Administration

Configure Sonicwall Firewall for Galaxy UCX

This document provides configuration instructions for a Sonicwall firewall to support Galaxy UCX / InfinityOne communications.

Depending on your network configuration, there may be additional configuration steps required.  

Step 1 – Port Forwarding Rules

SIP Port

Create a Port Forwarding rule of 5060-UDP for the incoming SIP Trunk.

Sonicwall is very aggressive about closing the 5060 port, if you use a SIP trunk then you will need this rule for inbound calls; outbound calls will work fine.

If you are using a non-standard port, change the rule accordingly. If you want tighter security, find out your IP Trunk Service Provder’s address range and restrict the incoming to that source.

RTP Ports

Create a Port Forwarding rule of 10000-39999-UDP for the incoming RTP.

If you want tighter security, find out your IP Trunk Service Provder’s address range and restrict the incoming to that source.

Step 2 – UDP Timeout

Set the UDP Timeout on your LAN->WAN Firewall Rule to 300 seconds – the default of 30 is too low.

Step 3 – NAT and SIP ALG

The user interface may be different for different versions of Sonicwall Firewall. Refer to the manufacturers manual to find the following parameters.

  • Enable Consistent NAT.
  • Disable SIP Transformations.

 

Contents