System Requirements

This article lists everything needed to deploy and connect VoIP Detective: the supported virtual environments, the resources the virtual machine needs, and the network ports required to receive call data from each supported platform.

Supported Platforms

VoIP Detective is a virtual appliance. It runs on any one of the following virtual environments:

Virtual Environment

Minimum Version

VMware ESXi

5.5+

VMware Workstation

15+

VMware Player

Supported

Microsoft Hyper-V

Hyper-V 10+ / Windows Server 2016+

Proxmox

Supported

Nutanix

Supported

Linux KVM

Supported

 

Phone system: Cisco Unified Communications Manager 8 or later. (Webex Calling, Microsoft Teams, and Cisco CUBE are also supported as call data sources – see Connectivity below.)

Virtual Machine Requirements

Resource

Requirement

vCPU

2

Memory

16 GB

Storage

1 TB (may be thin provisioned)

Internet access

Outbound access to *.voipdetective.com (see Connectivity). PRO users may bypass this with an offline license.

 

ℹ️ Tip: Storage is the resource most affected by call volume and retention. Thin provisioning lets you start small and grow as your call database fills up.

Connectivity

Open the following ports so VoIP Detective can receive call data. Each platform is independent – you only need the ports for the platforms you use.


Cisco Call Manager (CUCM)

Port

Direction

Purpose

22

CUCM → VoIP Detective

VoIP Detective has a built-in SFTP server. Once you add it as a “billing server” in CUCM, CUCM pushes CDR/CMR files to it over port 22 (SFTP).

8443

VoIP Detective → CUCM

Optional. Read-only AXL access used to import end-user names and device data.

 

CUBE

CUBE can send files to VoIP Detective over FTP (all CUBE versions) or SFTP (newer CUBE versions).  Select one of the below ports to allow CUBE to push files to VoIP Detective.  Only one port is needed.


Port

Direction

Purpose

22

CUBE → VoIP Detective

VoIP Detective has a built-in SFTP server. CUBE pushes CDR/CMR files to it over port 22 (SFTP).

21

CUBE → VoIP Detective


VoIP Detective has an optional built-in FTP server (must be enabled in the command line menu). CUBE pushes CDR/CMR files to it over port 21 (FTP).


Microsoft Teams

Teams reporting requires outbound access (port 443) from VoIP Detective to retrieve call records:

Purpose

Endpoint

Call data (Microsoft Graph)

https://graph.microsoft.com

OAuth / authentication

https://login.microsoftonline.com/

 

Webex Calling

Webex Calling reporting requires outbound access (port 443) from VoIP Detective to your Webex region. The endpoint depends on your location:

Region

Endpoint

Token exchange (all regions)

oauth.voipdetective.com

United States

analytics-calling.webexapis.com

European Union

analytics-calling-eu.webexapis.com

Asia Pacific

analytics-calling-in.webexapis.com

Government

analytics-calling-gov.webexapis.com

 

Outbound – Product Services

VoIP Detective Free contacts the following over port 443. PRO users can remove this requirement with an offline license.

Destination

Purpose

Port

www.voipdetective.com

Tests whether internet access is working and notifies the administrator when an update is available.

443

update.voipdetective.com

Provides upgrade details and delivers upgrades, applied from the GUI.

443

license.voipdetective.com

Contacted about every 7 days to verify the license is still active.

443


Outbound – Linux OS Updates

VoIP Detective runs on AlmaLinux. The command-line menu "update the linux OS (includes kernel)" uses the standard dnf package manager to install and update OS components. These connections are only needed while running those menu options; the appliance never updates the OS on its own.


Requirements are split into two tiers. Most organizations only need Tier 1.


Tier 1 – Routine OS updates

Needed for: OS updates, kernel upgrades, Apache upgrades, SNMP, disk expansion, and diagnostic tools.


DestinationPortPurpose
repo.almalinux.org443AlmaLinux package repositories
dlm.mariadb.com
443MariaDB database server updates


ℹ️ Tip: These hostnames apply after running option 2, configure repositories for restricted networks, under update the linux OS on the command-line menu. Without it, downloads come from public mirrors that cannot be listed in advance.



Tier 2 – PHP and application upgrades

Needed in addition to Tier 1 for: PHP version upgrades, install outbound SSH, and optional integrations. These are typically run during a planned maintenance window.



DestinationPortPurpose
rpms.remirepo.net443Remi repository – release package and HTTPS fallback
dl.fedoraproject.org443EPEL repository – supporting packages
pecl.php.net80Informix database driver (Informix integration only)
getcomposer.org443Composer installer (developer tooling only)


Important: the dnf (yum) package manager checks every enabled repository before installing anything. If a Tier 2 destination is enabled on the appliance but blocked by your firewall, even Tier 1 installs can fail with a timeout error. If you plan to allow Tier 1 only, run option 2, configure repositories for restricted networks, which sets the appliance to skip unreachable repositories. 



Outbound – Optional Services

ServiceDestinationPortPurpose
SMTP server
Your mail server
25 / 465 / 587
Sends scheduled reports and alerts by email
Microsoft 365 OAuth2
login.microsoftonline.com
443Authentication for Microsoft 365 email



 

Important: VoIP Detective is not designed to be internet-facing. Ensure it is not reachable directly from the internet and is not placed in your organization’s DMZ.

Related Articles

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article