Skip to content
English
  • There are no suggestions because the search field is empty.

Mursion Magic — Tech Implementation & Network Requirements (Human-Powered)

What your learners need to connect to Mursion Magic simulations.

This article covers the network, firewall, and device configuration required to run human-powered Mursion Magic simulations across your organization. If your organization also runs AI-powered simulations, see AI-powered simulations related articles for separate requirements.

Before You Begin

Before configuring your network, review the Supported Browsers & Device Requirements article so your IT team understands the browser, webcam, and microphone requirements participants will need on their end. Confirming these requirements up front prevents network changes from being undermined by an unsupported device later on.

Network & Firewall Planning

Start by mapping out where your participants will connect from:

  • Single office network: you'll typically only need to update one firewall.
  • Multiple offices, departments, or cohorts with different firewall policies: each of those networks will need the same allowlist applied.
  • VPN connections: confirm whether participants connect through a VPN. VPNs often apply different filtering rules than a standard office connection, and unaddressed VPN filtering is one of the most common causes of connection failures we see.

Testing Recommendations

Once your network changes are in place, test connectivity with a small group of participants representing each office location, firewall environment, and VPN or non-VPN configuration you support. Run this test at least 48 hours before a participant's first live session so any remaining issues can be resolved without delaying a scheduled simulation.

Human-Powered Allowlist (Ports, Domains, IPs)

Human-powered Mursion Magic sessions require outbound and inbound access to the following TURN servers over the standard WebRTC TCP and UDP port ranges:

Protocol Ports Destination
UDP 3478 turn-west-001.mursion.com
(IP address: 34.212.18.106)
TCP 443, 3478 turn-west-001.mursion.com
(IP address: 34.212.18.106)
UDP 3478 turn-west-002.mursion.com
(IP address: 52.39.110.64)
TCP 443, 3478 turn-west-002.mursion.com
(IP address: 52.39.110.64)

Make sure content filters and proxies are not blocking WebRTC traffic even when these ports are already open elsewhere in your configuration. This allowlist should only include human-powered destinations — AI/LiveKit destinations are covered separately in the AI Simulations article.

Zscaler SSL Inspection Bypass

If your organization uses Zscaler or a similar SSL inspection tool, exclude the following domains from SSL inspection:

Without this exclusion, participants typically experience dropped connections mid-session or a black screen when they try to join, since the inspection process interferes with the encrypted media stream.

WebSocket & HTTPS Allowlist

In addition to the TURN servers above, allowlist the wss:// and https:// traffic for:

Email Allowlisting

So participants reliably receive scheduling confirmations and session reminders, allowlist the following in your email security tools:

Link redirects in these emails also route through mursion.com, so that domain needs to be permitted for links to open correctly as well.

When to Contact Support

If a connection issue can't be resolved using the steps above, email support@mursion.com with:

  • Your organization name
  • The affected participant location(s)
  • The browser and operating system in use
  • A screenshot (or short recording) of the error
  • The date and time of the affected session