Recommended Router and Firewall Settings

Recommended Router and Firewall Settings

General Configuration

WARNING: It is recommended to consult your IT, MSP (Managed Service Provider), or another network professional when configuring advanced network settings or devices.

While resolving any network issues, we also recommend that Bandwidth Management/Traffic Shaping policies prioritizing VoIP traffic are configured and tested on your router/firewall.

Settings to Disable

  • SIP ALG (Application Layer Gateway) functions such as SIP Transformations, SIP Application Helpers, SIP Normalization, etc..
  • SPI (Stateful Packet Inspection)
  • AV Client Enforcement on any IP assigned to a phone
  • Content Filtering on any IP assigned to a phone

Settings to Enable

  • Bandwidth Management/Traffic Shaping (See below for a list of our network blocks and bandwidth requirements)
  • Default UDP session timeout to 300 seconds
  • Consistent NAT (Sonicwall)
  • Load balancing policy configured for ingress and egress of phones on same WAN interface only. (If applicable)
  • Inbound and outbound traffic on ports and subnets listed below
  • DNS resolution for the phones

Subnet and Port Configuration


Ports - Primecall Platform

  • 5060-5062 UDP - SIP
  • 20,000-40,000 UDP - RTP
  • 80, 443 TCP - HTTP/HTTPS

DHCP VLAN Option

Option 132: Set Voice VLAN ID

  • This only works for yealink brand phones and needs to be made as a custom option on the DHCP Server.
  • Type = String (ASCII)
  • Value = 'VLANTAG' for example '20' for VLAN 20
  • This DHCP option should be applied to your native DHCP sever so that the phones receive the configuration when first plugged in. 
    • It may also be applied to the voice VLAN, but is not required.

Bandwidth Requirements

Voice-only applications utilize G.711 U-Law as the primary codec and require 87.2 Kbps of bandwidth per active call. We've found a good rule of thumb is to round the requirement up to 100Kbps to account for signaling and overhead. 

For example…

A 10Mbps/1Mbps ISP connection that is solely dedicated to the phones would support 10 concurrent phone calls.

router settingsconsistent natsip algsettingsconfigurefirewall settings

    • Related Articles

    • Recommended Router and Firewall Settings

      General Configuration WARNING: It is recommended to consult your IT, MSP (Managed Service Provider), or another network professional when configuring advanced network settings or devices. While resolving any network issues, we also recommend that ...
    • Recommended Router and Firewall Settings

      General Configuration WARNING: It is recommended to consult your IT, MSP (Managed Service Provider), or another network professional when configuring advanced network settings or devices. While resolving any network issues, we also recommend that ...
    • Recommended Router and Firewall Settings

      General Configuration WARNING: It is recommended to consult your IT, MSP (Managed Service Provider), or another network professional when configuring advanced network settings or devices. While resolving any network issues, we also recommend that ...
    • Recommended Unifi Firewall Settings

      Configure Your Unifi Firewall for VoIP WARNING: Configuring the settings of your USG may result in a restart. It is recommended to perform these changes in your after hours. Create a Smart Queue A Smart Queue option is available with UniFi Security ...
    • Recommended Unifi Firewall Settings

      Configure Your Unifi Firewall for VoIP WARNING: Configuring the settings of your USG may result in a restart. It is recommended to perform these changes in your after hours. Create a Smart Queue A Smart Queue option is available with UniFi Security ...