Overview
This guide covers WatchGuard firewalls for SIP-based VoIP.
The main thing with WatchGuard is avoiding SIP proxy policies — packet filters are usually the better option.
Before you start
- Access to Firebox (Web UI or Policy Manager)
- SIP provider details
Ports used by VoIP
- SIP: 5060
- RTP: 10000–20000 UDP
Configuration
1. Remove SIP Proxy
If present:
- Go to Firewall Policies
- Remove SIP proxy policy
2. Create packet filter policies
Add policies for:
- SIP (UDP 5060)
- RTP range
Allow:
- Trusted → External
3. NAT settings
Ensure outbound NAT is working normally.
For hosted VoIP:
- No inbound NAT usually required
4. QoS / Traffic Management
Enable:
- Traffic management
Prioritise:
- RTP traffic
Good practice
- Avoid mixing proxy + packet filters
- Keep rules simple
- Monitor logs during testing
Troubleshooting
One-way audio
Check:
- RTP policy
- NAT behaviour
Calls fail or drop
Check:
- SIP proxy fully removed
- Firewall rules
Registration issues
Check:
- Access rules
- WAN connectivity
Quality issues
Check:
- Traffic prioritisation
- WAN usage
