Skip to content

Network & Firewall

Most call-quality and registration problems on Nova PBX are caused by the local network — usually SIP ALG or blocked RTP ports. This page is the diagnostic guide; the canonical reference for ports, codecs, bandwidth, and QoS is Nova PBX Network Requirements.


Open these outbound from your network:

ProtocolPort(s)Purpose
UDP / TCP5060SIP signaling
TLS5061SIP signaling (encrypted)
UDP10000–20000RTP media (voice audio)
TCP / HTTPS443Switchboard, provisioning, API

Full details, codecs, and QoS markings: Network Requirements.


SIP ALG (Application Layer Gateway) is the single most common cause of VoIP problems. It is enabled by default on many consumer and SMB routers and rewrites SIP packets in ways that break signaling.

Symptoms:

  • Phones register briefly then drop
  • One-way audio
  • Calls fail or drop after ~30 seconds
  • Phone shows registered but inbound calls don’t ring
BrandLocation
Ubiquiti UniFiSettings → Site/Advanced → SIP (ALG / Transformations) — disable
Cisco (IOS)no ip nat service sip udp port 5060
Cisco MerakiDisabled by default on newer firmware — verify under Security & SD-WAN → Firewall
NetgearAdvanced → WAN Setup → uncheck SIP ALG
TP-LinkAdvanced → NAT Forwarding → ALG → disable SIP
AsusWAN → NAT Passthrough → disable SIP Passthrough
MikroTikIP → Firewall → Service Ports → disable the sip entry
pfSenseAvoid the siproxd package; no ALG by default
FortinetDisable the SIP session helper / VoIP profile SIP inspection

After disabling SIP ALG, reboot the router and retest.


Two routers in the path (e.g. an ISP modem/router plus your own office router) means SIP traffic crosses two NAT layers — a common source of one-way audio and dropped registrations.

Fix: Put the ISP modem/router in bridge mode so only one device performs NAT.

Some enterprise firewalls map each outbound connection to a different external port, which breaks normal NAT traversal. If you’ve ruled out SIP ALG and double-NAT and still see audio problems on an enterprise firewall, contact support — explicit allow rules for SIPSTACK’s infrastructure usually resolve it.


Each concurrent G.711 call needs roughly 87 kbps each way (G.729: ~31 kbps). See Network Requirements for full per-codec figures and QoS (DSCP) recommendations.

A fast connection with high jitter or packet loss still produces bad audio — raw speed-test numbers don’t guarantee call quality.


  • Registered / Online — signaling works; quality issues are RTP-related (ports, bandwidth, jitter)
  • Unregistered / Offline — signaling is blocked; check ports 5060/5061, SIP ALG, and that your last PBX change was applied

Register the phone (or the Pulse app) on a mobile hotspot. If it works there but not on your office network, the problem is your office firewall/router.

Terminal window
ping -c 100 8.8.8.8

More than ~0.1% loss or >20 ms jitter on a sustained ping indicates a network problem that will degrade calls regardless of firewall settings.

If the above doesn’t identify it, contact support with: the extension and numbers involved, exact times (with timezone), whether the issue is inbound/outbound/both, and your router/firewall make and model. A SIP trace or packet capture from your side speeds things up dramatically.


Before contacting support for call-quality issues, verify:

  • SIP ALG disabled on every router in the path
  • UDP 5060 outbound open (TLS 5061 if used)
  • UDP 10000–20000 permitted both directions
  • TCP/HTTPS 443 outbound open
  • No double-NAT
  • Pending PBX changes applied
  • Phone tested on a mobile hotspot to isolate the office network
  • Packet loss < 0.1% and jitter < 20 ms on a sustained ping