Network & Firewall
Network & Firewall
Section titled “Network & Firewall”Most call-quality and registration problems on Nova PBX are caused by the local network — usually SIP ALG or blocked RTP ports. This page is the diagnostic guide; the canonical reference for ports, codecs, bandwidth, and QoS is Nova PBX Network Requirements.
Required Ports (summary)
Section titled “Required Ports (summary)”Open these outbound from your network:
| Protocol | Port(s) | Purpose |
|---|---|---|
| UDP / TCP | 5060 | SIP signaling |
| TLS | 5061 | SIP signaling (encrypted) |
| UDP | 10000–20000 | RTP media (voice audio) |
| TCP / HTTPS | 443 | Switchboard, provisioning, API |
Full details, codecs, and QoS markings: Network Requirements.
SIP ALG — Disable It
Section titled “SIP ALG — Disable It”SIP ALG (Application Layer Gateway) is the single most common cause of VoIP problems. It is enabled by default on many consumer and SMB routers and rewrites SIP packets in ways that break signaling.
Symptoms:
- Phones register briefly then drop
- One-way audio
- Calls fail or drop after ~30 seconds
- Phone shows registered but inbound calls don’t ring
Where to find it, by router brand
Section titled “Where to find it, by router brand”| Brand | Location |
|---|---|
| Ubiquiti UniFi | Settings → Site/Advanced → SIP (ALG / Transformations) — disable |
| Cisco (IOS) | no ip nat service sip udp port 5060 |
| Cisco Meraki | Disabled by default on newer firmware — verify under Security & SD-WAN → Firewall |
| Netgear | Advanced → WAN Setup → uncheck SIP ALG |
| TP-Link | Advanced → NAT Forwarding → ALG → disable SIP |
| Asus | WAN → NAT Passthrough → disable SIP Passthrough |
| MikroTik | IP → Firewall → Service Ports → disable the sip entry |
| pfSense | Avoid the siproxd package; no ALG by default |
| Fortinet | Disable the SIP session helper / VoIP profile SIP inspection |
After disabling SIP ALG, reboot the router and retest.
NAT Problems
Section titled “NAT Problems”Double-NAT
Section titled “Double-NAT”Two routers in the path (e.g. an ISP modem/router plus your own office router) means SIP traffic crosses two NAT layers — a common source of one-way audio and dropped registrations.
Fix: Put the ISP modem/router in bridge mode so only one device performs NAT.
Strict / symmetric NAT
Section titled “Strict / symmetric NAT”Some enterprise firewalls map each outbound connection to a different external port, which breaks normal NAT traversal. If you’ve ruled out SIP ALG and double-NAT and still see audio problems on an enterprise firewall, contact support — explicit allow rules for SIPSTACK’s infrastructure usually resolve it.
Bandwidth & Quality
Section titled “Bandwidth & Quality”Each concurrent G.711 call needs roughly 87 kbps each way (G.729: ~31 kbps). See Network Requirements for full per-codec figures and QoS (DSCP) recommendations.
A fast connection with high jitter or packet loss still produces bad audio — raw speed-test numbers don’t guarantee call quality.
Diagnosing Problems
Section titled “Diagnosing Problems”Step 1: Check SIP registration
Section titled “Step 1: Check SIP registration”- Registered / Online — signaling works; quality issues are RTP-related (ports, bandwidth, jitter)
- Unregistered / Offline — signaling is blocked; check ports 5060/5061, SIP ALG, and that your last PBX change was applied
Step 2: Test on a known-good network
Section titled “Step 2: Test on a known-good network”Register the phone (or the Pulse app) on a mobile hotspot. If it works there but not on your office network, the problem is your office firewall/router.
Step 3: Check for packet loss and jitter
Section titled “Step 3: Check for packet loss and jitter”ping -c 100 8.8.8.8More than ~0.1% loss or >20 ms jitter on a sustained ping indicates a network problem that will degrade calls regardless of firewall settings.
Step 4: Escalate with detail
Section titled “Step 4: Escalate with detail”If the above doesn’t identify it, contact support with: the extension and numbers involved, exact times (with timezone), whether the issue is inbound/outbound/both, and your router/firewall make and model. A SIP trace or packet capture from your side speeds things up dramatically.
Checklist
Section titled “Checklist”Before contacting support for call-quality issues, verify:
- SIP ALG disabled on every router in the path
- UDP 5060 outbound open (TLS 5061 if used)
- UDP 10000–20000 permitted both directions
- TCP/HTTPS 443 outbound open
- No double-NAT
- Pending PBX changes applied
- Phone tested on a mobile hotspot to isolate the office network
- Packet loss < 0.1% and jitter < 20 ms on a sustained ping