Firewall guide 10 min read Reviewed 9 September 2026

How to disable SIP ALG safely on a FortiGate firewall

FortiGate can process SIP through the SIP ALG or SIP session helper, and the exact disable procedure varies by FortiOS version and inspection design. Back up first, identify which mechanism owns the session, follow the matching Fortinet release instructions and clear only affected sessions before retesting.

Protect the service. Replace every placeholder with the value issued for your account. Never publish credentials, allow anonymous inbound SIP, or enable an unapproved caller ID.
Direct answer

FortiGate can process SIP through the SIP ALG or SIP session helper, and the exact disable procedure varies by FortiOS version and inspection design. Back up first, identify which mechanism owns the session, follow the matching Fortinet release instructions and clear only affected sessions before retesting.

Identify the FortiOS SIP processing path

FortiOS has used both a SIP ALG and a SIP session helper. Features, defaults and recommended commands have changed between releases. A copied command that deletes a numbered helper can affect the wrong entry where IDs differ.

  • Record the FortiGate model, FortiOS build, VDOM, HA role and policy ID carrying the SIP flow.
  • Back up configuration and ensure console or out-of-band access for rollback.
  • Inspect the active VoIP profile, firewall policy, session-helper table and a representative live session.
  • Confirm whether traffic is plain SIP, SIP over TLS or on a non-default port and whether central NAT is used.
Do not blindly delete “helper 13”

The session-helper entry number is not a universal promise. Display the table and use the exact Fortinet document for the installed FortiOS release before changing or deleting an entry.

Disable the correct FortiGate SIP inspection mechanism

  1. 1
    Match the official document to FortiOS

    Open Fortinet’s SIP ALG and SIP session-helper page for the exact FortiOS branch. Check release notes for behaviour changes before applying CLI.

  2. 2
    Remove SIP ALG from the policy path

    If the firewall policy or VoIP profile invokes the SIP ALG, change that supported policy/profile setting so SIP is not application-layer rewritten. Preserve IPS, antivirus and other required controls.

  3. 3
    Handle the session helper only if it is active

    Display system session-helper configuration, identify the entry whose name is sip and follow the version-specific Fortinet procedure. Do not assume an ID or delete unrelated helpers.

  4. 4
    Save and synchronise HA

    Confirm the intended configuration on the active and standby members and monitor HA status before touching sessions.

  5. 5
    Clear only affected sessions

    Use narrow source/destination/port filters and a maintenance window so existing non-VoIP traffic and unrelated calls are not dropped. New sessions are required to test the new inspection path.

Replace ALG behaviour with explicit secure policy

ControlRecommended approach
Registered SIPPermit the required outbound destination/port and return state; no blanket inbound VIP to a phone
Direct-IP SIPRestrict policies/VIPs to issued UKDDI signalling and media sources and exact destinations
ManagementAllow FortiGate and PBX administration only from trusted networks with MFA where supported
LoggingLog policy denies and session metadata without retaining SIP passwords or unnecessary call content
Flood/fraud protectionKeep rate, geography, dial-plan and account controls independent of the ALG

Validate the new FortiGate session path

  1. 1
    Create a fresh registration/session

    Restart only the affected registration or clear its filtered state, then confirm it uses the expected policy and no SIP helper/ALG rewriting.

  2. 2
    Test both directions

    Verify inbound and outbound calls, approved caller ID and exact DDI routing.

  3. 3
    Inspect signalling and media

    Confirm original Contact/SDP handling, two-way audio, keypad tones, hold, transfer and long-call stability.

  4. 4
    Monitor after the window

    Watch policy denies, session counts, HA health, registration state and call quality. Restore the backed-up design if impact extends beyond the scoped change.

TECHNICAL FAQ

Questions to check before raising a fault

Remove passwords from screenshots, configuration exports and packet captures before sharing them.

Is the FortiGate SIP ALG the same as the SIP session helper?

No. They are different FortiOS SIP-processing mechanisms, although release behaviour and migration paths can interact. Identify which mechanism is active before changing it.

Can I use a universal FortiGate CLI snippet?

No. Commands, defaults and helper IDs vary by FortiOS release and configuration. Use the exact official branch document and inspect before deleting or disabling anything.

Should I remove all security profiles from the VoIP policy?

No. Remove only incompatible SIP application-layer rewriting. Retain the firewall, source restrictions and other controls required by the security design.

OFFICIAL REFERENCES

Platform and standards documentation

Use the linked model and version documentation alongside this guide. Your UKDDI activation email takes priority for service-specific values.

NEXT TECHNICAL STEP

Related UKDDI guides

All technical guides →
STILL NOT REGISTERED?

Send the symptoms, not the secret.

Tell UKDDI the affected number, time of a test call, call direction, SIP response code and public PBX IP. Never send the SIP password.

Contact technical support