Optimizing VoIP Performance on Cisco Meraki MX Firewalls
Optimizing VoIP Performance on Cisco Meraki MX Firewalls
Section titled “Optimizing VoIP Performance on Cisco Meraki MX Firewalls”This guide covers Quality of Service (QoS) and network optimizations on Cisco Meraki MX firewalls to ensure high-quality VoIP performance with SIPSTACK. Following these steps reduces common issues such as dropped calls, choppy audio, jitter, echo, and one-way audio.
VoIP traffic is highly sensitive to latency, jitter, and packet loss. The Meraki MX provides robust tools to prioritize VoIP traffic and isolate it from competing network activity.
Prerequisites
Section titled “Prerequisites”- Admin access to the Meraki Dashboard
- Access to the SIPSTACK Switchboard portal for configuration details
- Knowledge of your WAN bandwidth (upstream and downstream)
- A VLAN for VoIP traffic (recommended)
- SIPSTACK-supported devices such as Polycom VVX, Yealink handsets, or the Switchboard app
Contact SIPSTACK Support for specific SIP server IP blocks and port details needed for firewall rules.
Step 1: Run Bandwidth Tests
Section titled “Step 1: Run Bandwidth Tests”Accurate WAN bandwidth figures are needed for effective QoS configuration.
- Temporarily disable existing traffic shaping and firewall rules to avoid skewed results.
- Go to speedtest.net and run three consecutive tests outside business hours. Note the lowest upload and download speeds from the tests.
- In the Meraki Dashboard, navigate to Security & SD-WAN > Configure > Traffic Shaping. Click the Details link for your WAN uplink and enter speeds slightly below the lowest test results. For example, if tests show 100 Mbps down / 20 Mbps up, set 95 Mbps down / 18 Mbps up. This prevents the uplink from saturating and pushing VoIP packets into queues.
Step 2: Configure a Voice VLAN
Section titled “Step 2: Configure a Voice VLAN”Segregating VoIP traffic into a dedicated VLAN isolates it from data traffic and simplifies QoS rules.
- Navigate to Security & SD-WAN > Configure > Addressing & VLANs.
- Enable VLANs if not already enabled.
- Add a new VLAN (e.g., VLAN 100, named “VOICE”) with a unique subnet (e.g.,
192.168.100.0/24) and set the MX gateway IP (e.g.,192.168.100.1). - For Meraki MS switches, configure access ports to advertise the Voice VLAN via LLDP or CDP. Navigate to Switches > Configure > Switch Ports, select the port, and set the Voice VLAN.
- If the MX handles inter-VLAN routing, ensure the Voice VLAN can reach SIPSTACK’s SIP servers without restriction.
Step 3: Configure QoS and Traffic Shaping
Section titled “Step 3: Configure QoS and Traffic Shaping”- Navigate to Security & SD-WAN > Configure > Traffic Shaping.
- Select the SSID or WAN uplink and enable traffic shaping for that interface.
- Click Create a new rule and select All VoIP & video conferencing. For SIPSTACK-specific traffic, create a custom rule using the IP blocks and ports from SIPSTACK Support.
- Configure the rule:
- Per-client bandwidth limit: Ignore SSID per-client limit (unlimited)
- Priority: High
- DSCP tag: 46 (EF — Expedited Forwarding)
- If using Meraki MS switches, navigate to Switches > Configure > Switch Settings > Quality of Service and add a QoS rule to trust incoming DSCP 46 tags for the Voice VLAN, mapping to CoS queue 3.
- Save all rules.
Step 4: Configure Firewall Rules
Section titled “Step 4: Configure Firewall Rules”- Navigate to Security & SD-WAN > Configure > Firewall.
- Add outbound Layer 3 rules to allow:
| Traffic Type | Protocol | Ports |
|---|---|---|
| SIP signaling | UDP | 5060–5061 |
| RTP media | UDP | 10000–65535 |
| HTTPS/Secure SIP | TCP | 443 |
| IPSec (for VPN-based VoIP) | UDP | 500, 4500 |
- Specify SIPSTACK’s IP blocks as the destination for SIP and RTP rules. Contact SIPSTACK Support for the current IP ranges.
- To prevent ghost or phantom calls, create rules that whitelist only SIPSTACK’s IP blocks for inbound SIP traffic on port 5060 and block all other sources.
- Disable load balancing for VoIP. If using dual WAN uplinks, set uplink preferences under Traffic Shaping to route SIPSTACK VoIP traffic over a single WAN connection.
- Disable ALG if needed. SIPSTACK’s Hosted PBX and Business SIP require proper NAT traversal. If recommended by SIPSTACK Support, disable Application Layer Gateway (ALG) under Security & SD-WAN > Configure > Firewall.
Step 5: Optimize Wi-Fi for VoIP (If Applicable)
Section titled “Step 5: Optimize Wi-Fi for VoIP (If Applicable)”For wireless VoIP devices such as the Switchboard app on smartphones or tablets:
- Ensure WMM (Wireless Multimedia) is enabled on Meraki MR access points under Wireless > Configure > Radio Settings.
- Navigate to Wireless > Configure > Firewall & Traffic Shaping, select the SSID used for SIPSTACK devices, and create a VoIP traffic shaping rule with DSCP 46 and unlimited per-client bandwidth.
- Ensure TCP 443, UDP 500, and UDP 4500 are allowed to support IPSec tunnels used by Wi-Fi calling and the Switchboard app.
Step 6: Monitor and Troubleshoot
Section titled “Step 6: Monitor and Troubleshoot”After configuration, use these tools to identify and resolve remaining quality issues:
Packet Captures: Navigate to Security & SD-WAN > Appliance Status > Packet Capture to capture VoIP traffic to SIPSTACK servers and analyze for packet loss, jitter, or latency.
VoIP Health (Meraki Insight): Enable VoIP Health monitoring under Network-Wide > Monitor > VoIP Health to measure call quality metrics to SIPSTACK servers.
Common issues:
| Issue | Likely Cause | Fix |
|---|---|---|
| Dropped calls | Circuit saturation or microbursts | Increase VoIP priority, reduce non-VoIP bandwidth limits |
| Choppy audio / jitter | VoIP not isolated or prioritized | Verify VLAN and QoS rules are applied correctly |
| One-way audio | NAT misconfiguration or ALG interference | Check NAT settings, disable ALG |
| Echo | High latency on VoIP path | Increase priority, verify WAN stability |
| Ghost / phantom calls | No IP whitelist on SIP port | Restrict inbound SIP to SIPSTACK IPs only |
Best Practices
Section titled “Best Practices”- Use a dedicated Voice VLAN to prevent VoIP traffic from competing with data.
- Whitelist SIPSTACK IP blocks in firewall and QoS rules for both security and performance.
- Avoid overcomplicating QoS on small networks with no reported issues and sufficient bandwidth.
- Re-run bandwidth tests periodically to ensure QoS limits still match actual WAN capacity.
- Use SIPSTACK’s secure provisioning for device configuration to reduce phantom call risk.