What are the IP and port ranges of sipgate?

Overview of the IP addresses, ports, and protocols for all sipgate services, including firewall configurations.

sipgate.de

Signaling:

  • IP: 217.10.79.9

  • Port: 5060

  • Protocol: UDP

RTP:

  • IP: 212.9.44.0/24 and 217.10.77.0/24

  • Port range: 15000 - 30000

  • Protocol: UDP

sip.sipgate.de

Protocol: TCP, TLS

Signaling

  • IP: 212.9.44.242, 212.9.44.244, 217.10.77.242, 217.10.77.244

  • Port: 5060/TCP, 5061/TLS, 443/WSS

  • Protocol: TCP, TLS, WSS

RTP:

  • IP range: 212.9.44.0/24 and 217.10.77.0/24

  • Port range: 15000 - 30000

  • Protocol: UDP

sipconnect.sipgate.de

Protocol: UDP

Signaling

  • IP: 217.10.68.150

  • Port: 5060

  • Protocol: UDP

RTP:

  • IP: 212.9.44.0/24 and 217.10.77.0/24

  • Port range: 15000 - 30000

  • Protocol: UDP

Note: IP addresses and port ranges may change due to expansions on our platform.

The IP address ranges used by sipgate are:

  • 217.10.64.0/20

  • 217.116.112.0/20

  • 212.9.32.0/19

Further information on the IP and firewall settings for the sipgate app can be found in the following article: What are the IP and firewall settings for the sipgate app?


Firewall configurations

sipgate.de via UDP + Sophos Firewall

1

Disable SIP Helper

The Sophos Firewall has a SIP module, the so-called SIP Helper. In exceptional cases, however, using this module can lead to disruptions. In such cases, it makes sense to disable the SIP Helper.

How to disable the SIP Helper in SFOS:

  1. Connect to the firewall via SSH

  2. Select the option 4. Device Console from

  3. Display the status of the SIP module:

  4. Disable the SIP module:

  5. If necessary, you can then re-enable the SIP module:

After disabling the SIP Helper, the VoIP firewall rules must be configured correctly so that communication works smoothly.

2

Increase UDP session timeout

A common reason for VoIP problems with the Sophos Firewall is a UDP timeout that is set too short. For smooth data transmission with sipgate, you need a longer timeout duration so that connections are not terminated prematurely.

How to adjust the UDP timeout in SFOS:

  1. Connect to the firewall via SSH

  2. Option 4. Device Console select

  3. Display current value:

  4. Set timeout value (e.g. 180 seconds):

We recommend values between 30 and 3600 seconds.

3

Create dedicated firewall rule for VoIP

A separate firewall rule for VoIP traffic provides more control and better troubleshooting.

A possible configuration can look like this:

  • Source zone: LAN

  • Source network: VoIP end devices (e.g. IP phones or telephone system)

  • Destination zone: WAN

  • Destination network: IP addresses or hostnames of the VoIP provider

  • Services: SIP (port 5060), RTP (e.g. ports 10000–20000)

The rule should be placed as high as possible in the policy order and have logging enabled.

4

Enable Quality of Service (QoS) for VoIP

To ensure that VoIP packets are not delayed even under high network load, prioritization via traffic/packet shaping is recommended.

How to set up QoS for VoIP on the Sophos Firewall:

  1. Go to System ServicesTraffic Shaping

  2. Create a new policy

  3. Policy settings:

    • Policy type: Guarantee

    • Priority: High

    • Bandwidth usage: Real-Time

    • Guaranteed bandwidth: depending on codec and number of simultaneous calls

  4. Assign traffic shaping policy to the VoIP firewall rule

5

Monitoring & troubleshooting

After configuration, it is recommended to monitor the voice connections and packet flows:

  • Firewall logs (Log Viewer → Firewall)

  • Live view (Diagnostics → Packet Capture)

  • SNMP monitoring can be used to monitor quality and latency.

sipgate.de via UDP + SecurePoint Firewall

In connection with the SecurePoint Firewall, the SIP Helper sometimes leads to undesirable behavior such as connection drops or one-way audio transmission. Disabling the SIP Helper can help here.

The manufacturer provides the following information on this: UTM/FAQ-VoIP

sipgate.de via UDP + Mikrotik Firewall

Sometimes the SIP Helper/ALG causes undesirable behavior such as dropped connections or one-way audio transmission. Disabling the SIP Helper/ALG can help here.

via terminal:

via web: IP → Firewall → Service ports: disable SIP

Then restart the firewall and VoIP apps/phones.

Further information can be found on the website of Mikrotik.

sipgate.de via UDP + FortiGate Firewall

Sometimes the SIP Helper/ALG causes undesirable behavior such as dropped connections or one-way audio transmission. Disabling the SIP Helper/ALG can help here.

Instructions from the manufacturer can be found here: Disabling VoIP Inspection

sipgate.de via UDP + Lancom Firewall

Sometimes the SIP Helper/ALG causes undesirable behavior such as dropped connections or one-way audio transmission. Disabling the SIP Helper/ALG can help here.

In LANconfig under Other servicesServicesSIP Application Layer Gateway: disable (disabled by default)

Sometimes the SIP Helper/ALG causes undesirable behavior such as dropped connections or one-way audio transmission. Disabling the SIP Helper/ALG can help here.

In the Deco app, go to More → Advanced → NAT Forwarding → SIP ALG to disable this option.

Images / manufacturer instructions: How do I disable SIP-ALG on my Decos?

sipgate.de via UDP + Netgear Firewall

Sometimes the SIP Helper/ALG causes undesirable behavior such as dropped connections or one-way audio transmission. Disabling the SIP Helper/ALG can help here.

  1. Click on the "Advanced" tab.

  2. Click "Configure".

  3. Then click "WAN Configuration".

  4. Then check the box for "Disable SIP ALG".

Please note that this setting only exists from firmware 1.0.0.50 onwards.

sipgate.de via UDP + Huawei Firewall

Sometimes the SIP Helper/ALG causes undesirable behavior such as dropped connections or one-way audio transmission. Disabling the SIP Helper/ALG can help here.

Click on "Security" and then under the sub-item "SIP ALG settings" → disable SIP ALG.

sipgate.de via UDP + Vodafone GigaCube Firewall

Sometimes the SIP Helper/ALG causes undesirable behavior such as dropped connections or one-way audio transmission. Disabling the SIP Helper/ALG can help here.

Go to "Security" and then disable SIP ALG under the item "SIP ALG settings" → SIP ALG.


Errors and solutions

sipgate app error: "The action is not possible. You are offline. Check your internet connection"

Analysis: sipgate app → Help → Export logs → renderer.log

Cause 1: There is no internet connection Solution 1: Check internet connection

Cause 2: Internet connection works, Google IP range blocked outbound via firewall rule software / hardware firewall Solution 2: Check local firewall rules software firewall: "Windows Defender" or hardware firewall: router and allow Google IP range

sipgate app error: Call accepted, but no audio on either side

Analysis:

Cause IPv4 internet: Firewall IPv4 212.9.44.0/24 and 217.10.77.0/24 blocks Solution IPv4 internet: Firewall IPv4 212.9.44.0/24 and 217.10.77.0/24 allow

Cause IPv6 internet: Firewall IPv6 2001:ab7:2000:3::0/64 blocks Solution IPv6 internet: Firewall IPv6 2001:ab7:2000:3::0/64 allow

sipgate app error: Status offline and outgoing calls do not work

Analysis: sipgate.de → Help → Export logs: renderer.log

Cause IPv4 internet: 212.9.44.242, 212.9.44.244, 217.10.77.242, 217.10.77.244 blocks Solution IPv4 internet: 212.9.44.242, 212.9.44.244, 217.10.77.242, 217.10.77.244 allow

Cause IPv6 internet: [2001:ab7::17], [2001:ab7::18], [2001:ab7::19], [2001:ab7::1a] blocks Solution IPv6 internet: [2001:ab7::17], [2001:ab7::18], [2001:ab7::19], [2001:ab7::1a] allow

Last updated