Chapter 22 VoIP Solutions: SIP : FortiGate VoIP solutions: SIP : The SIP ALG : Configuration example: SIP in Transparent Mode : Configuration steps - web‑based manager
  
Configuration steps - web‑based manager
 
Before you begin this procedure you may have to go to System > Config > Features and turn on VoIP. To find VoIP select the Show More button.
To add firewall addresses for the SIP phones
1. Go to Policy & Objects > Objects > Addresses.
2. Add the following addresses for Phone A and Phone B:
Category
Address
Name
Phone_A
Type
Subnet
Subnet / IP Range
10.31.101.20/255.255.255.255
Interface
port1
Category
Address
Name
Phone_B
Type
Subnet / IP Range
Subnet / IP Range
10.31.101.30/255.255.255.255
Interface
port2
To add security policies to apply the SIP ALG to SIP sessions
1. Go to Policy & Objects > Policy > IPv4.
2. Select Create New to add a security policy.
3. Add a security policy to allow Phone A to send SIP request messages to Phone B:
Incoming Interface
port1
Source Address
Phone_A
Outgoing Interface
port2
Destination Address
Phone_B
Schedule
always
Service
SIP
Action
ACCEPT
4. Turn on VoIP and select the default VoIP profile.
5. Select OK.
6. Add a security policy to allow Phone B to send SIP request messages to Phone A:
Incoming Interface
port2
Source Address
Phone_B
Outgoing Interface
port1
Destination Address
Phone_A
Schedule
always
Service
SIP
Action
ACCEPT
7. Turn on VoIP and select the default VoIP profile.
8. Select OK.