.
- Include the SBC's FQDN in the Common Name or SAN — a wildcard covering the domain is acceptable.
- Be presented as a complete chain including intermediates. An incomplete chain fails the handshake.
Your SBC also needs the DigiCert root certificates installed so that it trusts Zoom's side of the connection.
Plan for certificate lifecycle¶
An expired certificate takes the trunk down
Every call goes with it. Certificate renewal needs a named owner and expiry monitoring well ahead of the date — not a calendar reminder on the day.
Encryption in transit¶
TLS 1.2 for signaling, SRTP for media, with your SBC configured to support at least one cipher from each of Zoom's published signaling and media cipher lists. Topology hiding is also required so that internal addressing is not exposed in SIP headers.
Mutual TLS — optional¶
Zoom publishes regional FQDNs you can use for peer-name verification on your SBC. Note that Zoom's side does not validate the Common Name or SAN of your SBC certificate.
References¶
For the approved certificate authorities, root certificate fingerprints, cipher priorities, and the complete per-region IP and port tables, work from Zoom's official article rather than the summary above:
- Zoom — BYOC-P SBC security and certificate requirements: KB0079203
Port, protocol, and certificate requirements in this document reflect Zoom's published guidance as of the date above. Verify against the live Zoom documentation before implementation.