US English (US)
CA French (Canada)

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below using as much detail as possible so that our team can best assist you.

  • Home
  • Contact Us
  • Employee Log In
  • Getting Started
  • Using Your SpectrumVoIP Services
  • Working Remotely
  • Frequently Asked Questions
  • Troubleshooting
  • Training Resources
English (US)
US English (US)
CA French (Canada)
  • Home
  • Frequently Asked Questions
  • Common Equipment and Feature Questions
  • Network Setup Help
  • Router and Firewall Settings

Recommended Fortinet Firewall Settings

Learn how to optimize your Fortinet firewall settings to work alongside VoIP services.

Written by Adrian Angwenyi

Updated at April 14th, 2025

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request. We’ll reach back to you via email as soon as possible.

Please fill out the contact form below using as much detail as possible so that our team can best assist you.

After clicking 'Submit Ticket' you wil receive an email confirmation that your ticket has reached a member of our support team. They will reply back to continue to supporting, or you can call in referencing the ticket number on the email. (469) 429-2500

  • Getting Started
    Policies Preparing to Use VoIP Services Billing Basics Register an SMS Campaign Connect Your Device Using Your Phones Web Portals
  • Using Your SpectrumVoIP Services
    Customer Announcements Basic Phone Use The Stratus Platform The Enswitch Platforms SMS Messaging Use Your Fax Service Manage Your Network Equipment
  • Working Remotely
    Relocate Your Phone Use Your Phone Remotely Stratus Working Remotely Enswitch Working Remotely
  • Frequently Asked Questions
    Getting Help Common Equipment and Feature Questions SMS Campaign Registry Billing and Accounting Questions LNP / Porting Telephone Numbers
  • Troubleshooting
    Common VoIP Issues and Solutions Fax Problems Phone Problems Share Your Screen
  • Training Resources
    Web Portal User Guides Phone Video Tutorials Phone Guides Fax Guides Stratus Mobile App Guides ES Mobile App Guides StratusHUB Guides ES Desktop App Guides
+ More

Table of Contents

From the Command Line Interface Step 1: Remove SIP Helper Step 2: Disable SIP Helper and SIP NAT Trace Step 3: Disable Strict Register From the GUI / UX Step 1: Enable Traffic Shaping Step 2: Create a VoIP Traffic Shaper Step 3: Add Addresses, Services, and Address Groups Addresses Address Group Services/Ports Port Ranges for Services Step 4: Create an IPv4 Policy Step 5: Set REGISTER, INVITE, and SCCP Request Limits Step 6: Create a Traffic Shaping Policy Optional Step 7: SD-WAN Deployment Note: Warning:

From the Command Line Interface

WARNING: Please pay particular attention to spaces and dashes in the CLI based steps, or you may receive error warnings.

 

Step 1: Remove SIP Helper

  1. In the Command Line Interface (CLI) run the following commands:
    • config system session-helper
    • show
  2. For this example, edit 13 contains SIP

    WARNING: Depending on your deployment sip may be a different number, please substitute the correct entry number for the delete command.

     
     
  3. Enter the following commands:
    • delete 13
    • end

 

Step 2: Disable SIP Helper and SIP NAT Trace

In the Command Line Interface (CLI) run the following commands:

  • config system settings
  • set default-voip-alg-mode kernel-helper-based
  • set sip-nat-trace disable
  • end

✔ Reboot the Router while using the Web GUI under Status, or in the CLI with the following command:

execute reboot
 

 

Step 3: Disable Strict Register

Strict Register forces VoIP devices through a pinhole at port 65476 and will cause duplicate porting to occur.

To disable this setting, run the following commands in the Command Line Interface (CLI):

  • config voip profile
  • edit <Profile_name>
  • config sip
  • set strict-register disable
  • set invite-rate 300
  • set register-rate 300
  • end

 


From the GUI / UX

Step 1: Enable Traffic Shaping

  1. Navigate to System → Feature Visibility.
  2. In the Additional Features column, enable Traffic Shaping and VoIP.
  3. Click the Apply button to save these changes.

 

Step 2: Create a VoIP Traffic Shaper

  1. Navigate to Policy & Objects → Traffic Shaping → Traffic Shapers.
  2. Click the + Create New button.
  3. Fill in the following information:
    • Name - Type a name, such as SVoIP RTP Out.
    • Traffic priority - High, this will decrease the chance the traffic gets dropped during times of heavy network load
    • Maximum Bandwidth - In general this not needed in connections faster than 100 mbps
    • Guaranteed Bandwidth - Allocate at least 1000 kbps.
  4. Click the OK button to create this traffic shaper.

Note:

A 10Mbps/1Mbps ISP connection that is solely dedicated to the phones would support 10 concurrent phone calls. Please adjust the Guaranteed Bandwidth depending on your ISP speeds and the needs for phone calls.

 

 

Step 3: Add Addresses, Services, and Address Groups

Addresses

  1. Navigate to Policy & Objects → Addresses.
  2. Reference this table to see the addresses that should be added.

    Note: Here are the public subnets associated with our services:

    199.71.209.0/24

    24.227.249.0/25

    72.249.136.32/28

    206.123.122.32/27

    212.69.157.32/27

    40.143.31.64/27

    45.41.5.0/24

    12.150.91.0/24

     
  1. Click the + Create new button.
  2. Fill in the following information:
    • Name - Type a descriptive name about this address.
    • Type - Select Subnet.
    • IP/Netmask - Type the address you need from step 2. 
  1. Click the OK button.
  2. Repeat steps 2-5 for each address/port.

 

Address Group

  1. Navigate to Policy & Objects → Addresses and go to the Address Group tab.
  2. Click the + Create New button.
  3. In the New Address Group menu, fill in the following information:

    • Name - Type a descriptive name, such as “SpectrumVoIPServices”.
    • Type - Click Group.
    • Members - Click the + icon and select the SpectrumVoIP Address Objects that were created.
  4. Once you have selected all of the addresses look for the Close button at the bottom of the Select Entries.
  5. Click the OK button.

 

Services/Ports

  1. Navigate to Policy & Objects → Services.
  2. Click the + Create new button.

     
  3. In the New Service menu, fill in the following information:
    • Name - Type a descriptive name.
    • Category - Select VoIP, Messaging & Other Applications.
    • Protocol Type - Select TCP/UDP/SCTP.
    • Address - Click IP Range and type in the subnet of one of the addresses from the Address section.
    • Destination Port - For this option, do the following:
      • Select the appropriate port type, such as UDP.
      • Set the port range to match what is used by your platform.

        Port Ranges for Services

        Stratus Ports

        Main Utilized Ports

            •  5060-5062 UDP - SIP
            •  20,000-40,000 UDP - RTP
            •  80, 443 TCP - HTTP/HTTPS

        Portal Dynamic Updates

            •  8001 - TCP

        Text-to-Speech Services - TCP and UDP

            •  35.175.185.150:3001
            •  35.175.185.150:8000
            •  44.212.88.215:8000
            •  54.149.243.27:3001
            •  54.149.243.27:8000
            •  54.70.235.134:3001
            •  54.70.235.134:8000

        StratusMEETING - TCP and UDP

            •  54.188.133.147:3443
            •  3.130.158.184:3443
            •  35.183.150.146:3443

        StratusWEB PHONE

            •  9002 - TCP - websockets

         

        ES1 and ES2 Platform Ports

            •  5060-5062 UDP - SIP
            •  10,000-20,000 UDP - RTP
            •  80, 443 TCP - HTTP/HTTPS

         

        Push Notifications Ports

        Google's Firebase Cloud Messaging (FCM)

            •  443, 5228, 5229, 5230 - TCP

        Apple's Push Notification Service (APNs)

            •  5223, 443, 2197 - TCP

        More Info: Port 5223 is the primary port for communication with APNs. Ports 443 and 2197 are used for sending notifications from MDM to APNs and as a fallback on Wi-Fi if 5223 can't be reached.

         
         
         
  4. Click the OK button when ready. 

 

Step 4: Create an IPv4 Policy

  1. Navigate to Policy & Objects → IPv4 Policy.
  2. Click the + Create New button.
  3. Fill in the following information:

    Important:

    It is highly recommended for security purposes that you have a separate subnet for the phones and make this firewall policy as specific as possible.

     
    • Name - Type a descriptive name, such as LAN to SVoIP.
    • Incoming Interface - Select your LAN (Or Voice VLAN) interface.
    • Outgoing Interface - Select your WAN interface.
    • Action - Select ✔ ACCEPT.
    • Source - LAN addresses (Or Voice VLAN addresses)
    • Destination - The SpectrumVoIP Address Group Create previously
    • Schedule - Always
    • Service - SVoIP RTP Out, HTTP, & HTTPS
    • Inspection mode - Flow Based
    • NAT - ENABLE NAT
    • IP Pool Configuration - Select Use Outgoing Interface Address.
    • Preserve Source Port - DISABLE
    • Passive health check - DISABLE
    • AntiVirus - DISABLE
    • Web Filter - DISABLE
    • DNS Filter - DISABLE
    • Application Control - DISABLE
    • VoIP - ENABLE DEFAULT
    • SSL inspection - SET TO NO INSPECTION
    • Log Allowed Traffic - Select All Sessions.  
  4. Click the OK button.
  5. Ensure the policy is active or turn it on once you apply the settings.

Warning:

To ensure the phones are able to provision, please ensure the Inspection mode is set to Flow-based and the SSL inspection is set to Certificate Inspection.

 

Step 5: Set REGISTER, INVITE, and SCCP Request Limits

  1. Navigate to Security Policies → VoIP. 
  2. Set the Limit “REGISTER” requests and Limit “INVITE” requests option to the value specified by your installation technician.

    Quick Tip: 300 can be used if the exact value is not known.

     
  3. If necessary, set the SCCP limit as well. 

Note:

In the vast majority of cases, SCCP can be left at 0. Please consult your network administrator for this particular setting.

 

 

Step 6: Create a Traffic Shaping Policy

  1. Navigate to Policy & Objects → Traffic Shaping Policy. 
  2. Click the + Create New button.
  3. In the menu, fill in the following information:

    WARNING: Pay careful attention to the SIP and VOIP selections as they may be in different locations depending on the age, and firmware version of your Fortinet.

    Ensure you select the name of the Policy / Traffic Shaper you created earlier.

     
    • Service - Select select the Service we created earlier for the RTP.
    • Application - Select SIP.
    • Outgoing Interface - Select your internet interface.
    • Shared Shaper - Select the new Traffic Shaper you created earlier.
    • Reverse Shaper - Select the new Traffic Shaper you created earlier.
  4. Click the OK button.

Optional Step 7: SD-WAN Deployment

Note:

To prevent issues with provisioning, it is highly recommended to send SD-WAN traffic out one interface.

 
  1. Navigate to Network → SD-WAN → SD-WAN Rules
  2. Create a new rule with the following parameters:

Warning:

There are many metrics that can be used to determine which ISP to send traffic out of, some common ones are jitter, latency, and packet loss. When manually setting the ISP for VoIP traffic, it will not load balance or fail-over to the secondary ISP. This will not affect other internet traffic.

 

 


✔ Congratulations! You have completed the pre-engagement setup.

If you have issues or questions with the configurations described above, a good first point of contact is to call our SpectrumVoIP technical support team at (469) 429-2500. Another excellent option is to call Fortinet at (844) 459-2514 or (866) 648-4638. 

Please be aware that your device must have an active Maintenance and Support Agreement in effect for Fortinet's services.

 

optimal configurations fortinet firewall fortigate firewall settings voip set up network prepare for voip voip settings network settings

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Recommended Sonicwall Firewall Settings
  • Customer Stories
  • Hardware
  • Channel Partners
  • Pricing
  • Blog
  • Contact Us

Main Products

  • Business Phone Software
  • VoIP Features
  • VoIP Integrations
  • Stratus Managed Network
  • AI Business Surveillance
  • Internet

More Products

  • Stratus Web Portal
  • Stratus Fax
  • Emergency Lines
  • Business Texting
  • Business Cellular
  • Business Phone Hardware

Resources

  • About Us
  • FAQ
  • Careers
  • Support
  • Training
  • SpectrumVoIP Store

Connect

  • Facebook Fill 1 Created with Sketch.
  • Twitter Fill 1 Created with Sketch.
  • LinkedIn Group 2 Created with Sketch.
  • YouTube
  • Instagram
  • Pinterest

SpectrumVoIP Status

© SpectrumVoIP™ 2022. All Rights Reserved


Knowledge Base Software powered by Helpjuice

Main — (972) 312-0388 Sales — 866-506-3457 Support — (469) 429-2500 Terms of Service Privacy Policy
Expand