Recommended Firewall Settings

Modified on Wed, May 9, 2018 at 9:24 AM


SIP ALG (Disable)

Although "Technological Geniuses" invented SIP ALG to help the "flow" of VoIP traffic, it is often implemented incorrectly on even high end routers/firewalls causing breaks in the signal stream which in turn, can cause many strange issues.  Therefore we recommend disabling SIP ALG.  


Constant NAT (Enable)

NAT is short for Network Address Translation.  Its purpose is to change one host IP address within one subnet to another IP address within a different subnet.  This translation is called one-to-one translation.  Some services including VoIP don't take too kindly to unexpected changes which is why we recommend enabling Constant NAT.


UDP Time Out (Extend to 120 seconds)

Extending UDP Timeout helps to ensure the potential gaps between device registration intervals are kept to a minimum.


Use a reliable DNS Server

DNS is the service responsible for converting FQDN's into IP's.  Most Internet Service Providers recommend using their DNS servers. However, this may not necessarily be the most reliable choice.  No DNS server can claim they have zero errors.  The trick is finding one that has the least amount of errors.  This is why we recommend setting Google's DNS (8.8.8.8) as your routers Primary DNS server.


Open RTP port range 1024 - 23000

RTP or Real Time Protocol will dynamically fall into any of these ports. 



Optional Settings

Firewall Whitelist IP's

The following IP addresses should be allowed full access to client networks.

Unity Client IM&P (TCP Port 2208)

masteraccess.com

im.unityclient.com

185.42.19.38


Device Registration Servers (TCP/UDP Ports 5060-5065)

199.168.177.13
199.168.177.14
199.168.179.167
199.168.181.13
199.168.181.14
199.168.182.167

Device Auto Provisioning Servers (TCP Ports 80 & 443)

199.168.176.165
199.168.180.165

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article