How to disable SIP ALG on SonicWALL Firewalls.

How to disable SIP ALG on SonicWALL Firewalls.

Consistent NAT

  1. Click on VoIP
  2. Click on Settings
  3. Set Enable consistent NAT to enabled
  4. Every other checkbox on this page should be unchecked as well.
  5. Click Accept

Advanced Firewall Settings

  1. Click on Firewall Settings
  2. Click on Advanced
  3. Set Enable Stealth Mode and Randomize IP ID to disabled.
  4. Click Accept

Create Custom VoIP Services

  1. Under Network > Services click Add...
  2. Fill the popup as follows:
    • Name: VoIP RTP
    • Protocol: UDP
    • Port Range: 3000 - 65000
    • Sub Type: None
  3. Click Add
  4. Click on Service Groups > Add Group...
  5. Name: VOIP Services
  6. Add the following services to the right box
    1. SIP
    2. VoIP RTP
  7. Click Add

Create LAN > WAN Rule for Services

  1. Navigate to Firewall > Access Rules
  2. Click on Matrix
  3. Click on the arrow under LAN > WAN
  4. Click on Add...
    • Source Port: Any
    • Service: VOIP Services
    • Source: Any
    • Destination: Any 
    • Users Included: All
    • Users Excluded: None
    • Schedule: Always On
    • Comment: QoS for VoIP Phones
    • Enable Logging: True
    • Allow Fragmented Packets: True
  5.  Click on the Advanced tab
    • UDP Connection Inactivity Timeout (seconds): 90

Create Address Group for Voice Services

  1. Click Firewall > Address Objects > Add
  2. Fill out the following: 
  3. Add each IP Address for Voice Services as an Address Object
  4. Create an Address Groupand add the address objects that were created
    • Name: Voice Services

Excluding Voice Services IPs under Security Services (if applicable)

  1. Click Security Services 
  2. Check each Service and see if it is enabled
  3. If so, you need to enable the Exclusion List on each service and set it to Voice Services
  4. Example: Content Filter
  5. Once you exclude it, click Accept

    • Related Articles

    • Disable SIP ALG on Fortinet-Fortigate Firewalls

      By default, a new Fortinet Firewall has SIP ALG enabled, a protocol to help with the voice-over-IP systems. Most of the time, this protocol causes issues with many SIP service providers, so it is recommended to disable it. The process to do so is ...
    • SIP ALG Issues with VoIP and why it should be disabled

      SIP ALG should be disabled for Voiceware VoIP system. Please note that on many routers and firewalls SIP ALG is by default enabled. To find out if SIP ALG is disabled, please download the attached file for Windows. 1. Make sure the Windows machine is ...
    • Disable SIP ALG - Ubiquiti EdgeRouter

      Disabling SIP ALG for Ubiquiti EdgeRouter User Interface Log in to EdgeMax User Interface The router default is set to 192.168.1.1 The default username and password: ubnt (Your IT admin likely updated the login credentials and default gateway IP ...
    • Disable SIP ALG - Ubiquiti EdgeRouter

      1. Log in to EdgeMax User Interface 1. The router default is set to 192.168.1.1 2. The default username and password: ubnt (Your IT admin likely updated the login credentials and default gateway IP address) 2. Select System -> Conntrack -> Modules -> ...
    • Phone not registering after standard troubleshooting steps

      SIP phones communicate with our Registration Server (NDP) server using the UDP (User Datagram Protocol ) protocol. I have found that, in 2 different locations of one of our clients, the phones won't register with this standard type of protocol ...