Disabling SIP ALG on FortiGate Firewalls
← Network & Firewall
Terminal window
Terminal window
Terminal window
Disabling SIP ALG on FortiGate Firewalls
Section titled “Disabling SIP ALG on FortiGate Firewalls”SIP ALG (Application Layer Gateway) attempts to assist with NAT traversal for SIP traffic but typically causes more problems than it solves. On FortiGate firewalls, SIP ALG interference can result in:
- One-way audio on calls
- Calls dropping after 30 seconds
- Registration failures or repeated re-registrations
- Audio delays or jitter
Disabling SIP ALG is strongly recommended for any FortiGate behind which VoIP devices register with SIPSTACK.
Method 1: Web Interface (GUI)
Section titled “Method 1: Web Interface (GUI)”Step 1: Log into the FortiGate Web Interface
Section titled “Step 1: Log into the FortiGate Web Interface”- Open a browser and navigate to the FortiGate management IP address.
- Log in with your administrator credentials.
Step 2: Disable SIP ALG via Application Control
Section titled “Step 2: Disable SIP ALG via Application Control”- Navigate to Security Profiles → Application Control.
- Open the Application Control profile applied to your LAN-to-WAN policy.
- In the Application Overrides section, find SIP.
- Set the SIP action to Block or Monitor (not Allow) — this prevents FortiGate from processing SIP packets through the ALG engine.
Step 3: Disable via VoIP Profile (FortiOS 6.4+)
Section titled “Step 3: Disable via VoIP Profile (FortiOS 6.4+)”- Navigate to Security Profiles → VoIP.
- Edit the profile assigned to your internet-facing policy.
- Set SIP to disabled, or delete the VoIP profile from the policy entirely.
Method 2: CLI (Recommended — Reliable Across All FortiOS Versions)
Section titled “Method 2: CLI (Recommended — Reliable Across All FortiOS Versions)”SSH or console into the FortiGate and run:
config system settings set sip-helper disable set sip-nat-trace disableend
config system session-helper showendThe show output lists numbered session helpers. Find the entry for SIP (typically port 5060) and delete it:
config system session-helper delete 13endReplace 13 with the actual entry number shown for SIP in your output.
Reboot the FortiGate after making CLI changes:
execute rebootStep 4: Verify and Test
Section titled “Step 4: Verify and Test”- After changes are applied, check that VoIP phones re-register successfully.
- Make a test call — confirm two-way audio on both ends.
- Monitor VoIP traffic for 10–15 minutes to confirm stability.