# Cloud Proxy migration guide (/en/realtime-media/video/reference/cloud-proxy-migration-guide/windows)

> For AI agents: see the complete documentation index at [llms.txt](/llms.txt).

Agora has updated IP whitelist configuration to enhance security and simplify management. This guide helps you update your cloud proxy settings to avoid service interruptions. Following are the key changes:

* **Reduced IP ranges**: Narrower network segments improve security
* **Single IP addressing**: Cloud machines now use single-point IPs
* **Updated subnet masks**: Physical machines now use /28 instead of /26
* **New access point IP list**: Introduced in SDK 3.4.0 for improved high availability

<CalloutContainer type="info">
  <CalloutTitle>
    Implementation notes
  </CalloutTitle>

  <CalloutDescription>
    * All IP addresses and network ranges have been technically verified.
    * Update your firewall rules according to the specified timeline.
    * Continue using your current configuration if you must configure before the new delivery dates.
    * Test your configuration thoroughly using the [validation steps](../reference/cloud-proxy-allowed-ips#validation-and-testing).
  </CalloutDescription>
</CalloutContainer>

## Summary of changes

Following are the key changes:

* Access Point IPs have been updated with additional regional support
* Some Signaling service IPs have been replaced or expanded
* All media service network segments remain the same
* Port configurations remain unchanged

## Whitelist migration

The following tables provide the essential information needed to migrate your Cloud Proxy configurations to the new network architecture. Each table outlines:

* **Service type**: The Agora service you want to access
* **Current IP addresses**: Your existing setup that needs to be updated
* **New IP addresses**: The specific IP addresses, ports, and network segments to implement
* **Protocol**: The supported transport protocol(s) used to connect to the service
* **Port**: The network port number used for establishing the connection
* **Required action**: The specific changes needed for each component

Use these tables to identify the configurations applicable to your regions.

<CalloutContainer type="info">
  <CalloutDescription>
    When adding IP addresses:

    * If you use cloud proxy with [Restricted media zones](/en/realtime-media/video/build/manage-connection-and-quality/geofencing), add only the IP addresses dedicated to your specified region.
    * If you do not restrict media zones, add all IP addresses to ensure connectivity.
  </CalloutDescription>
</CalloutContainer>

      
  
      
  
      
  
      
  
      
### Native RTC Force UDP mode

#### North America

| Service type      | Current IP addresses                                                            | New IP addresses                                                                                                                                                                                                                                                                 | Protocol | Port                     | Action required                       |
| ----------------- | ------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------------------ | ------------------------------------- |
| Signaling Service | `184.72.16.87`, `35.168.106.53`                                                 | `106.14.12.130`, `118.190.148.38`, `184.72.16.87`, `35.168.106.53`, `35.156.231.150`, `15.237.134.178`, `54.178.26.110`, `52.221.23.86`, `13.230.60.35`, `15.206.47.129`, `13.127.149.196`, `13.209.247.137`, `13.124.182.235`, `23.98.43.152`, `107.155.14.132`, `69.28.51.142` | UDP      | `8443`                   | Add new IPs to existing configuration |
| Cloud Proxy       | `128.14.195.192/28`, `128.14.245.16/28`, `128.14.72.80/28`, `128.14.200.208/28` | `128.14.195.192/28`, `128.14.245.16/28`, `128.14.72.80/28`, `128.14.200.208/28`                                                                                                                                                                                                  | UDP      | `4590-4600`, `8001-8010` | No change required                    |

#### Europe

| Service type      | Current IP addresses                                                         | New IP addresses                                                                                                                                                                                                                                                                 | Protocol | Port                     | Action required                       |
| ----------------- | ---------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------------------ | ------------------------------------- |
| Signaling Service | `35.156.231.150`, `15.237.134.178`                                           | `106.14.12.130`, `118.190.148.38`, `184.72.16.87`, `35.168.106.53`, `35.156.231.150`, `15.237.134.178`, `54.178.26.110`, `52.221.23.86`, `13.230.60.35`, `15.206.47.129`, `13.127.149.196`, `13.209.247.137`, `13.124.182.235`, `23.98.43.152`, `107.155.14.132`, `69.28.51.142` | UDP      | `8443`                   | Add new IPs to existing configuration |
| Cloud Proxy       | `104.166.160.208/28`, `23.236.110.32/28`, `104.166.142.134`, `104.166.161.4` | `104.166.160.208/28`, `23.236.110.32/28`, `104.166.142.134`, `104.166.161.4`                                                                                                                                                                                                     | UDP      | `4590-4600`, `8001-8010` | No change required                    |

#### Asia, excluding Mainland China

| Service type      | Current IP addresses                                         | New IP addresses                                                                                                                                                                                                                                                                 | Protocol | Port                     | Action required                       |
| ----------------- | ------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------------------ | ------------------------------------- |
| Signaling Service | `54.178.26.110`, `52.221.23.86`, `13.230.60.35`              | `106.14.12.130`, `118.190.148.38`, `184.72.16.87`, `35.168.106.53`, `35.156.231.150`, `15.237.134.178`, `54.178.26.110`, `52.221.23.86`, `13.230.60.35`, `15.206.47.129`, `13.127.149.196`, `13.209.247.137`, `13.124.182.235`, `23.98.43.152`, `107.155.14.132`, `69.28.51.142` | UDP      | `8443`                   | Add new IPs to existing configuration |
| Cloud Proxy       | `128.1.186.240/28`, `129.227.73.32/28`, `103.193.127.208/28` | `128.1.186.240/28`, `129.227.73.32/28`, `103.193.127.208/28`                                                                                                                                                                                                                     | UDP      | `4590-4600`, `8001-8010` | No change required                    |

#### Japan

| Service type      | Current IP addresses                                                         | New IP addresses                                                                                                                                                                                                                                                                 | Protocol | Port                     | Action required                       |
| ----------------- | ---------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------------------ | ------------------------------------- |
| Signaling Service | `54.178.26.110`, `52.221.23.86`, `13.230.60.35`                              | `106.14.12.130`, `118.190.148.38`, `184.72.16.87`, `35.168.106.53`, `35.156.231.150`, `15.237.134.178`, `54.178.26.110`, `52.221.23.86`, `13.230.60.35`, `15.206.47.129`, `13.127.149.196`, `13.209.247.137`, `13.124.182.235`, `23.98.43.152`, `107.155.14.132`, `69.28.51.142` | UDP      | `8443`                   | Add new IPs to existing configuration |
| Cloud Proxy       | `129.227.113.112/28`, `129.227.55.96/28`, `122.10.153.74`, `129.227.234.123` | `129.227.113.112/28`, `129.227.55.96/28`, `122.10.153.74`, `129.227.234.123`                                                                                                                                                                                                     | UDP      | `4590-4600`, `8001-8010` | No change required                    |

#### India

| Service type      | Current IP addresses                                           | New IP addresses                                                                                                                                                                                                                                                                 | Protocol | Port                     | Action required                       |
| ----------------- | -------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------------------ | ------------------------------------- |
| Signaling Service | `15.206.47.129`, `13.127.149.196`                              | `106.14.12.130`, `118.190.148.38`, `184.72.16.87`, `35.168.106.53`, `35.156.231.150`, `15.237.134.178`, `54.178.26.110`, `52.221.23.86`, `13.230.60.35`, `15.206.47.129`, `13.127.149.196`, `13.209.247.137`, `13.124.182.235`, `23.98.43.152`, `107.155.14.132`, `69.28.51.142` | UDP      | `8443`                   | Add new IPs to existing configuration |
| Cloud Proxy       | `129.227.217.128/28`, `129.227.108.208/28`, `128.1.105.112/28` | `129.227.217.128/28`, `129.227.108.208/28`, `128.1.105.112/28`                                                                                                                                                                                                                   | UDP      | `4590-4600`, `8001-8010` | No change required                    |

#### Mainland China

| Service type      | Current IP addresses                                                                                                                                                             | New IP addresses                                                                                                                                                                 | Protocol | Port                     | Action required    |
| ----------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------------------ | ------------------ |
| Signaling Service | `106.14.12.130`, `118.190.148.38`                                                                                                                                                | `106.14.12.130`, `118.190.148.38`                                                                                                                                                | UDP      | `8443`                   | No change required |
| Cloud Proxy       | `14.29.38.144/28`, `27.45.161.144/28`, `183.232.200.144/28`, `115.238.206.0/28`, `106.3.209.0/28`, `112.13.216.0/28`, `219.153.111.128/28`, `221.178.42.0/28`, `113.207.12.0/28` | `14.29.38.144/28`, `27.45.161.144/28`, `183.232.200.144/28`, `115.238.206.0/28`, `106.3.209.0/28`, `112.13.216.0/28`, `219.153.111.128/28`, `221.178.42.0/28`, `113.207.12.0/28` | UDP      | `4590-4600`, `8001-8010` | No change required |

### Native RTC Force TCP mode

#### North America

| Service type      | Current IP addresses                                                            | New IP addresses                                                                                                                                                                                                                                                                | Protocol | Port  | Action required                       |
| ----------------- | ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ----- | ------------------------------------- |
| Signaling Service | `52.54.85.111`, `184.72.18.217`                                                 | `101.132.108.165`, `123.56.235.221`, `52.54.85.111`, `184.72.18.217`, `52.28.239.238`, `3.9.120.239`, `13.250.89.184`, `18.176.162.64`, `168.138.214.216`, `20.193.241.143`, `3.109.116.108`, `3.36.161.253`, `15.164.88.208`, `164.52.43.58`, `54.205.123.178`, `50.18.20.222` | TCP      | `443` | Add new IPs to existing configuration |
| Cloud Proxy       | `128.14.195.192/28`, `128.14.245.16/28`, `128.14.72.80/28`, `128.14.200.208/28` | `128.14.195.192/28`, `128.14.245.16/28`, `128.14.72.80/28`, `128.14.200.208/28`                                                                                                                                                                                                 | TCP      | `443` | No change required                    |

#### Europe

| Service type      | Current IP addresses                                                         | New IP addresses                                                                                                                                                                                                                                                                | Protocol | Port  | Action required                       |
| ----------------- | ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ----- | ------------------------------------- |
| Signaling Service | `52.28.239.238`, `3.9.120.239`                                               | `101.132.108.165`, `123.56.235.221`, `52.54.85.111`, `184.72.18.217`, `52.28.239.238`, `3.9.120.239`, `13.250.89.184`, `18.176.162.64`, `168.138.214.216`, `20.193.241.143`, `3.109.116.108`, `3.36.161.253`, `15.164.88.208`, `164.52.43.58`, `54.205.123.178`, `50.18.20.222` | TCP      | `443` | Add new IPs to existing configuration |
| Cloud Proxy       | `104.166.160.208/28`, `23.236.110.32/28`, `104.166.142.134`, `104.166.161.4` | `104.166.160.208/28`, `23.236.110.32/28`, `104.166.142.134`, `104.166.161.4`                                                                                                                                                                                                    | TCP      | `443` | No change required                    |

#### Asia, excluding Mainland China

| Service type      | Current IP addresses                                         | New IP addresses                                                                                                                                                                                                                                                                | Protocol | Port  | Action required                       |
| ----------------- | ------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ----- | ------------------------------------- |
| Signaling Service | `13.250.89.184`, `18.176.162.64`                             | `101.132.108.165`, `123.56.235.221`, `52.54.85.111`, `184.72.18.217`, `52.28.239.238`, `3.9.120.239`, `13.250.89.184`, `18.176.162.64`, `168.138.214.216`, `20.193.241.143`, `3.109.116.108`, `3.36.161.253`, `15.164.88.208`, `164.52.43.58`, `54.205.123.178`, `50.18.20.222` | TCP      | `443` | Add new IPs to existing configuration |
| Cloud Proxy       | `128.1.186.240/28`, `129.227.73.32/28`, `103.193.127.208/28` | `128.1.186.240/28`, `129.227.73.32/28`, `103.193.127.208/28`                                                                                                                                                                                                                    | TCP      | `443` | No change required                    |

#### Japan

| Service type      | Current IP addresses                                                         | New IP addresses                                                                                                                                                                                                                                                                | Protocol | Port  | Action required                       |
| ----------------- | ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ----- | ------------------------------------- |
| Signaling Service | `168.138.214.216`, `18.176.162.64`                                           | `101.132.108.165`, `123.56.235.221`, `52.54.85.111`, `184.72.18.217`, `52.28.239.238`, `3.9.120.239`, `13.250.89.184`, `18.176.162.64`, `168.138.214.216`, `20.193.241.143`, `3.109.116.108`, `3.36.161.253`, `15.164.88.208`, `164.52.43.58`, `54.205.123.178`, `50.18.20.222` | TCP      | `443` | Add new IPs to existing configuration |
| Cloud Proxy       | `129.227.113.112/28`, `129.227.55.96/28`, `122.10.153.74`, `129.227.234.123` | `129.227.113.112/28`, `129.227.55.96/28`, `122.10.153.74`, `129.227.234.123`                                                                                                                                                                                                    | TCP      | `443` | No change required                    |

#### India

| Service type      | Current IP addresses                                           | New IP addresses                                                                                                                                                                                                                                                                | Protocol | Port  | Action required                       |
| ----------------- | -------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ----- | ------------------------------------- |
| Signaling Service | `3.109.116.108`, `20.193.241.143`                              | `101.132.108.165`, `123.56.235.221`, `52.54.85.111`, `184.72.18.217`, `52.28.239.238`, `3.9.120.239`, `13.250.89.184`, `18.176.162.64`, `168.138.214.216`, `20.193.241.143`, `3.109.116.108`, `3.36.161.253`, `15.164.88.208`, `164.52.43.58`, `54.205.123.178`, `50.18.20.222` | TCP      | `443` | Add new IPs to existing configuration |
| Cloud Proxy       | `129.227.217.128/28`, `129.227.108.208/28`, `128.1.105.112/28` | `129.227.217.128/28`, `129.227.108.208/28`, `128.1.105.112/28`                                                                                                                                                                                                                  | TCP      | `443` | No change required                    |

#### Mainland China

| Service type      | Current IP addresses                                                                                                                                                             | New IP addresses                                                                                                                                                                 | Protocol | Port  | Action required                       |
| ----------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ----- | ------------------------------------- |
| Signaling Service | `101.132.108.165`, `123.56.235.221`                                                                                                                                              | `101.132.108.165`, `123.56.235.221`                                                                                                                                              | TCP      | `443` | Add new IPs to existing configuration |
| Cloud Proxy       | `14.29.38.144/28`, `27.45.161.144/28`, `183.232.200.144/28`, `115.238.206.0/28`, `106.3.209.0/28`, `112.13.216.0/28`, `219.153.111.128/28`, `221.178.42.0/28`, `113.207.12.0/28` | `14.29.38.144/28`, `27.45.161.144/28`, `183.232.200.144/28`, `115.238.206.0/28`, `106.3.209.0/28`, `112.13.216.0/28`, `219.153.111.128/28`, `221.178.42.0/28`, `113.207.12.0/28` | TCP      | `443` | No change required                    |

    
  
      
  
      
  
      
  
      
  
      
  
      
  
## Implementation and validation

Use the following approach to successfully migrate your Cloud Proxy configuration without service disruption.

### Implement migration

Once you've completed testing, use a phased approach to implement the new Cloud Proxy configuration:

* Begin with non-production environments
* Update firewall rules based on your region

### Post-migration validation

After implementing the changes, verify your new configuration and check the connectivity.

1. **Test connectivity**

   Configure your client to use UDP Cloud Proxy mode and enable connectivity testing.

2. **Prepare fallback strategy**

   * Maintain complete documentation of original configuration
   * Create rollback procedures for quickly reverting changes if needed
   * Keep support contact information readily available

### Get support

For implementation assistance, contact [support@agora.io](mailto\:support@agora.io) with your specific SDK version and region requirements.
