Twilio Troubleshooting

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors

Twilio Connectivity – Troubleshooting Guide

Audience: IT, Network, and Firewall Teams

Purpose: Validate network readiness for Twilio Voice and WebRTC services.


1. Mandatory Connectivity Test (Step 1)

All customers must run the official Twilio WebRTC diagnostics test.

πŸ”— Test URL:
πŸ‘‰
https://networktest.twilio.com/

Expected Result

ALL tests must show PASS, especially:

  • TURN UDP Connectivity
  • Voice Test (PCMU)
  • Voice Test (Opus)

If ALL Tests Pass

βœ… Network connectivity is NOT the issue.
Proceed to application-level troubleshooting.

If ANY Test Fails

❌ A network firewall or security policy is blocking Twilio traffic.
Proceed to Section 2 – Firewall Validation.


2. Firewall & Network Requirements (Mandatory)

2.1 Required Ports & Protocols

Ensure the following outbound traffic is allowed:

ProtocolIP Address / Port(s)Purpose
IP Address168.86.128.0/18To enable Twilio’s audio packets to flow freely
TCP443HTTPS, TLS signaling
UDP3478STUN
UDP5349TURN
UDP10000–60000Twilio media (RTP audio)

2.2 Required Domains (FQDNs)

Allow outbound access to:

  • *.twilio.com

If your firewall requires explicit FQDN allow-listing, ensure wildcard support is enabled.


3. Next-Generation Firewall (App-ID) Configuration

For Palo Alto, Fortinet, Check Point, Sophos, or other NGFWs, ensure Application-ID rules are not blocking Twilio traffic.

App-IDRole in Twilio / WebRTC
dtlsKey exchange for SRTP encryption
stunNAT traversal & ICE negotiation
rtpReal-time media transport
rtcpMedia control traffic
webrtcCovers DTLS, RTP, STUN
sslHTTPS / TLS signaling
web-browsingTwilio Console / browser UI
dnsDomain name resolution
sip (optional)Only for SIP Trunking / BYOC

πŸ” Best Practice:
Allow App-ID + Port-based rules together. App-ID detection may fail on encrypted traffic; ports provide fallback.


4. Common Misconfigurations to Check

  • ❌ UDP traffic blocked (most common issue)
  • ❌ RTP ports restricted or incorrectly narrowed
  • ❌ STUN / TURN App-ID blocked
  • ❌ SSL inspection breaking DTLS / WebRTC
  • ❌ Outdated Twilio IP or FQDN allow-list

5. If Tests Still Fail

  • Firewall logs showing blocked traffic
  • Destination IP / FQDN
  • Port and protocol
  • App-ID (if applicable)

Confirm:

  • Outbound UDP allowed
  • No SSL inspection on WebRTC traffic
  • Twilio FQDNs or IPs in policy

6. Quick Validation Checklist (For IT Teams)

  • βœ… Twilio Network Test β†’ All PASS
  • βœ… TCP 443 outbound allowed
  • βœ… UDP 3478 & 5349 allowed
  • βœ… UDP 10000–60000 allowed
  • βœ… *.twilio.com allowed
  • βœ… STUN / DTLS / RTP / WebRTC App-IDs not blocked
  • βœ… No SSL decryption for WebRTC
  • βœ… Whitelist - 168.86.128.0/18

7. Summary

  • Twilio requires UDP for voice quality
  • All tests must PASS on the Twilio network test page
  • Most failures are caused by firewall App-ID or UDP restrictions
  • Use Port + App-ID rules together for best results

Related Post

Webhooks

Automatically send Onflo ticket and asset information to your other business systems. Overview Webhooks let Onflo automatically send information to another system the moment something happens. When a ticket is created or an asset is added, Onflo can instantly push

Read More ➜

API Tokens

How customers create and manage the tokens that let their software connect to the Onflo API Overview API Tokens is a feature in Onflo Settings that lets a customer generate a secure key which their own software can use to

Read More ➜

Community Promotion Toolkit

Ideas and ready-to-use templates to help you introduce or reintroduce Onflo to your community. Choose Your Approach There’s more than one way to introduce your service desk to your community. The approach you choose will depend on your district’s communication

Read More ➜