This article describes how to resolve the issue when VoIP calls may drop or encounter poor quality.
Applies to the following Sophos products and versions Sophos Firewall
When there is no SIP misconfiguration, VoIP issues usually occur due to UDP time-out value.
Sophos XG Firewall has a default UDP time-out of 60 seconds which is usually low for reliable VoIP communication. Usually the VoIP provider declare recommended UDP time-out for best experience. Common value is 150 seconds which is perfect for most VoIP scenarios.
To verify the current UDP time-out value, from the command line interface (CLI), choose option 4. Device Console and run the following command:
To modify the UDP time-out value to 150 seconds, run the following command:
set advanced-firewall udp-timeout-stream 150
Note: When there is a Site-to-Site VPN and/or IPS configured in the XG, then the following two commands help resolving the VoIP calls drop or poor quality issue:
set ips sip_preproc disable
set vpn conn-remove-tunnel-up disable
If you've spotted an error or would like to provide feedback on this article, please use the section below to rate and comment on the article. This is invaluable to us to ensure that we continually strive to give our customers the best information possible.
Every comment submitted here is read (by a human) but we do not reply to specific technical questions. For technical support post a question to the community. Or click here for new feature/product improvements. Alternatively for paid/licensed products open a support ticket.