Mursion Magic — Tech Implementation & Network Requirements (Human-Powered)
What your learners need to connect to Mursion Magic simulations.
This article covers the network, firewall, and device configuration required to run human-powered Mursion Magic simulations across your organization. If your organization also runs AI-powered simulations, see AI-powered simulations related articles for separate requirements.
Before You Begin
Before configuring your network, review the Supported Browsers & Device Requirements article so your IT team understands the browser, webcam, and microphone requirements participants will need on their end. Confirming these requirements up front prevents network changes from being undermined by an unsupported device later on.
Network & Firewall Planning
Start by mapping out where your participants will connect from:
- Single office network: you'll typically only need to update one firewall.
- Multiple offices, departments, or cohorts with different firewall policies: each of those networks will need the same allowlist applied.
- VPN connections: confirm whether participants connect through a VPN. VPNs often apply different filtering rules than a standard office connection, and unaddressed VPN filtering is one of the most common causes of connection failures we see.
Testing Recommendations
Once your network changes are in place, test connectivity with a small group of participants representing each office location, firewall environment, and VPN or non-VPN configuration you support. Run this test at least 48 hours before a participant's first live session so any remaining issues can be resolved without delaying a scheduled simulation.
Human-Powered Allowlist (Ports, Domains, IPs)
Human-powered Mursion Magic sessions require outbound and inbound access to the following TURN servers over the standard WebRTC TCP and UDP port ranges:
| Protocol | Ports | Destination |
| UDP | 3478 | turn-west-001.mursion.com (IP address: 34.212.18.106) |
| TCP | 443, 3478 | turn-west-001.mursion.com (IP address: 34.212.18.106) |
| UDP | 3478 | turn-west-002.mursion.com (IP address: 52.39.110.64) |
| TCP | 443, 3478 | turn-west-002.mursion.com (IP address: 52.39.110.64) |
Make sure content filters and proxies are not blocking WebRTC traffic even when these ports are already open elsewhere in your configuration. This allowlist should only include human-powered destinations — AI/LiveKit destinations are covered separately in the AI Simulations article.
Zscaler SSL Inspection Bypass
If your organization uses Zscaler or a similar SSL inspection tool, exclude the following domains from SSL inspection:
Without this exclusion, participants typically experience dropped connections mid-session or a black screen when they try to join, since the inspection process interferes with the encrypted media stream.
WebSocket & HTTPS Allowlist
In addition to the TURN servers above, allowlist the wss:// and https:// traffic for:
Email Allowlisting
So participants reliably receive scheduling confirmations and session reminders, allowlist the following in your email security tools:
Link redirects in these emails also route through mursion.com, so that domain needs to be permitted for links to open correctly as well.
When to Contact Support
If a connection issue can't be resolved using the steps above, email support@mursion.com with:
- Your organization name
- The affected participant location(s)
- The browser and operating system in use
- A screenshot (or short recording) of the error
- The date and time of the affected session