Skip to content

General Firewall Configuration for VoIP

← Network & Firewall

This article covers the ports and IP rules your firewall needs to allow for SIPSTACK VoIP service to work reliably. Misconfigured firewalls are one of the most common causes of one-way audio, dropped calls, and registration failures.

Open the following ports on your firewall for all VoIP traffic to and from SIPSTACK servers:

ServicePortsProtocolDescription
SIP Signaling5060–5098TCP/UDPSIP call setup and signaling
RTP Media10000–65535UDPAudio/video media streams
T.38 Fax4000–4999UDPT.38 fax-over-IP transmission

SIP ALG (Application Layer Gateway) is a router feature that attempts to rewrite SIP packets. It nearly always causes problems with VoIP services, including:

  • Calls connecting but no audio
  • Registration failures
  • Calls dropping after exactly 30 seconds

Always disable SIP ALG on your router/firewall. See:

If your firewall uses allowlists, you’ll need to permit traffic from SIPSTACK infrastructure. Contact SIPSTACK Support for the current list of IP addresses and subnets for your region.

SettingRecommended Value
SIP ALGDisabled
UDP session timeout600 seconds or higher
TCP session timeout1800 seconds or higher
NAT keep-aliveEnabled
DSCP marking for SIPEF (Expedited Forwarding)