Skip to content

Optimizing VoIP Performance on Cisco Meraki MX Firewalls

← Network & Firewall

Optimizing VoIP Performance on Cisco Meraki MX Firewalls

Section titled “Optimizing VoIP Performance on Cisco Meraki MX Firewalls”

This guide covers Quality of Service (QoS) and network optimizations on Cisco Meraki MX firewalls to ensure high-quality VoIP performance with SIPSTACK. Following these steps reduces common issues such as dropped calls, choppy audio, jitter, echo, and one-way audio.

VoIP traffic is highly sensitive to latency, jitter, and packet loss. The Meraki MX provides robust tools to prioritize VoIP traffic and isolate it from competing network activity.

  • Admin access to the Meraki Dashboard
  • Access to the SIPSTACK Switchboard portal for configuration details
  • Knowledge of your WAN bandwidth (upstream and downstream)
  • A VLAN for VoIP traffic (recommended)
  • SIPSTACK-supported devices such as Polycom VVX, Yealink handsets, or the Switchboard app

Contact SIPSTACK Support for specific SIP server IP blocks and port details needed for firewall rules.

Accurate WAN bandwidth figures are needed for effective QoS configuration.

  1. Temporarily disable existing traffic shaping and firewall rules to avoid skewed results.
  2. Go to speedtest.net and run three consecutive tests outside business hours. Note the lowest upload and download speeds from the tests.
  3. In the Meraki Dashboard, navigate to Security & SD-WAN > Configure > Traffic Shaping. Click the Details link for your WAN uplink and enter speeds slightly below the lowest test results. For example, if tests show 100 Mbps down / 20 Mbps up, set 95 Mbps down / 18 Mbps up. This prevents the uplink from saturating and pushing VoIP packets into queues.

Segregating VoIP traffic into a dedicated VLAN isolates it from data traffic and simplifies QoS rules.

  1. Navigate to Security & SD-WAN > Configure > Addressing & VLANs.
  2. Enable VLANs if not already enabled.
  3. Add a new VLAN (e.g., VLAN 100, named “VOICE”) with a unique subnet (e.g., 192.168.100.0/24) and set the MX gateway IP (e.g., 192.168.100.1).
  4. For Meraki MS switches, configure access ports to advertise the Voice VLAN via LLDP or CDP. Navigate to Switches > Configure > Switch Ports, select the port, and set the Voice VLAN.
  5. If the MX handles inter-VLAN routing, ensure the Voice VLAN can reach SIPSTACK’s SIP servers without restriction.
  1. Navigate to Security & SD-WAN > Configure > Traffic Shaping.
  2. Select the SSID or WAN uplink and enable traffic shaping for that interface.
  3. Click Create a new rule and select All VoIP & video conferencing. For SIPSTACK-specific traffic, create a custom rule using the IP blocks and ports from SIPSTACK Support.
  4. Configure the rule:
    • Per-client bandwidth limit: Ignore SSID per-client limit (unlimited)
    • Priority: High
    • DSCP tag: 46 (EF — Expedited Forwarding)
  5. If using Meraki MS switches, navigate to Switches > Configure > Switch Settings > Quality of Service and add a QoS rule to trust incoming DSCP 46 tags for the Voice VLAN, mapping to CoS queue 3.
  6. Save all rules.
  1. Navigate to Security & SD-WAN > Configure > Firewall.
  2. Add outbound Layer 3 rules to allow:
Traffic TypeProtocolPorts
SIP signalingUDP5060–5061
RTP mediaUDP10000–65535
HTTPS/Secure SIPTCP443
IPSec (for VPN-based VoIP)UDP500, 4500
  1. Specify SIPSTACK’s IP blocks as the destination for SIP and RTP rules. Contact SIPSTACK Support for the current IP ranges.
  2. To prevent ghost or phantom calls, create rules that whitelist only SIPSTACK’s IP blocks for inbound SIP traffic on port 5060 and block all other sources.
  3. Disable load balancing for VoIP. If using dual WAN uplinks, set uplink preferences under Traffic Shaping to route SIPSTACK VoIP traffic over a single WAN connection.
  4. Disable ALG if needed. SIPSTACK’s Hosted PBX and Business SIP require proper NAT traversal. If recommended by SIPSTACK Support, disable Application Layer Gateway (ALG) under Security & SD-WAN > Configure > Firewall.

Step 5: Optimize Wi-Fi for VoIP (If Applicable)

Section titled “Step 5: Optimize Wi-Fi for VoIP (If Applicable)”

For wireless VoIP devices such as the Switchboard app on smartphones or tablets:

  1. Ensure WMM (Wireless Multimedia) is enabled on Meraki MR access points under Wireless > Configure > Radio Settings.
  2. Navigate to Wireless > Configure > Firewall & Traffic Shaping, select the SSID used for SIPSTACK devices, and create a VoIP traffic shaping rule with DSCP 46 and unlimited per-client bandwidth.
  3. Ensure TCP 443, UDP 500, and UDP 4500 are allowed to support IPSec tunnels used by Wi-Fi calling and the Switchboard app.

After configuration, use these tools to identify and resolve remaining quality issues:

Packet Captures: Navigate to Security & SD-WAN > Appliance Status > Packet Capture to capture VoIP traffic to SIPSTACK servers and analyze for packet loss, jitter, or latency.

VoIP Health (Meraki Insight): Enable VoIP Health monitoring under Network-Wide > Monitor > VoIP Health to measure call quality metrics to SIPSTACK servers.

Common issues:

IssueLikely CauseFix
Dropped callsCircuit saturation or microburstsIncrease VoIP priority, reduce non-VoIP bandwidth limits
Choppy audio / jitterVoIP not isolated or prioritizedVerify VLAN and QoS rules are applied correctly
One-way audioNAT misconfiguration or ALG interferenceCheck NAT settings, disable ALG
EchoHigh latency on VoIP pathIncrease priority, verify WAN stability
Ghost / phantom callsNo IP whitelist on SIP portRestrict inbound SIP to SIPSTACK IPs only
  • Use a dedicated Voice VLAN to prevent VoIP traffic from competing with data.
  • Whitelist SIPSTACK IP blocks in firewall and QoS rules for both security and performance.
  • Avoid overcomplicating QoS on small networks with no reported issues and sufficient bandwidth.
  • Re-run bandwidth tests periodically to ensure QoS limits still match actual WAN capacity.
  • Use SIPSTACK’s secure provisioning for device configuration to reduce phantom call risk.