Help Center / Smarter Voice / Devices / Troubleshoot a device network

Devices

Troubleshoot a device network in Smarter Voice

Here’s a sample rule set you can provide to your IT team:

On this page

NAT / SIP ALG

  • Disabling SIP ALG is generally the first resolution for device issues - make sure to check this item on your network devices before troubleshooting further

  • Disable SIP ALG or other protocol-interfering features (many break VoIP).

  • Ensure your NAT is enabled on only one device

Outbound Rules

  • Allow TCP/UDP outbound to your VoIP provider’s service IP range (or hostname) on the ports in Section 2.

  • Allow UDP outbound from your network to service IP range on ephemeral ports (e.g., 10,000-65,535).

Inbound / Return Traffic

  • Ensure your firewall/NAT allows return traffic to the original internal source port (ephemeral) when initiated from the service endpoint.

  • Use “Allow established/related” rules rather than opening wide inbound access.

Ephemeral Ports & Media

When your softphone registers and then places or receives a call, the media (audio, video) and sometimes fallback signaling use ephemeral (temporary) ports chosen by your operating system or device. For smooth operation:

  • Allow outbound UDP from your LAN to the service’s media server IPs on the full ephemeral port range (commonly 10,000-65,535 or OS default).

  • Allow return traffic into those ephemeral ports — most firewalls allow “established/related” traffic automatically and consider it best practice.

  • Example: Your softphone picks source port 53,421 for RTP; traffic should be allowed from service endpoint back to 53,421.

Important: The ports listed in Section 2 are the destination/listening ports. Your softphone’s source port will be ephemeral and not in that list—so firewall rules must account for that.

Required Port Destinations (Inbound/Outbound)

Please ensure that your network firewall/NAT allows traffic to the following destination ports — both TCP and UDP, as indicated:

ProtocolPort(s)Purpose
TCP80HTTP registration / service communication
TCP443HTTPS / secure WebRTC signaling
TCP/UDP5000Alternate registration or proprietary signaling
TCP/UDP5060-5065SIP signaling (non-TLS) / fallback SIP ports
TCP/UDP5443Secure signaling port
TCP/UDP5555Additional signaling / management port
TCP/UDP7000Media or backup signaling path
TCP/UDP7078-7079Backup media/data path
TCP/UDP8443Secure WebRTC / HTTPS media fallback
TCP/UDP9078-9079Additional media/data fallback ports

Example: Outbound from your softphone → server at port 5060 (UDP)

Inbound/outbound return traffic will flow once allowed.

Troubleshooting Tips

  • If registration fails, check that destination signaling ports are allowed and reachable.

  • If you get one-way audio or no audio: likely your media ports or return traffic are blocked—verify ephemeral UDP is allowed and SIP ALG is disabled.

  • If calls drop mid-call, check NAT timeouts and that mappings remain active for media, and SIP ALG is disabled.