Skip to content

SIP/VoIP Registration Issues with Fortinet Firewalls

← Troubleshooting

Fortinet FortiGate firewalls can interfere with SIP/VoIP traffic in several ways — most commonly through SIP ALG (Application Layer Gateway), overly aggressive IPS rules, or NAT misconfiguration. This guide walks through the standard troubleshooting sequence for phones that fail to register or drop calls behind a FortiGate.

Prerequisites: Administrative access to the FortiGate web UI or CLI, and basic familiarity with firewall policies.

Before adjusting firewall settings, confirm the phones have valid network configuration:

  • IP address, subnet mask, and default gateway are correct
  • Phones can ping the default gateway
  • DNS resolution is working

If basic connectivity is broken, fix that first before investigating SIP-specific issues.

SIP ALG is the most common cause of registration and call quality issues on FortiGate. It intercepts and rewrites SIP packets in ways that break standard SIP behaviour.

Via web UI:

  1. Log in to the FortiGate web UI.
  2. Go to System > Feature Visibility and enable VoIP if not already enabled.
  3. Go to Security Profiles > VoIP Profiles.
  4. Edit the profile applied to your SIP traffic policy.
  5. Find the SIP settings and disable SIP ALG.
  6. Apply the profile to the firewall policy governing SIP traffic.

Via CLI (fastest method):

Terminal window
config system settings
set default-voip-alg-mode kernel-helper-based
set sip-helper disable
set sip-nat-trace disable
end

After disabling SIP ALG, restart the phones and test registration.

Confirm the firewall has an explicit allow policy for SIP traffic:

  • Source: IP addresses or subnet of your VoIP phones
  • Destination: SIPSTACK SIP proxy IP ranges (contact SIPSTACK support for the current list)
  • Service: SIP (UDP/TCP 5060), SIP-TLS (TCP 5061), RTP/SRTP (UDP 10000–20000)
  • Action: Accept

If no such policy exists, SIP traffic is likely being dropped by an implicit deny rule.

Step 4: Adjust IPS and Application Control

Section titled “Step 4: Adjust IPS and Application Control”

Intrusion Prevention (IPS) and Application Control can block legitimate SIP traffic if signatures are too aggressive:

  1. Go to Security Profiles > Intrusion Prevention.
  2. Search for SIP-related signatures and verify they are set to Monitor (not Block) or create an exception for traffic to/from SIPSTACK’s proxy addresses.
  3. In Application Control, ensure SIP and VoIP applications are allowed for the relevant policy.

SIP traffic must traverse NAT correctly for registration and two-way audio to work:

  • Enable consistent NAT (also called endpoint-independent NAT or full-cone NAT) for SIP traffic
  • Ensure the phone’s SIP contact header reflects the public WAN IP — phones behind NAT must send the WAN address, not the LAN address, in the SIP Contact and Via headers
  • If phones are sending LAN addresses in SIP headers, configure STUN on the phones or use a SIP proxy that handles NAT traversal (SIPSTACK’s servers handle this automatically for provisioned phones)

If registration still fails after the above steps:

  1. Go to Log & Report > Forward Traffic and filter for traffic to/from the SIP proxy IP addresses.
  2. Look for blocked or denied entries — note the policy and reason.
  3. Run a packet capture on the FortiGate interface to inspect the actual SIP traffic:
Terminal window
diagnose sniffer packet any "port 5060" 4

Share the capture output with SIPSTACK support if you cannot identify the block reason.

SymptomMost Likely CauseFix
Phone registers but no audioRTP ports blockedOpen UDP 10000–20000 to SIPSTACK media servers
Phone registers intermittentlySIP ALG rewriting packetsDisable SIP ALG
Phone never registersFirewall policy missingAdd explicit allow policy for SIP
One-way audioNAT traversal issueVerify consistent NAT, check SIP contact header
Calls drop after 30 secondsSIP session timer not refreshedCheck IPS is not blocking SIP re-INVITE

For further assistance, contact SIPSTACK support with your FortiGate model, firmware version, and a description of the registration failure.