Description | This article describes an issue when attempting to apply an VoIP profile with feature set to ips, it cannot be applied to a firewall policy. |
Scope | FortiGate v7.4.3, v7.6.0. |
Solution |
In version v7.2.5, the VoIP profile allows the combination of applying SIP ALG (proxy based) and SIP IPS (flow based) profi....
In some scenario, when a VoIP profile has been configured to IPS, it is possible to select the profile in the firewall policies but it fails to save.
edit "sip-ips" set feature-set ips config sip set log-violations enable end
This profile should be applied in conjunction with a SIP-ALG profile and set through the CLI using the command set ips-voip-filter <voip_profile>:
config firewall policy set voip-profile "sip-voipd" <-- Proxy-based VoIP profile.
In 7.2.9, 7.4.5, 7.6.1 the IPS profile will be filtered out. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.