General Firewall Configuration for VoIP
← Network & Firewall
General Firewall Configuration for VoIP
Section titled “General Firewall Configuration for VoIP”This article covers the ports and IP rules your firewall needs to allow for SIPSTACK VoIP service to work reliably. Misconfigured firewalls are one of the most common causes of one-way audio, dropped calls, and registration failures.
Required Ports
Section titled “Required Ports”Open the following ports on your firewall for all VoIP traffic to and from SIPSTACK servers:
| Service | Ports | Protocol | Description |
|---|---|---|---|
| SIP Signaling | 5060–5098 | TCP/UDP | SIP call setup and signaling |
| RTP Media | 10000–65535 | UDP | Audio/video media streams |
| T.38 Fax | 4000–4999 | UDP | T.38 fax-over-IP transmission |
Disable SIP ALG
Section titled “Disable SIP ALG”SIP ALG (Application Layer Gateway) is a router feature that attempts to rewrite SIP packets. It nearly always causes problems with VoIP services, including:
- Calls connecting but no audio
- Registration failures
- Calls dropping after exactly 30 seconds
Always disable SIP ALG on your router/firewall. See:
IP Whitelisting
Section titled “IP Whitelisting”If your firewall uses allowlists, you’ll need to permit traffic from SIPSTACK infrastructure. Contact SIPSTACK Support for the current list of IP addresses and subnets for your region.
Recommended Firewall Settings
Section titled “Recommended Firewall Settings”| Setting | Recommended Value |
|---|---|
| SIP ALG | Disabled |
| UDP session timeout | 600 seconds or higher |
| TCP session timeout | 1800 seconds or higher |
| NAT keep-alive | Enabled |
| DSCP marking for SIP | EF (Expedited Forwarding) |