Tech

Configuring your firewall for remote users

Published on:

February 6, 2020

Configuring your firewall for remote users is essential for enabling VoIP communications through the Vodia PBX. This setup requires allowing specific TCP and UDP ports, including 5060 and 5061 for SIP signaling, UDP ports 49152 to 64512 for RTP and TCP ports 80 and 443 for web access. Additionally, setting the appropriate IP routing entries ensures both internal and remote phones can communicate effectively, utilizing a netmask that accommodates local network traffic while allowing access from external sources. This dual configuration allows for seamless call management across different network environments.

A firewall controls the incoming and outgoing network traffic based on an applied rule set and establishes a barrier between a trusted, secure LAN and/or WAN network(s) and the internet (neither secure nor trusted).

Vodia Networks recommends a LAN architecture where the voice traffic bypasses the firewall:

LAN Achritecture

If a firewall feature is configured, it must allow the following ports to pass (if you want to connect remote users to the PBX then you will need to configure the Vodia SBC settings):

  • Allow TCP/UDP ports 5060, 5061 (for SIP)
  • Allow UDP ports 49152–64512(for RTP)1
  • Allow UDP port 123 (for NTP)
  • Allow TCP port 80 (for HTTP)
  • Allow TCP port 443 (for HTTPS)

Vodia PBX SBC

Vodia SBC - SIP Settings

In order to make the PBX show the public IP address, you need an entry that matches "every other IP address". In other words, the netmask must be 0.0.0.0 (for example, "0.0.0.0/0.0.0.0/123.124.125.126"). The problem is it will block all calls on the private network, so there is also a necessary rule for the private network.

Example: Let's say the PBX is running on 192.168.1.2 address, the netmask is 255.255.0.0 and the internal SIP phones have 192.168.x.x addresses. So the first part of the entry will be "192.168.0.0/255.255.0.0/192.168.1.2". This part will take care of the internal phones. Now, if the phone and PBX have to talk to remote phones and servers, then you have added another part to the "IP Routing List". Consider the public IP address is 123.124.125.126 (this the IP address provided/assigned by the internet service provider). You can check the public IP using http://whatismyip.com/), then you will have "0.0.0.0/0.0.0.0/123.124.125.126" as the other part of the entry.

Putting it all together, an entry of "192.168.0.0/255.255.0.0/192.168.1.2 0.0.0.0/0.0.0.0/123.124.125.126" will make the PBX serve both internal and remote phones.

In this example, the PBX would not look at the routing presented by the operating system.

Latest Articles

View All

Unlock Smarter Workflows with the Vodia and monday.com Integration

Vodia’s latest integration with monday.com combines powerful business communications with an intuitive, AI-driven CRM platform used by 61 percent of the Fortune 500. This integration automatically logs inbound and outbound calls from your Vodia PBX directly into monday.com boards, creating and updating contact records while maintaining detailed call histories. Designed to streamline workflows and enhance collaboration, this seamless connection helps businesses save time, reduce manual data entry, and improve productivity through smarter communication management.

June 20, 2025

Vodia and Microsoft Teams: A Robust Integration for Business

The integration between Vodia PBX and Microsoft Teams gives businesses a seamless way to combine powerful SIP-based telephony with modern collaboration tools. With advanced call control, a built-in Session Border Controller (SBC), and extensive customization options, the Vodia PBX enables organizations to manage both Teams and SIP users within a single, secure, and flexible system. This hybrid architecture allows companies to tailor their communications infrastructure to match their specific operational needs - whether across departments, locations, or user roles.

June 17, 2025

Flowroute SMS and MMS With Vodia PBX | Video Tutorial

Vodia PBX integrates seamlessly with Flowroute to enable SMS and MMS messaging within your VoIP system. This video tutorial guides you through the entire process - from setting up your Flowroute account and configuring SMS and MMS in the Flowroute portal to webhook setup for message delivery and thorough testing to ensure everything runs smoothly. Designed for businesses and service providers alike, this comprehensive guide helps you quickly and efficiently add reliable, scalable text messaging features to your communication infrastructure, enhancing your overall VoIP experience.

June 16, 2025