This document provides configuration instructions for a Sonicwall firewall to support Galaxy UCX / InfinityOne communications.
Depending on your network configuration, there may be additional configuration steps required.
Step 1 – Port Forwarding Rules
SIP Port
Create a Port Forwarding rule of 5060-UDP for the incoming SIP Trunk.
Sonicwall is very aggressive about closing the 5060 port, if you use a SIP trunk then you will need this rule for inbound calls; outbound calls will work fine.
If you are using a non-standard port, change the rule accordingly. If you want tighter security, find out your IP Trunk Service Provder’s address range and restrict the incoming to that source.
RTP Ports
Create a Port Forwarding rule of 10000-39999-UDP for the incoming RTP.
If you want tighter security, find out your IP Trunk Service Provder’s address range and restrict the incoming to that source.
Step 2 – UDP Timeout
Set the UDP Timeout on your LAN->WAN Firewall Rule to 300 seconds – the default of 30 is too low.
Step 3 – NAT and SIP ALG
The user interface may be different for different versions of Sonicwall Firewall. Refer to the manufacturers manual to find the following parameters.
- Enable Consistent NAT.
- Disable SIP Transformations.