---
notionId: "29bf0d27c798803ab36ce0f9f0020d8d"
product: "business-phone"
cluster: "devices"
intent: "business-phone.troubleshoot-device-network"
docSlug: "troubleshoot-device-network"
task: "Troubleshoot a device network in Business Phone"
title: "Troubleshoot a device network in Business Phone | VirtualPBX"
meta_description: "Here’s a sample rule set you can provide to your IT team:"
answer: "Here’s a sample rule set you can provide to your IT team:"
audience: "admin"
updated: "2026-01-01"
legacy: ["troubleshooting-network-issues-on-your-device"]
headings: [{"depth":3,"text":"Recommended Firewall/NAT Rule Set","id":"recommended-firewallnat-rule-set"},{"depth":3,"text":"NAT / SIP ALG","id":"nat--sip-alg"},{"depth":3,"text":"Outbound Rules","id":"outbound-rules"},{"depth":3,"text":"Inbound / Return Traffic","id":"inbound--return-traffic"},{"depth":3,"text":"Ephemeral Ports & Media","id":"ephemeral-ports--media"},{"depth":3,"text":"Required Port Destinations (Inbound/Outbound)","id":"required-port-destinations-inboundoutbound"},{"depth":3,"text":"Troubleshooting Tips","id":"troubleshooting-tips"}]
lint: ["meta-answer","answer-first","headings"]
---

<aside class="note"><p>Port destinations and network settings are very important for making sure your device works correctly. Refer to our recommendations below when troubleshooting </p></aside>

### Recommended Firewall/NAT Rule Set

### NAT / SIP ALG

<ul>
<li><p>Disabling SIP ALG is generally the first resolution for device issues - make sure to check this item on your network devices before troubleshooting further </p>
</li>
<li><p>Disable SIP ALG or other protocol-interfering features (many break VoIP).</p>
</li>
<li><p>Ensure your NAT is enabled on only one deviceMultiple devices attempting to NAT can cause what’s called dual NATing, meaning multiple devices are trying to give your phone an internal IP address. This can cause phoens to lose connection imtermittently, or consistently.</p>
</li>
</ul>

### Outbound Rules

<ul>
<li><p>Allow TCP/UDP outbound to your VoIP provider’s service IP range (or hostname) on the ports in Section 2.</p>
</li>
<li><p>Allow UDP outbound from your network to service IP range on ephemeral ports (e.g., 10,000-65,535).</p>
</li>
</ul>

### Inbound / Return Traffic

<ul>
<li><p>Ensure your firewall/NAT allows return traffic to the original internal source port (ephemeral) when initiated from the service endpoint.</p>
</li>
<li><p>Use “Allow established/related” rules rather than opening wide inbound access.</p>
</li>
</ul>

### Ephemeral Ports & Media

When your softphone registers and then places or receives a call, the media (audio, video) and sometimes fallback signaling use ephemeral (temporary) ports chosen by your operating system or device. For smooth operation:

<ul>
<li><p>Allow outbound UDP from your LAN to the service’s media server IPs on the full ephemeral port range (commonly 10,000-65,535 or OS default).</p>
</li>
<li><p>Allow return traffic into those ephemeral ports — most firewalls allow “established/related” traffic automatically and consider it best practice.</p>
</li>
<li><p>Example: Your softphone picks source port 53,421 for RTP; traffic should be allowed from service endpoint back to 53,421.</p>
</li>
</ul>

Important: The ports listed in Section 2 are the destination/listening ports. Your softphone’s source port will be ephemeral and not in that list—so firewall rules must account for that.

### Required Port Destinations (Inbound/Outbound)

Please ensure that your network firewall/NAT allows traffic to the following destination ports — both TCP and UDP, as indicated:

<div class="table-scroll" tabindex="0"><table><tr><th>Protocol</th><th>Port(s)</th><th>Purpose</th></tr><tr><td>TCP</td><td>80</td><td>HTTP registration / service communication</td></tr><tr><td>TCP</td><td>443</td><td>HTTPS / secure WebRTC signaling</td></tr><tr><td>TCP/UDP</td><td>5000</td><td>Alternate registration or proprietary signaling</td></tr><tr><td>TCP/UDP</td><td>5060-5065</td><td>SIP signaling (non-TLS) / fallback SIP ports</td></tr><tr><td>TCP/UDP</td><td>5443</td><td>Secure signaling port</td></tr><tr><td>TCP/UDP</td><td>5555</td><td>Additional signaling / management port</td></tr><tr><td>TCP/UDP</td><td>7000</td><td>Media or backup signaling path</td></tr><tr><td>TCP/UDP</td><td>7078-7079</td><td>Backup media/data path</td></tr><tr><td>TCP/UDP</td><td>8443</td><td>Secure WebRTC / HTTPS media fallback</td></tr><tr><td>TCP/UDP</td><td>9078-9079</td><td>Additional media/data fallback ports</td></tr></table></div>

Example: Outbound from your softphone → server at port 5060 (UDP)

Inbound/outbound return traffic will flow once allowed.

### Troubleshooting Tips

<ul>
<li><p>If registration fails, check that destination signaling ports are allowed and reachable.</p>
</li>
<li><p>If you get one-way audio or no audio: likely your media ports or return traffic are blocked—verify ephemeral UDP is allowed and SIP ALG is disabled.</p>
</li>
<li><p>If calls drop mid-call, check NAT timeouts and that mappings remain active for media, and SIP ALG is disabled.</p>
</li>
</ul>
