Storable CRM and Collections Knowledge Base

Allow Storable CRM to Work with Your Firewall

Storable CRM

Ensure Storable CRM functions reliably by configuring your firewall and network to allow required domains, IP ranges, and application traffic.

Quick Start
1. Confirm you can update firewall and network settings in your environment.
2. Add the Storable CRM, Twilio, and SendGrid domains and IP ranges to your organization's allowlist.
3. Configure Windows Defender Firewall inbound and outbound rules for ports 9001 and 9002 on user machines.
4. Validate that Storable CRM, calling, chat, and email features work as expected.
5. Contact Storable CRM Support if you need help completing these steps.

Whitelist Storable CRM Domains

  1. Provide your IT team with the purpose of Storable CRM so they understand these domains are required for core functionality.

  2. Ask IT to add the following domains to the organization's firewall or web filter allowlist:

    • *.Storable CRM.com (required for all Storable CRM functionality)

    • *.newrelic.com (used for server monitoring; blocking can cause script errors)

    • *.fastly.net (used by New Relic)

    • *.livechatinc.com (required for in-app chat support)

    • *.infusionsoft.com (required for forms on the Storable CRM website)

    • *.bootstrapcdn.com (used by the location version of Storable CRM)

    • *maps.googleapis.com

    • *google-content.com

  3. Confirm with IT that any SSL inspection or content filtering rules will not interfere with these domains.

Configure Storable CRM Location Client

  1. Decide whether the Storable CRM Location Client will use Google DNS or a custom DNS resolver.

  2. For the Google DNS installer, provide IT with this download link and ensure it is allowed through the firewall: https://dl.Storable CRM.com/Storable CRM.exe.

  3. Confirm that outbound DNS queries to Google DNS 8.8.8.8 are allowed so Network Validation succeeds.

  4. For the custom DNS installer, provide IT with this download link and ensure it is allowed through the firewall: https://dl.Storable CRM.com/Storable CRM-Per-User.exe.

  5. Install the appropriate Location Client on user machines after the URLs and DNS traffic are allowed.

Whitelist Twilio Resources

  1. Explain to IT that Storable CRM uses Twilio for voice and video services, and that Twilio domains, IPs, and ports must be allowed.

  2. Share Twilio's connectivity documentation so IT can review all current requirements:

  3. Direct IT to Twilio's latest SIP trunking IP list so they can monitor ongoing changes: https://www.twilio.com/docs/sip-trunking/ip-addresses.

  4. Review the following signaling IP ranges and associated ports with IT so they can be allowed:

    54.172.60.0/30 which translates to: 54.172.60.0, 54.172.60.1, 54.172.60.2, 54.172.60.3
    Ports: 5060 (UDP/TCP), 5061 (TLS)

    54.244.51.0/30 which translates to: 54.244.51.0, 54.244.51.1, 54.244.51.2, 54.244.51.3
    Ports: 5060 (UDP/TCP), 5061 (TLS)

  5. Communicate Twilio's media IP updates to IT so they understand which ranges are being retired and which must be allowed:

    After January 23, 2024, these media IPs will be retired:

    54.172.60.0/23
    34.203.250.0/23
    Port Range: 10,000 to 20,000 (UDP)

    54.244.51.0/24
    Port Range: 10,000 to 20,000 (UDP)

    Beginning December 5, 2023, Twilio will be updating their media IP range. For more information, direct IT to Twilio's security FAQ: https://www.twilio.com/docs/voice/voice-media-ip-expansion-security-faq.

    168.86.128.0/18
    Network Range: 168.86.128.0 - 168.86.191.255
    Port Range: 10,000 to 60,000 (UDP)

Whitelist SendGrid Resources

  1. Inform IT that Storable CRM uses SendGrid to send emails, and that SendGrid domains and IPs must be allowed so emails are delivered successfully.

  2. Provide the following dedicated SendGrid IPs to be allowed: 149.72.141.201 and 167.89.110.17.

  3. Ask IT to allow outbound traffic to these SendGrid domains:

Allow Required Ports

  1. Review network security policies with IT and confirm that the following ports are open as required by Storable CRM:

    • Port 9002 (used by the location version of Storable CRM to push notifications)

    • Port 9001 (used by Call Center software)

  2. Document which ports are open (edge firewall, local machine firewall, or both) for future troubleshooting.

Create Firewall With Storable CRM Support

  1. If you prefer a guided setup, contact Storable CRM Support via email, chat, or phone.

  2. Coordinate a time with Support and be ready to share access to a representative workstation.

  3. Download and open the remote-access file provided by Support to connect to your computer securely.

  4. Work with the Support representative as they confirm your allowlist configuration and create the necessary firewall rules.

Create Your Own Firewall Rules

Use this section if you or your IT team are configuring Windows Defender Firewall directly on user machines.

Access Windows Defender Firewall

  1. On the user's Windows machine, click Search (A) to open the system search bar.

  2. In the search field, type Control Panel (B) and select it from the results.

  3. Within Control Panel, use the search box to enter Firewall (C).

  4. Once inside your control panel, enter the term "Firewall" (D).

  5. In the search results, select Windows Defender Firewall (E) to open the firewall settings.

  6. In the left navigation pane, click Advanced Settings (F) to open the Windows Defender Firewall with Advanced Security console.

Create Inbound Rules

  1. In the left navigation pane of the Advanced Security console, click Inbound Rules (G) to display existing rules.

  1. Select New Rule (H) to start creating the first inbound rule for CP TCP.

3. Choose Port (I), then click Next (J) to continue.

  1. On the protocol and ports screen, select Specific Local Ports (K). Enter 9001, 9002, then click Next (L).

  1. On the action screen, select Allow The Connection (M) and click Next (N).

  1. Confirm that Domain, Private, and Public are selected, then click Next (O).

  1. On the name screen, enter CP TCP (P) as the rule name and click Finish (Q) to save the inbound rule.

Create Second Inbound Rule For UDP

  1. From the Inbound Rules list, use the Actions pane to click New Rule (A) and begin creating the CP UDP rule.

  1. On the rule type screen, select Port (B) and click Next (C).

3. On the protocol and ports screen, choose UDP (D), enter the required ports (such as 9001 and 9002, if applicable to your configuration), and click Next (E).

  1. On the action screen, keep Allow The Connection (F) selected and click Next (F).

  1. On the profile screen, confirm that Domain, Private, and Public are all selected, then click Next (G).

  1. On the name screen, enter CP UDP (H) as the rule name and click Finish (I) to save the inbound UDP rule.

Create Outbound Rules

  1. In the left navigation pane of the Advanced Security console, click Outbound Rules (J) to view existing outbound rules.

  2. Repeat the same configuration steps you used for Inbound Rules to create corresponding outbound rules for CP TCP and CP UDP, ensuring ports 9001 and 9002 are allowed outbound.

  3. Review both inbound and outbound rule lists to confirm that CP TCP and CP UDP rules are enabled and correctly scoped to the intended profiles (Domain, Private, Public).

Feedback received!

Error submitting feedback, please try again later