Configuring WatchGuard Firebox for VoIP
Configuring WatchGuard Firebox for VoIP
Section titled “Configuring WatchGuard Firebox for VoIP”Incoming calls experience intermittent no-audio or one-way audio when the WatchGuard firewall does not properly handle NAT translation for RTP media streams. Outbound and internal calls typically work fine. This guide walks through the configuration steps to resolve the issue.
Symptoms
Section titled “Symptoms”- No audio on incoming calls (intermittent)
- Caller cannot hear the called party
- Outgoing calls work normally
- Internal calls work normally
Prerequisites
Section titled “Prerequisites”| Requirement | Details |
|---|---|
| WatchGuard Firebox | Any model with supported Fireware OS |
| Admin Access | Login credentials for WatchGuard Web UI |
| SIP ALG | Must be disabled |
| SIPSTACK RTP Range | UDP 10000–65535 |
| Phone RTP Range | UDP 2222–2269 (Polycom default) |
Configuration Steps
Section titled “Configuration Steps”Step 1: Disable SIP ALG
Section titled “Step 1: Disable SIP ALG”- Navigate to System > Global Settings.
- Uncheck Enable SIP ALG.
- Click Save.
- Reboot the Firebox for the change to take effect.
Step 2: Configure 1-to-1 NAT for the VoIP Subnet
Section titled “Step 2: Configure 1-to-1 NAT for the VoIP Subnet”1-to-1 NAT ensures the firewall rewrites the phone’s private IP in SDP packets to your public IP, which is the core fix for one-way audio on incoming calls.
- Navigate to Network > NAT > 1-to-1 NAT.
- Click Add.
- Configure:
| Setting | Value |
|---|---|
| Name | SIPSTACK-VoIP-NAT |
| Enable | Checked |
| Type | IP Range or Network |
| Internal IP Range | Your phone subnet (e.g., 192.168.1.0/24) |
| External IP | Your public IP |
| Direction | Bidirectional |
- Under Advanced Options, enable NAT Reflection (if available) and Sticky Connections. Set Connection Timeout to
300 seconds. - Click Save.
Step 3: Configure Outbound NAT with Port Preservation
Section titled “Step 3: Configure Outbound NAT with Port Preservation”If 1-to-1 NAT is unavailable, use Dynamic NAT with these settings:
- Navigate to Network > NAT > Dynamic NAT.
- Click Add and configure:
Name: SIPSTACK-VoIP-OutboundFrom: Internal phone networkTo: Any-ExternalNAT Type: Dynamic NATNAT to: Use Interface IP- Enable Preserve Source Port and Sticky Connections. Set UDP Timeout to
300 seconds.
Step 4: Create Firewall Policies
Section titled “Step 4: Create Firewall Policies”Outbound SIP Policy
Section titled “Outbound SIP Policy”| Setting | Value |
|---|---|
| Name | SIPSTACK-SIP-Outbound |
| From | Internal Network |
| To | SIPSTACK SIP server IPs |
| Service | SIP (or Custom UDP 5060) |
| Action | Allow |
| NAT | Use policy-based NAT (from Step 2 or 3) |
Inbound RTP Policy
Section titled “Inbound RTP Policy”This policy is required for incoming audio to work correctly.
| Setting | Value |
|---|---|
| Name | SIPSTACK-RTP-Inbound |
| From | Any-External |
| To | Firebox |
| Service | Custom |
| Protocol | UDP |
| Port Range | 2222–2269 (Polycom) AND 10000–65535 (SIPSTACK) |
| Action | Allow |
| NAT | 1-to-1 NAT (from Step 2) |
Enable Handle as VoIP Traffic, Disable Deep Packet Inspection, and Enable Fast Path in Advanced Settings.
Outbound RTP Policy
Section titled “Outbound RTP Policy”| Setting | Value |
|---|---|
| Name | SIPSTACK-RTP-Outbound |
| From | Internal Network |
| To | Any-External |
| Protocol | UDP |
| Port Range | 10000–65535 |
| Action | Allow |
| NAT | Use policy-based NAT |
Step 5: Configure UDP Session Timeout
Section titled “Step 5: Configure UDP Session Timeout”- Navigate to Firewall > Firewall Settings > Global Settings.
- Set timeouts:
| Timeout Type | Value |
|---|---|
| UDP Timeout | 300 seconds |
| UDP Stream Timeout | 300 seconds |
| VoIP Session Timeout | 3600 seconds (if available) |
- Click Save.
Step 6: Enable NAT Traversal Helper (If Available)
Section titled “Step 6: Enable NAT Traversal Helper (If Available)”Some WatchGuard models include a NAT traversal helper that performs better than SIP ALG:
- Navigate to System > Packet Handling.
- Look for NAT Traversal or STUN Helper.
- If present, enable it and configure:
- Protocol:
UDP - Ports:
3478, 5060, 10000–65535
- Protocol:
Verifying the Configuration
Section titled “Verifying the Configuration”Make an inbound test call, then check System Manager > Active Connections and look for:
- UDP 5060 connections to SIPSTACK IPs
- UDP connections in the 2222–2269 range (phone RTP)
- UDP connections in the 10000–65535 range (SIPSTACK RTP)
If connections appear but audio is still missing, the NAT translation is not rewriting the SDP IP correctly.
Troubleshooting
Section titled “Troubleshooting”Still no audio on incoming calls?
- Verify SIP ALG is truly disabled. In Traffic Monitor, SIP packets should not have an ALG tag.
- Check for private IP leaks in SDP. In Traffic Monitor, filter for port 5060 and inspect SIP 200 OK packets. If you see
c=IN IP4 192.168.x.x, NAT is not rewriting the SDP. - Try Static Port NAT. Map
YourPublicIP:2222–2269→PhoneSubnet:2222–2269. - Enable logging on all VoIP policies and look for denied packets during calls.
Alternative: SNAT Rules
If standard NAT does not work, try Source NAT (SNAT):
- Navigate to Network > SNAT.
- Create a rule:
Name: Force-VoIP-SNATFrom: Internal phone networkTo: SIPSTACK IPsAction: SNATSNAT to: Your Public IPPreserve Ports: YESSummary
Section titled “Summary”Three settings are critical for WatchGuard VoIP compatibility:
- SIP ALG must be disabled — it breaks NAT traversal.
- 1-to-1 NAT or SNAT — ensures proper IP rewriting in SDP.
- Inbound RTP ports open — both the phone RTP range and the SIPSTACK RTP range.