Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Info
iconfalse
Info
iconfalse
Expand
titleFirmware Settings
  1. Verify and update the firmware.
    • External Link - Sonicwall Firmware update guide
    • Note: TheTZ Series should have firmware 5.8 or greater  (The device does need to be registered, but it does NOT require a paid subscription to download the firmware.)
Info
iconfalse
Expand
titleVoIP Settings
  1. Select VoIP from the left.
  2. Click on Settings.
    1. Ensure that Enable consistent NAT is ENABLED.
      1. (Some firmware versions will need this DISABLED, but it is best to start with Enabled and test from there.)
    2. Ensure that Enable SIP Transformations is DISABLED.
    3. Click Apply to save changes.
Info
iconfalse
Image Removed
Expand
titleFirewall Rules & Objects
  1. On the left, click Firewall > Access Rules > Matrix.
    1. Select the LAN to LAN arrow and disable or delete any VoIP or Voice rules under Destination or Service.
    2. Select the LAN to WAN arrow and disable or delete any VoIP or Voice rules under Destination or Service.
    3. Select the WAN to LAN arrow and disable or delete any VoIP or Voice rules under Destination or Service.
    4. Select the LAN to WAN arrow and disable or delete any VoIP or Voice rules under Destination or Service.
  2. Next, click Network on the left, and then click Address Objects (May be Under Firewall for Certain Firmware Revisions)
  3. Click Add and do the following.
    1. Name: Audian VoIP Server 1, 2, 3, 4, 5, and so on.
      • Zone Assignment: WAN
      • Type: Host
      • Network: Every IP Below needs to be added as an address object
  • 52.11.88.63
  • 52.27.186.140
  • 54.86.30.113
  • 54.144.238.86

  • 54.148.70.218
  • 54.148.57.6

  • 54.149.90.30

  • 3.13.153.32

  • 3.13.149.205

  • 3.19.84.238

  • 3.86.0.189

  • 3.130.148.40

  • 18.215.197.50

  • 34.202.125.217
Note

Please contact Audian support for a list of our IP addresses to whitelist.


Image Added

  • Click the Address Group tab at the top
    1. Click Add Group and add Audian
    2. Add all of the Audian objects and then click OK.
  • Navigate to Firewall > Access Rules > Click Add
    1. Set the Following
      • Action: Allow
      • From Zone: LAN
      • To Zone: WAN
      • Service: Any
      • Source: Any
      • Destinations: Audian
      • Allow Fragmented Packets: Checked
    2. Click Advanced tab and set the following.
      • UDP Connection Inactivity Timeout (seconds): 360
  • Navigate to Firewall > Access Rules > Click Add
    1. Set the Following
      • Action: Allow
      • From Zone: WAN
      • To Zone: LAN
      • Service: Any
      • Source: Audian
      • Destinations: Any
      • Allow Fragmented Packets: Checked
    2. Click Advanced tab and set the following.
      • UDP Connection Inactivity Timeout (seconds): 360
  • Save all changes
    • **It may take several minutes (up to 60) for the phones to properly re-register.  You can reboot all phones if you would like to make this happen quicker. 
  • Info
    iconfalse
    Expand
    titleBandwidth Management Settings
    1. On the left, navigate to Network > Interfaces.
    2. Click the Configure button under WAN.
    3. Select the Advanced tab, and then enable both Egress and Ingress Bandwidth Management. 
    4. Set your speed in Kbps in both of the boxes.
      1. Ingress= Download Speed (this should be set to your download speed in Kbps (x Mbps * 1024)Egress = Upload Speed (this should be set to your upload speed in Kbps (x Mbps * 1024
    5. Hit OK to save changes.
    6. Next, navigate to the Firewall Settings Menu, and then to BWM
    7. Ensure that Bandwidth Management Type is set to "Global"
    8. Ensure that at a minimum one priority above Medium (the default) is selected.  In this case, we have selected "High"
    9. Set this to a guaranteed reserve of between 20-30%.  (Make sure the guaranteed numbers add up to 100% as well)
      1. OPTIONAL - An Audian technician can give more details on the percentage number if needed, but essentially each voice channel uses around 50Kbps, so if you expect a maximum of 5 simultaneous voice calls, you would want to "guarantee" around 50Kbps * 5 = 250Kbps of bandwidth.  In our example, the maximum upload is 5,120Kbps, so we would want to set aside 250/5,120 = 6% of the available connection as guaranteed. In most cases, 10% is a good number to use.  Also keep in mind that this just GUARANTEES that much connection.  If no voice traffic is being used, the full connection will be used for your data and other connections.
    10. Hit Accept to save your changes.
    11. Navigate to Firewall, Access Rules, and then to the LAN -> WAN rule that was created to allow VoIP traffic previously (in the Sonicwall Guide).
    12. Select the configure button
    13. Select the "Ethernet BWM" tab
    14. Check to enable both Inbound and Outbound Bandwidth Management
    15. Select the Priority that you set in the previous Firewall settings (in this example, "2 High")
    16. Select OK to save

    You have now configured your sonicwall to automatically give a higher priority to any traffic that is going to the Audian servers, and to allow a percentage of your connection to be "guaranteed" for that traffic.  This should eliminate any call quality issues with high usage clients.