Skip to content
Business IT Services, Support Melbourne
  • IT Services
    • Managed IT Services
    • Cloud Services
    • Microsoft 365 Managed Service
    • IT Consulting Services
    • Remote IT Support
    • Business Communication
      • Get started with 3CX
  • Industries
    • Accounting Firms
    • Law Firms
    • Realestate
    • Medical Centres
    • Pharmacies
    • Conveyancing Firms
  • Cybersecurity
    • SaaS Security
    • Assessment
    • The Essential Eight
      • Quick Assessment
    • Playbooks
    • Computer Security Threats
  • Remote IT Support
    • TeamViewer Windows
    • TeamViewer Mac
    • TeamViewer Linux
Get in Touch

Windows

23
  • Command and PowerShell History
  • How to increase the disk size of VM in VirtualBox
  • Saved Windows Credentials
  • View installed software using wmic
  • How to Disable Revocation Check for SSTP VPN
  • Enabling Group Policy editor on Windows 10 Home
  • Source file names are larger than supported file system
  • How to change file creation or modified date
  • Another account from your organisation is already signed in
  • How to check if Microsoft Defender for Endpoint is running
  • Disabling Office 365 Autodiscover – Exchange Self hosted
  • Access to Removable Drives not Protected by BitLocker
  • The Group Policy settings for BitLocker startup options are in conflict and cannot be applied
  • How do you extend a User Profile Disk
  • Resizing User Virtual Disk RDP (Esxi VM)
  • Essential Network Ports for Windows Services
  • Why does OneDrive keep duplicating files
  • Troubleshooting USB devices
  • Download Maps Manager Delayed Start Red in Server 2016
  • Pros and cons working with DNS, DHCP, IPAM, Wireless, LAN, WAN
  • What is a DHCP Servers and DHCP relays
  • How to find user profile disk from registry
  • Understanding Multi-Factor Authentication
Linux

Linux

8
  • Rsync linux
  • CSF Shell Command
  • mysql-8.0-gpg package error
  • Linux Exim Cheat sheet
  • csf configserv commands
  • Nmap cheat sheet
  • nmap
  • Windows Privilege Escalation

Networking

4
  • Cannot access FortiGate web GUI admin interface
  • How to find Fortinet PSK
  • Pros and cons working with DNS, DHCP, IPAM, Wireless, LAN, WAN
  • Disabling SIP ALG on FortiGate Firewall

General IT Support

12
  • TPM has malfunction error 80090016 keyset does not exist
  • Command and PowerShell History
  • How to increase the disk size of VM in VirtualBox
  • Saved Windows Credentials
  • View installed software using wmic
  • How to improve the WIFI coverage in the office
  • Best Practices for Data Backup and Recovery
  • How to change file creation or modified date
  • How to sync a SharePoint site with OneDrive
  • Cannot access FortiGate web GUI admin interface
  • Pros and cons working with DNS, DHCP, IPAM, Wireless, LAN, WAN
  • What is a DHCP Servers and DHCP relays

Network Connectivity

4
  • How to improve the WIFI coverage in the office
  • Common Internet connectivity problems and solutions
  • What is SSTP VPN?
  • Enabling iPhone hotspot

Cyber Security & Compliance

3
  • How to check if Microsoft Defender for Endpoint is running
  • The Group Policy settings for BitLocker startup options are in conflict and cannot be applied
  • Windows Privilege Escalation

Remote IT Support & Helpdesk

5
  • Atera client not showing up in Customer’s dashboard
  • The Group Policy settings for BitLocker startup options are in conflict and cannot be applied
  • How do you extend a User Profile Disk
  • Resizing User Virtual Disk RDP (Esxi VM)
  • mysql-8.0-gpg package error
View Categories
  • Home
  • kb
  • Networking
  • Disabling SIP ALG on FortiGate Firewall

Disabling SIP ALG on FortiGate Firewall

1 min read

Disabling SIP ALG #

SIP ALG can have a significant impact on VoIP phone systems by interfering with the smooth transmission of voice data. This feature, designed to modify and manage SIP packets, often causes more harm than good in VoIP environments. For many businesses, SIP ALG results in connection issues like dropped calls, delays, one-way audio, or failed call registration. These disruptions occur because SIP ALG alters the packets in ways that can confuse VoIP traffic, leading to degraded call quality. To ensure reliable and clear communication, many VoIP providers recommend disabling SIP ALG, especially in networks with heavy VoIP usage. Understanding and adjusting SIP ALG settings can be crucial to maintaining high-quality VoIP performance for your business.

How to disabled SIP ALG on FortiGate firewall router #

On FortiGate firewalls SIP Application Layer Gateway (SIP ALG) is enabled by default. This will cause problems with SIP VoIP phones registration and call processing.

Access the FortiGate CLI:

  • Log into the FortiGate device and open the CLI (either through SSH or directly via the console).

Note: Backup configuration of your firewall before making any changes

Step 1: #

FortiOS starting at software release 6.2.2 : Run following commands from FortiGate firewall CLI

  1. config system settings
  2. set sip-expectation disable
  3. set sip-nat-trace disable
  4. set default-voip-alg-mode kernel-helper-based
  5. end

FortiOS older than software release 6.2.2 : Run following commands from FortiGate firewall CLI #

  1. config system settings
  2. set sip-helper disable
  3. set sip-nat-trace disable
  4. set default-voip-alg-mode kernel-helper-based
  5. end

If you see an error while entering “set default-voip-alg-mode kernel-helper-based” , just ignore it.

Rest of configuration is the same for all FortiOS versions

Step 2: #

Next we need to locate SIP entry in session helper list and delete it

  1. config system session-helper
  2. show

Scroll down until you see an entry for SIP, in our example it was number 13 but this may be different depending on model and software release. Now execute following commands:

  1. delete 13
  2. end

Step 3: #

Disable the VoIP Profile . The last set of commands disables processing of RTP protocol on the firewall.

  1. config voip profile
  2. edit default
  3. config sip
  4. set rtp disable
  5. end
  6. end

Normally FortiGate firewalls do not require a reboot when you change configuration, but , it seems, in this case we need reboot it to activate session helper changes.

Step 4: #

Last step – restart or power cycle all your SIP phones and devices.

Share This Article :
  • Facebook
  • X
  • LinkedIn
  • Pinterest
Pros and cons working with DNS, DHCP, IPAM, Wireless, LAN, WAN
Table of Contents
  • Disabling SIP ALG
  • How to disabled SIP ALG on FortiGate firewall router
  • Step 1:
  • FortiOS older than software release 6.2.2 : Run following commands from FortiGate firewall CLI
  • Step 2:
  • Step 3:
  • Step 4:
Melbourne business IT logo

Melbits is Melbourne Business IT Service and technology solutions provider. Our tailored and strategic approach ensures that your business will receive expert IT support, cybersecurity and consulting that aligns with your business needs, empowering your business, driving growth and success.

You can reach us at 03 9069 6788

IT Services

  • Managed IT Services
  • Cloud Services
  • Cybersecurity
  • Remote IT Services
  • Business Communication
  • IT Consulting

Industries

  • Accounting Firms
  • Law Firms
  • Realestate
  • Medical Centres
  • Pharmacies
  • Conveyancing Firms

Additional Links

  • About Us
  • Knowledge Base
  • Case Studies
  • Blog
  • Contact
  • FAQ

© 2025 Melbit Services, All Rights Reserved.

  • Terms and Conditions
  • Privacy Policy