Emergency server help: get in touch

PJSIP NAT Settings Generator: Asterisk, FreePBX, Issabel, VitalPBX, 3CX

Generate the PJSIP NAT settings for Asterisk or FreePBX: transport local_net and external addresses, endpoint rtp_symmetric, force_rport and rewrite_contact, rtp.conf, router port forwards and the commands that prove it works.

Status
Live
Last updated
October 6, 2026

This NAT settings generator writes the configuration your PBX needs when the PBX, the phones or both sit behind a router. It covers plain Asterisk (PJSIP or legacy chan_sip), FreePBX, Issabel, VitalPBX, Vicidial/ViciBox, FusionPBX/FreeSWITCH, 3CX and MikoPBX, with each platform’s own menu paths and default ports. Tell it which side is behind NAT, your public IP or hostname, your local networks, the transport and the RTP range, and it returns the transport section, the endpoint and AOR options, rtp.conf, the router and firewall changes, and the commands that confirm it works. It runs in your browser.

Short answer: PBX behind NAT needs local_net, external_media_address and external_signaling_address on the transport plus the RTP range forwarded to it. Phones behind NAT need rtp_symmetric, force_rport, rewrite_contact, direct_media=no and a 25-second qualify_frequency. SIP ALG must be off on every router.

When you need NAT settings

SIP puts IP addresses inside its messages. Behind a router, those addresses are private, so the other side sends replies and audio somewhere it cannot reach. The symptoms are one-way or no audio, calls that drop after about 32 seconds, and phones that register but stop receiving calls. The PJSIP behind NAT guide explains the background; this tool writes the lines.

How to use the generator

  • Choose who is behind NAT: the PBX, remote phones, or both.
  • Enter the public IP or hostname of the PBX’s router (check it with What is my IP from the PBX network).
  • List every network that reaches the PBX directly, including VPN ranges, in CIDR form.
  • Pick your platform (Asterisk config files, or the FreePBX, Issabel, VitalPBX, Vicidial, FusionPBX, 3CX or MikoPBX screens), the transport and the RTP range. Leave the SIP port and RTP range blank to use that platform’s defaults.
  • Apply the result, restart Asterisk for transport changes, and run the checks in the last table.

What each setting does

SettingWhereWhat it does
local_netTransportNetworks treated as inside; they get the private address
external_media_addressTransportPublic IP written into the SDP so audio comes back to the router
external_signaling_addressTransportPublic IP in Via and Contact so replies and BYE arrive
rtp_symmetricEndpointSend audio to the address audio arrives from
force_rport / rewrite_contactEndpointReply to and store the phone’s real public address and port
direct_media=noEndpointKeep audio through Asterisk
qualify_frequencyAORKeepalive that holds the NAT mapping open

We loaded the generator’s output for a PBX behind NAT into Asterisk 20.6 in a lab and confirmed every value with pjsip show transport, pjsip show endpoint and pjsip show aor.

Common mistakes

  • Using the PBX’s LAN address as the external address (the tool refuses private addresses).
  • Forgetting the VPN range in local_net, so VPN phones get the public address and lose audio.
  • Changing the transport and only reloading: transports need a restart.
  • Leaving SIP ALG on, which rewrites the same headers these settings fix.
  • Running behind carrier-grade NAT (100.64.0.0/10), where port forwards cannot work; the tool warns when the address is in that range.

PJSIP NAT generator at a glance

PJSIP NAT generator summary card: PBX behind NAT needs local_net, external_media_address and external_signaling_address on the transport plus the RTP…
In short: PBX behind NAT needs local_net, external_media_address and external_signaling_address on the transport plus the RTP range forwarded to it.
PJSIP NAT generator sections: When you need NAT settings, How to use the generator, What each setting does and Common mistakes
Covers: When you need NAT settings, How to use the generator, What each setting does and Common mistakes.
PJSIP NAT generator questions answered: Is my IP address sent anywhere? My PBX is on a VPS with a public IP. Do I need any of this?
Answers: Is my IP address sent anywhere? My PBX is on a VPS with a public IP. Do I need any of this?

Official documentation: Asterisk PJSIP configuration, RFC 3581: rport.

Related: PJSIP behind NAT guide · Fix one-way audio · SIP firewall rules generator · SIP trace analyzer.

Frequently asked questions

Is my IP address sent anywhere?

No. The generator runs in your browser; nothing you type is sent to srvscripts.com.

My PBX is on a VPS with a public IP. Do I need any of this?

Not on the transport. Choose “remote phones behind NAT”: the phones still need rtp_symmetric, force_rport, rewrite_contact and keepalives.

Does it work for chan_sip?

No. chan_sip used nat=force_rport,comedia, externip and localnet, and it was removed in Asterisk 21. This tool writes PJSIP settings.

Do I need to forward port 5060?

Not for a trunk that registers, because the registration keeps the mapping open. You do need it for IP-authenticated trunks and for remote phones connecting in, ideally only from known addresses. The RTP range does need forwarding when the PBX is behind NAT.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.