WatchGuard XTM – VoIP Configuration

Learn how to configure VoIP on WatchGuard XTM for optimal performance and security in your network communications.

Overview

This guide covers WatchGuard firewalls for SIP-based VoIP.

The main thing with WatchGuard is avoiding SIP proxy policies — packet filters are usually the better option.

 

Before you start

  • Access to Firebox (Web UI or Policy Manager)
  • SIP provider details

 

Ports used by VoIP

  • SIP: 5060
  • RTP: 10000–20000 UDP

 

Configuration

1. Remove SIP Proxy

If present:

  • Go to Firewall Policies
  • Remove SIP proxy policy

 

2. Create packet filter policies

Add policies for:

  • SIP (UDP 5060)
  • RTP range

Allow:

  • Trusted → External

 

3. NAT settings

Ensure outbound NAT is working normally.

For hosted VoIP:

  • No inbound NAT usually required

 

4. QoS / Traffic Management

Enable:

  • Traffic management

Prioritise:

  • RTP traffic

 

Good practice

  • Avoid mixing proxy + packet filters
  • Keep rules simple
  • Monitor logs during testing

 

Troubleshooting

 

One-way audio

Check:

  • RTP policy
  • NAT behaviour

 

Calls fail or drop

Check:

  • SIP proxy fully removed
  • Firewall rules

 

Registration issues

Check:

  • Access rules
  • WAN connectivity

 

Quality issues

Check:

  • Traffic prioritisation
  • WAN usage