This guide walks you through the process of creating and managing firewall policies on a WatchGuard Firebox to ensure proper VoIP traffic flow for Bravo.
🔹 Firewall policies control traffic flow between different destinations using specified protocols.
🔹 To ensure Bravo system phones connect properly, allow traffic to the following RingFree systems:
✅ sipe.ringfree.net
✅ sipc.ringfree.net
✅ sipw.ringfree.net
✅ UDP 5080 (SIP Signaling)
✅ UDP 20000-27999 (RTP Traffic – Audio Transmission)
These settings are essential for creating a firewall policy on any WatchGuard device.
1️⃣ Navigate to: Firewall > Firewall Policies
2️⃣ Click "Add Policy".
3️⃣ Select Policy Type: Custom and click "Add".
4️⃣ In the Add Firewall Policy screen:
RingFreePacket Filter1️⃣ Click "Add" under Protocols.
2️⃣ Configure the first protocol:
Single PortUDP50803️⃣ Click "Add" again to configure RTP Traffic:
Port RangeUDP20000279994️⃣ Click Save to confirm the firewall rule.
After saving the policy:
✅ Ensure it is set From: Any-Trusted To: Any-External for UDP 5080 & 20000-27999.
✅ If a customer requires stricter security, modify the From and To fields to specific networks.
✅ Click "Add Policy" to finalize.
1️⃣ Navigate to Firewall > Firewall Policies.
2️⃣ Click "Edit" on the RingFree policy.
3️⃣ Select the protocol you want to update and click "Edit".
4️⃣ After making changes, click "Save".
✅ The updated settings will apply across all firewall policies using this template.
WatchGuard uses aliases to simplify firewall configuration. These aliases group networks under predefined names:
| Alias | Definition |
|---|---|
| Any | Includes any IP address on any active interface. |
| Firebox | Represents the Firebox’s own IP addresses. |
| External | Covers networks connected to the external interface. |
| Any-External | Represents all external-type networks/interfaces. |
| Trusted | Includes networks connected to a trusted interface. |
| Any-Trusted | Covers all trusted-type networks/interfaces. |
| Optional | Represents networks connected to an optional interface. |
| Any-Optional | Includes all optional-type networks/interfaces. |
🔹 Use these aliases carefully to ensure proper security and traffic flow.
✅ Ensure VoIP traffic is properly allowed through UDP ports 5080 and 20000-27999.
✅ Modify aliases if more specific restrictions are required.
✅ Regularly review firewall policies to prevent unexpected call failures.
By following these steps, you can successfully create and manage WatchGuard Firebox policies for Bravo’s VoIP services.