Skip to content

Configuring WatchGuard Firebox for VoIP

← Network & Firewall

Incoming calls experience intermittent no-audio or one-way audio when the WatchGuard firewall does not properly handle NAT translation for RTP media streams. Outbound and internal calls typically work fine. This guide walks through the configuration steps to resolve the issue.

  • No audio on incoming calls (intermittent)
  • Caller cannot hear the called party
  • Outgoing calls work normally
  • Internal calls work normally
RequirementDetails
WatchGuard FireboxAny model with supported Fireware OS
Admin AccessLogin credentials for WatchGuard Web UI
SIP ALGMust be disabled
SIPSTACK RTP RangeUDP 10000–65535
Phone RTP RangeUDP 2222–2269 (Polycom default)
  1. Navigate to System > Global Settings.
  2. Uncheck Enable SIP ALG.
  3. Click Save.
  4. Reboot the Firebox for the change to take effect.

Step 2: Configure 1-to-1 NAT for the VoIP Subnet

Section titled “Step 2: Configure 1-to-1 NAT for the VoIP Subnet”

1-to-1 NAT ensures the firewall rewrites the phone’s private IP in SDP packets to your public IP, which is the core fix for one-way audio on incoming calls.

  1. Navigate to Network > NAT > 1-to-1 NAT.
  2. Click Add.
  3. Configure:
SettingValue
NameSIPSTACK-VoIP-NAT
EnableChecked
TypeIP Range or Network
Internal IP RangeYour phone subnet (e.g., 192.168.1.0/24)
External IPYour public IP
DirectionBidirectional
  1. Under Advanced Options, enable NAT Reflection (if available) and Sticky Connections. Set Connection Timeout to 300 seconds.
  2. Click Save.

Step 3: Configure Outbound NAT with Port Preservation

Section titled “Step 3: Configure Outbound NAT with Port Preservation”

If 1-to-1 NAT is unavailable, use Dynamic NAT with these settings:

  1. Navigate to Network > NAT > Dynamic NAT.
  2. Click Add and configure:
Name: SIPSTACK-VoIP-Outbound
From: Internal phone network
To: Any-External
NAT Type: Dynamic NAT
NAT to: Use Interface IP
  1. Enable Preserve Source Port and Sticky Connections. Set UDP Timeout to 300 seconds.
SettingValue
NameSIPSTACK-SIP-Outbound
FromInternal Network
ToSIPSTACK SIP server IPs
ServiceSIP (or Custom UDP 5060)
ActionAllow
NATUse policy-based NAT (from Step 2 or 3)

This policy is required for incoming audio to work correctly.

SettingValue
NameSIPSTACK-RTP-Inbound
FromAny-External
ToFirebox
ServiceCustom
ProtocolUDP
Port Range2222–2269 (Polycom) AND 10000–65535 (SIPSTACK)
ActionAllow
NAT1-to-1 NAT (from Step 2)

Enable Handle as VoIP Traffic, Disable Deep Packet Inspection, and Enable Fast Path in Advanced Settings.

SettingValue
NameSIPSTACK-RTP-Outbound
FromInternal Network
ToAny-External
ProtocolUDP
Port Range10000–65535
ActionAllow
NATUse policy-based NAT
  1. Navigate to Firewall > Firewall Settings > Global Settings.
  2. Set timeouts:
Timeout TypeValue
UDP Timeout300 seconds
UDP Stream Timeout300 seconds
VoIP Session Timeout3600 seconds (if available)
  1. Click Save.

Step 6: Enable NAT Traversal Helper (If Available)

Section titled “Step 6: Enable NAT Traversal Helper (If Available)”

Some WatchGuard models include a NAT traversal helper that performs better than SIP ALG:

  1. Navigate to System > Packet Handling.
  2. Look for NAT Traversal or STUN Helper.
  3. If present, enable it and configure:
    • Protocol: UDP
    • Ports: 3478, 5060, 10000–65535

Make an inbound test call, then check System Manager > Active Connections and look for:

  • UDP 5060 connections to SIPSTACK IPs
  • UDP connections in the 2222–2269 range (phone RTP)
  • UDP connections in the 10000–65535 range (SIPSTACK RTP)

If connections appear but audio is still missing, the NAT translation is not rewriting the SDP IP correctly.

Still no audio on incoming calls?

  1. Verify SIP ALG is truly disabled. In Traffic Monitor, SIP packets should not have an ALG tag.
  2. Check for private IP leaks in SDP. In Traffic Monitor, filter for port 5060 and inspect SIP 200 OK packets. If you see c=IN IP4 192.168.x.x, NAT is not rewriting the SDP.
  3. Try Static Port NAT. Map YourPublicIP:2222–2269 → PhoneSubnet:2222–2269.
  4. Enable logging on all VoIP policies and look for denied packets during calls.

Alternative: SNAT Rules

If standard NAT does not work, try Source NAT (SNAT):

  1. Navigate to Network > SNAT.
  2. Create a rule:
Name: Force-VoIP-SNAT
From: Internal phone network
To: SIPSTACK IPs
Action: SNAT
SNAT to: Your Public IP
Preserve Ports: YES

Three settings are critical for WatchGuard VoIP compatibility:

  1. SIP ALG must be disabled — it breaks NAT traversal.
  2. 1-to-1 NAT or SNAT — ensures proper IP rewriting in SDP.
  3. Inbound RTP ports open — both the phone RTP range and the SIPSTACK RTP range.