Open the CLI interface for your Fortigate Firewall
Before making any changes be sure to backup your configuration
In the CLI enter the following commands
Use the following commands for a device on FortiOS starting at 6.2.2
config system settingsset sip-expectation disableset sip-nat-trace disableset default-voip-alg-mode kernel-helper-basedend
For devices below FortiOS version 6.2.2use the following commands
config system settingsset sip-helper disableset sip-nat-trace disableset default-voip-alg-mode kernel-helper-basedend
β
If you encounter and error while entering
set default-voip-alg-mode kernel-helper-basedgo ahead and ignore itThe rest of the configuration will be the same for all FortiOS versions
Run the following commands
config system session-helpershowHere you will want to find the entry for SIP, this is typically 12 but it may differ depending on software version and model
delete 12Alternatively use the entry you found in the previous step
end
Enter the following commands in the CLI to disable RTP processing
config voip profileedit defaultconfig sipset rtp disableendend
Once done go ahead and reboot the device, Fortigate firewalls do not require a reboot when you change configuration but in this case, we will need the reboot to activate the session helper changes
Lastly, reboot all of your SIP Devices/Phones
FORTIGATE SIP ALG Disable
S
Written by Support
Updated over 8 months ago