Skip to content

Network Requirements

This page documents the network configuration required for Nova PBX to function correctly. Incorrect firewall rules or router settings are the most common cause of one-way audio, dropped calls, and registration failures.

Open these ports outbound from your network to the SIPSTACK infrastructure:

ProtocolPort(s)Purpose
UDP5060SIP signaling (standard)
TCP5060SIP signaling (TCP transport)
TLS5061SIP signaling (encrypted)
UDP10000–20000RTP media (audio streams)
TCP / HTTPS443SIPSTACK provisioning server and Switchboard portal
CodecBandwidth (bidirectional)QualityNotes
G.711 ulaw~87 kbpsHighDefault for North America
G.711 alaw~87 kbpsHighCommon in Europe
G.722~87 kbpsHD WidebandRequires G.722-capable endpoints
G.729~31 kbpsCompressedLow bandwidth; requires license on some devices

G.711 ulaw is recommended for most deployments. G.729 is suitable for sites with limited bandwidth but reduces audio fidelity.

CodecPer-call bandwidth (one direction)Bidirectional
G.711 ulaw~43.5 kbps~87 kbps
G.711 alaw~43.5 kbps~87 kbps
G.722~43.5 kbps~87 kbps
G.729~15.2 kbps~31 kbps

These figures include RTP packet overhead. For capacity planning, add 10–15% headroom above your expected peak concurrent calls.

Minimum recommended internet speeds:

  • Baseline: 10 Mbps symmetric
  • Per additional concurrent call: 100 kbps (G.711) or 35 kbps (G.729)
  • Example: 10 concurrent G.711 calls = ~10 Mbps + 870 kbps = ~11 Mbps needed

If your network supports QoS, configure DSCP markings to prioritize voice traffic:

Traffic TypeDSCP ValueDSCP Name
SIP signaling24CS3
RTP audio46EF (Expedited Forwarding)

Mark and queue EF traffic in a priority queue on your switches and routers. This is especially important on networks that share internet bandwidth with video conferencing, file transfers, or backups.

Nova PBX handles NAT traversal via symmetric RTP and STUN. Most deployments work without special configuration. If you experience one-way audio after disabling SIP ALG:

  1. Ensure the RTP port range (10000–20000 UDP) is open outbound on your firewall.
  2. Verify your SIP devices are not running behind a double-NAT (e.g. a router behind another router).
  3. If you use a strict outbound firewall, create explicit allow rules for the SIPSTACK SBC IP ranges (available in the Switchboard portal under Account → Network).

SIP ALG is known to break VoIP on the following common router brands:

  • Cisco Meraki (disabled by default in newer firmware; verify under Security & SD-WAN → Firewall)
  • Ubiquiti UniFi (disabled in USG and UDM under Settings → Site → Advanced → SIP Transformations)
  • Mikrotik (disable ip firewall service-port for SIP)
  • Netgear (Advanced → WAN Setup → uncheck “SIP ALG”)
  • TP-Link (Advanced → NAT Forwarding → ALG → disable SIP)

For other brands, search your router model + “disable SIP ALG” for specific steps.

If you are experiencing call issues, work through this checklist:

  1. SIP ALG disabled on all routers and firewalls in the path
  2. UDP 5060 and UDP 10000–20000 open outbound
  3. HTTPS 443 accessible to the SIPSTACK provisioning server (for device auto-provisioning)
  4. No double-NAT
  5. Sufficient bandwidth for peak concurrent call volume
  6. QoS configured if sharing bandwidth with other high-usage applications

See Troubleshooting Network & Firewall Issues for detailed diagnostic steps.