SIP/VoIP Registration Issues with Fortinet Firewalls
Fortinet FortiGate firewalls can interfere with SIP/VoIP traffic in several ways — most commonly through SIP ALG (Application Layer Gateway), overly aggressive IPS rules, or NAT misconfiguration. This guide walks through the standard troubleshooting sequence for phones that fail to register or drop calls behind a FortiGate.
Prerequisites: Administrative access to the FortiGate web UI or CLI, and basic familiarity with firewall policies.
Step 1: Verify Basic Network Connectivity
Section titled “Step 1: Verify Basic Network Connectivity”Before adjusting firewall settings, confirm the phones have valid network configuration:
- IP address, subnet mask, and default gateway are correct
- Phones can ping the default gateway
- DNS resolution is working
If basic connectivity is broken, fix that first before investigating SIP-specific issues.
Step 2: Disable SIP ALG
Section titled “Step 2: Disable SIP ALG”SIP ALG is the most common cause of registration and call quality issues on FortiGate. It intercepts and rewrites SIP packets in ways that break standard SIP behaviour.
Via web UI:
- Log in to the FortiGate web UI.
- Go to System > Feature Visibility and enable VoIP if not already enabled.
- Go to Security Profiles > VoIP Profiles.
- Edit the profile applied to your SIP traffic policy.
- Find the SIP settings and disable SIP ALG.
- Apply the profile to the firewall policy governing SIP traffic.
Via CLI (fastest method):
config system settings set default-voip-alg-mode kernel-helper-based set sip-helper disable set sip-nat-trace disableendAfter disabling SIP ALG, restart the phones and test registration.
Step 3: Review Firewall Policies
Section titled “Step 3: Review Firewall Policies”Confirm the firewall has an explicit allow policy for SIP traffic:
- Source: IP addresses or subnet of your VoIP phones
- Destination: SIPSTACK SIP proxy IP ranges (contact SIPSTACK support for the current list)
- Service: SIP (UDP/TCP 5060), SIP-TLS (TCP 5061), RTP/SRTP (UDP 10000–20000)
- Action: Accept
If no such policy exists, SIP traffic is likely being dropped by an implicit deny rule.
Step 4: Adjust IPS and Application Control
Section titled “Step 4: Adjust IPS and Application Control”Intrusion Prevention (IPS) and Application Control can block legitimate SIP traffic if signatures are too aggressive:
- Go to Security Profiles > Intrusion Prevention.
- Search for SIP-related signatures and verify they are set to Monitor (not Block) or create an exception for traffic to/from SIPSTACK’s proxy addresses.
- In Application Control, ensure SIP and VoIP applications are allowed for the relevant policy.
Step 5: Check NAT Configuration
Section titled “Step 5: Check NAT Configuration”SIP traffic must traverse NAT correctly for registration and two-way audio to work:
- Enable consistent NAT (also called endpoint-independent NAT or full-cone NAT) for SIP traffic
- Ensure the phone’s SIP contact header reflects the public WAN IP — phones behind NAT must send the WAN address, not the LAN address, in the SIP Contact and Via headers
- If phones are sending LAN addresses in SIP headers, configure STUN on the phones or use a SIP proxy that handles NAT traversal (SIPSTACK’s servers handle this automatically for provisioned phones)
Step 6: Capture and Review Logs
Section titled “Step 6: Capture and Review Logs”If registration still fails after the above steps:
- Go to Log & Report > Forward Traffic and filter for traffic to/from the SIP proxy IP addresses.
- Look for blocked or denied entries — note the policy and reason.
- Run a packet capture on the FortiGate interface to inspect the actual SIP traffic:
diagnose sniffer packet any "port 5060" 4Share the capture output with SIPSTACK support if you cannot identify the block reason.
Common Issues Quick Reference
Section titled “Common Issues Quick Reference”| Symptom | Most Likely Cause | Fix |
|---|---|---|
| Phone registers but no audio | RTP ports blocked | Open UDP 10000–20000 to SIPSTACK media servers |
| Phone registers intermittently | SIP ALG rewriting packets | Disable SIP ALG |
| Phone never registers | Firewall policy missing | Add explicit allow policy for SIP |
| One-way audio | NAT traversal issue | Verify consistent NAT, check SIP contact header |
| Calls drop after 30 seconds | SIP session timer not refreshed | Check IPS is not blocking SIP re-INVITE |
For further assistance, contact SIPSTACK support with your FortiGate model, firmware version, and a description of the registration failure.