How to Enable DHCP Option 160 on a FortiNet Firewall
How to Enable DHCP Option 160 on a FortiNet Firewall
Section titled “How to Enable DHCP Option 160 on a FortiNet Firewall”DHCP Option 160 tells IP phones the URL of the provisioning server during the DHCP lease request. Configuring this on your FortiGate firewall allows supported phones to auto-provision without manual URL entry on each device.
Prerequisites
Section titled “Prerequisites”-
Admin access to the FortiGate web interface (Web-based Manager)
-
Your organization’s provisioning URL from Switchboard → Nova PBX → System → PBX Settings → Provisioning Access:
https://<slug>:<PIN>@cfg.sipstack.com/<slug>/<slug>is your tenant slug and<PIN>your provisioning PIN — replace both, including the angle brackets. The PIN is shown once when generated. Lost it? Rotate it in Provisioning Access — phones keep working on the old PIN for 24 hours. Background, verification steps and the same value for other DHCP servers: DHCP Option 160: Provisioning URL for Nova PBX Phones.
Configuration Steps
Section titled “Configuration Steps”1. Log In to the FortiGate Web Interface
Section titled “1. Log In to the FortiGate Web Interface”Open a browser, enter the FortiGate IP address, and log in with your administrative credentials.
2. Navigate to Network Interfaces
Section titled “2. Navigate to Network Interfaces”From the left menu, select Network > Interfaces.
3. Select the Interface
Section titled “3. Select the Interface”Find the interface hosting your DHCP server — typically a LAN or internal interface. Click Edit.
4. Open the DHCP Server Settings
Section titled “4. Open the DHCP Server Settings”Scroll down to the DHCP Server section. Ensure Enable DHCP Server is checked. If it is not enabled, enable it now.
5. Add DHCP Option 160
Section titled “5. Add DHCP Option 160”In the DHCP Server settings, find Advanced or DHCP Options and click Create New (or Add):
| Field | Value |
|---|---|
| Name | Option160 (or any descriptive name) |
| Code | 160 |
| Type | String |
| Value | https://<slug>:<PIN>@cfg.sipstack.com/<slug>/ with your slug and PIN filled in |
Click OK to save the option.
6. Apply Changes
Section titled “6. Apply Changes”Scroll to the bottom of the interface settings page and click OK or Save to apply all changes.
7. Test the Configuration
Section titled “7. Test the Configuration”Connect an IP phone that you have already registered under Nova PBX → Devices (with an extension on line 1 and Apply Changes clicked). The phone receives the provisioning server URL during its DHCP lease, fetches its configuration and shows its extension within a minute or two.
Related Resources
Section titled “Related Resources”- DHCP Option 160: Provisioning URL for Nova PBX Phones — the same value for Windows Server, pfSense, ISC dhcpd and MikroTik, plus verification and troubleshooting
- General Firewall Configuration for VoIP
- Enabling QoS on a FortiGate Firewall for VoIP