WatchGuard Set up for VOIP

Keep in mind different firmware versions will interact with hosted VoIP services in different ways. While this device may be fully functional on the tested and/or current firmware version, it is possible newer revisions will cause disruptions in service or make a device fully compliant with the required settings for hosted VoIP services where it was previously not.


Administrative Information

  1. Make sure your router is powered on and connected to your network.
  2. In a browser on a computer on the same network as the router, navigate to the following IP address:
  3. Log in (default credentials shown below).
    • Username: admin
    • Password: readwrite

Tested on firmware version 11.2.B257005.

Firewall Configuration

  1. Go to Firewall > Firewall Policies.
  2. Click Add to add the policies highlighted below.

Add Aliases (Voiceopia Servers)

  1. Go to Firewall > Aliases.
  2. Enter Voiceopia Servers in the Alias Name and Description fields.
  3. Add the Voiceopia subnets by clicking the Add Member button. 
    1. Voiceopia subnets (server addresses) will be provided upon request.
  4. Click Save.

Configure Policies

  1. Go to Firewall > Firewall Policies.
  2. Add a Policy and go to Policy Configuration > Policy.
  3. Name the policy Voiceopia and check the box to Enable it.
  4. Set Connections to Allowed.
  5. From Any-Trusted.
  6. Add Voiceopia Servers in the To field
  7. Go to the Properties tab.
  8. Enter information for the ports as seen below.
    1. 5060 - UDP
    2. 5061 - UDP
    3. 5061 - TCP
    4. 42463 - UDP
    5. 42463 - TCP
    6. 83 - UDP
    7. 83 - TCP
  9. Check the box next to Specify the custom idle timeout and set to the timeout to 300 seconds. This helps to prevent dropped calls. 
  10. Go to the Advanced tab.
  11. Select the options below to enable the following in the NAT section:
    • 1-to-1 NAT (Use Network NAT Settings)
    • Dynamic NAT
      • Select Use Network NAT Settings
  12. Click the checkbox next to Override Per-Interface Settings.
  13. Set the following values for QoS:
    • Marking Type: DSCP
    • Marking Method: Preserve
    • Prioritize Traffic Based on: Custom Value
    • Value: 7 (Highest)
  14. Click Save.
    watchguard advanced.png

Traffic Management Policies

  1. Go to Firewall > Traffic Management > Policies.
  2. Add a Traffic Management Action called Voiceopia Minimum.
  3. For the Voiceopia Policy, select Voiceopia Minimum as the Traffic Management Action.
  4. Click Save.

Configure Traffic Management Action Settings

  1. Go to Firewall > Traffic Management > Action Settings.
  2. Set the Outgoing InterfaceMinimum Bandwidth, and Maximum Bandwidth to the values listed below.
    1. Outgoing Interface = External
    2. Minimum Bandwidth = 100Kbps multiplied by each phone onsite (example: 10 phones = 1000Kbps)
    3. Maximum Bandwidth = 105Kbps multiplied by each phone onsite (example: 10 phones = 1050Kbps)
  3. Click Save


Please sign in to leave a comment.