Intercom Network Settings

Learn about the required network settings for Verkada Intercoms

This article outlines the required network settings that your Verkada Intercomarrow-up-right needs to communicate with Verkada Command. For more information on the required network settings for other Verkada product lines see Required Network Settings.

circle-exclamation

Status LED

A flashing blue status LED on the top of the intercom indicates the intercom is not communicating with Command. If you see this behavior, check that the network is set up correctly with the intercom's requirements. If the problem persists, contact Verkada Support.

IP address

Intercoms must be assigned an IPv4 address to communicate on the LAN and to Verkada Command. Intercoms use Dynamic Host Configuration Protocol (DHCP) and User Datagram Protocol (UDP) to obtain their IP addresses and network configurations.

If you require your intercom to have a specific IP address, create a DHCP reservation using the device's Media Access Control (MAC) address (found on the device's label).

circle-exclamation

Domain Name System

Intercoms use the DNS server to resolve Verkada's fully qualified domain names (FQDN) to IP addresses to communicate with them. Your DHCP server tells the intercom where the DNS server is on the network and the intercom communicates using UDP port 53.

circle-exclamation

Power

Intercoms are powered through Power over Ethernet (PoE). This means the network switch needs to provide power to the intercom, or a PoE injector needs to be utilized. For specifics on power requirements, see the Intercom datasheetarrow-up-right.

Firewall settings

Intercoms require access to many endpoints to ensure they can communicate with Command and all features will be accessible. Many customers may want to allow the intercoms to communicate with the general required endpoints.

These are the general domains to allow, applicable for all organization-regions:

Mandatory for Intercoms and Desk Stations

Domain/IP
Protocol/Port

*:4100

TCP/UDP on LAN

34.216.15.26

UDP:123

35.166.49.153

TCP+UDP/443, UDP:123

168.86.128.0/18

UDP:1024 to 65535

*.verkada.com

TCP+UDP/443, UDP:123

*.amazonaws.com

TCP+UDP/443, UDP/1024 to 65535

*.host.livekit.cloud

UDP:3478, UDP:50000 to 60000

*.livekit.cloud

TCP/443, UDP:50000 to 60000

*.turn.livekit.cloud

TCP/443, UDP:50000 to 60000

*.twilio.com

TCP+UDP/443, 5060, 5061

time.cloudflare.com

TCP/4460 + UDP:123

circle-info

LiveKit enables high-quality, low-latency video and audio streaming with Verkada intercoms.

If you prefer a more granular allowlist, you can add IP addresses, full FQDNs, and wildcard domains to your firewall rules based on the region where your devices are located.

circle-info

Your region is selected when you create an organization in Command.

Standard Verkada Endpoints

Domain/IP
Protocol/Port

api.control.verkada.com

TCP/UDP:443

api.global-prod.control.verkada.com

TCP/UDP:443

api-ga.control.verkada.com

TCP/UDP:443

device.pyramid.verkada.com

TCP/UDP:443

firmware.control.verkada.com

TCP/UDP:443

update.control.verkada.com

TCP/UDP:443

user.pyramid.verkada.com

TCP/UDP:443

vconductor.global-prod.command.verkada.com

TCP/UDP:443

NTP Endpoints

Domain/IP
Protocol/Port

34.216.15.26

UDP:123

35.166.49.153

UDP:123 + TCP/UDP:443

time.control.verkada.com

UDP:123

time.cloudflare.com

TCP:4460

time.cloudflare.com

UDP:123

Streaming Endpoints

Domain/IP
Protocol/Port

*:4100

TCP/UDP on LAN (only required for local streaming)

*.us-west-2.compute.amazonaws.com

UDP:1024 to 65535 (webRTC)

index.control.verkada.com

TCP/UDP:443

relay.control.verkada.com

TCP/UDP:443

relay.global-prod.control.verkada.com

TCP/UDP:443

Calling Endpoints

Domain/IP
Protocol/Port

143.223.88.0/21

TCP:443, TCP:7881, UDP:3478, UDP:50000-60000

161.115.160.0/19

TCP:443, TCP:7881, UDP:3478, UDP:50000-60000

168.86.128.0/18

UDP:1024 to 65535

chunderm.gll.twilio.com

TCP:443

ers.twilio.com

TCP:443

eventgw.twilio.com

TCP:443

verkada-erik-sip.sip.twilio.com

TCP+UDP:5060, 5061

verkada-erik-sip.sip.us1.twilio.com

TCP+UDP:5060, 5061

verkada.sip.us1.twilio.com

TCP+UDP:5060, 5061

verkada-vinter-audio-files-prod1.s3.amazonaws.com

TCP+UDP:443

Access Control Endpoints

Domain/IP
Protocol/Port

access.control.verkada.com

TCP/UDP:443

vcerberus.command.verkada.com

TCP/UDP:443

Cloud Backup Endpoints

Domain/IP
Protocol/Port

s3.ap-southeast-2.amazonaws.com

TCP:443†

s3.ca-central-1.amazonaws.com

TCP:443†

s3.us-west-2.amazonaws.com

TCP:443†

Desk Station Endpoints

Domain/IP
Protocol/Port

17.57.144.0/22

TCP:443, TCP:5223, TCP:2197

17.188.20.0/23

TCP:443, TCP:5223, TCP:2197

17.188.128.0/18

TCP:443, TCP:5223, TCP:2197

17.249.0.0/16

TCP:443, TCP:5223, TCP:2197

17.252.0.0/16

TCP:443, TCP:5223, TCP:2197

143.223.88.0/21

TCP:443, TCP:7881, UDP:3478, UDP:50000-60000

161.115.160.0/19

TCP:443, TCP:7881, UDP:3478, UDP:50000-60000

168.86.128.0/18

UDP:1024-65535

access.control.verkada.com

TCP+UDP:443

api.command.verkada.com

TCP+UDP:443

api.global-prod.control.verkada.com

TCP+UDP:443

vauth.command.verkada.com

TCP+UDP:443

vglobal.global-prod.verkada.com

TCP+UDP:443

vlogging.command.verkada.com

TCP+UDP:443

vparrot.command.verkada.com

TCP+UDP:443

vprovision.command.verkada.com

TCP+UDP:443

vsearchapi.command.verkada.com

TCP+UDP:443

vsubmit.command.verkada.com

TCP+UDP:443

vsight.command.verkada.com

TCP+UDP:443

*.camera.verkada-lan.com

TCP+UDP:4100

chunderm.gll.twilio.com

TCP:443

ers.twilio.com

TCP:443

eventgw.twilio.com

TCP:443

time.cloudflare.com

TCP:4460, UDP:123

circle-exclamation
circle-info

Use the Verkada Network Testerarrow-up-right to verify your devices can connect to Verkada Command. Select your region and the Intercom product type to run the check.

The following endpoints must be allowed on your network for the test to work:

  • speed.cloudflare.com

  • network-tester.support.verkada.com

circle-info

Revisions

September 2024:

  • Added LiveKit endpoints for high-quality video and audio streams.

Last updated

Was this helpful?