Created on 08-29-2023 01:55 AM Edited on 08-28-2024 03:27 AM By Jean-Philippe_P
Description
This article explains the recommended scenarios for to use of each VoIP mode that is available on a FortiGate firewall.
Scope
Any supported version of FortiGate.
Solution
The following VoIP modes are available on the FortiGate firewall:
See the FortiGate documentation page for an explanation of these settings.
Use the following CLI command to review the VOIP mode:
config system settings
set default-voip-alg-mode
The query will return the following:
proxy-based: Use a default proxy-based VoIP ALG.
kernel-helper-based: Use the SIP session helper.
A SIP session helper is used when traffic does not match a policy that includes a VOIP security profile and the VOIP mode is set to kernel-helper-based.
Please note that the SIP session-helper is a legacy feature existing for compatibility reasons. It is not recommended to use a SIP session-helper to perform a SIP inspection. Please use SIP ALG instead.
SIP ALG is used in the following conditions:
As a final verification, use this guide to see which mode is used:
Technical Tip: How to confirm if FortiGate is using SIP Session Helper or SIP ALG
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.