# PJSIP Behind NAT: Asterisk and FreePBX Settings for Two-Way Audio

Source: https://srvscripts.com/guides/pjsip-nat-asterisk-freepbx/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

NAT is behind most one-way audio, calls that drop after 32 seconds and phones that register but never ring. SIP carries IP addresses inside its messages, and a PBX or phone behind a router advertises its private address unless it is told otherwise. PJSIP has a small set of settings that fix this, split between the transport (when the PBX is behind NAT) and the endpoints (when the phones are). This guide explains each one, where FreePBX keeps them, and how to prove they work.

**Short answer:** If the PBX is behind NAT, set `local_net`, `external_media_address` and `external_signaling_address` on the PJSIP transport and forward the RTP range to the PBX. If phones are behind NAT, set `rtp_symmetric=yes`, `force_rport=yes`, `rewrite_contact=yes` and `direct_media=no` on their endpoints and a `qualify_frequency` of about 25 seconds. Turn SIP ALG off on every router. Our [PJSIP NAT settings generator](/tools/pjsip-nat-generator/) writes the exact lines.

In short: If the PBX is behind NAT, set local_net, external_media_address and external_signaling_address on the PJSIP transport and forward the RTP range to the PBX.

## Which side is behind NAT?

| Setup | Settings needed | Port forwards |
| --- | --- | --- |
| PBX on a VPS with a public IP, phones in offices | Endpoint NAT settings only | None on the office routers |
| PBX in the office behind a router, provider on the internet | Transport NAT settings (and endpoint settings for any remote phones) | RTP range to the PBX; SIP only for IP-authenticated trunks |
| PBX and remote phones both behind NAT | Both | RTP range to the PBX |

## PBX behind NAT: transport settings

When the PBX has a private address, Asterisk must write the router’s public address into SIP headers and the SDP for anyone outside the LAN, and keep using the private address for phones inside it. `local_net` defines “inside”; everything else gets the external addresses.

```
[transport-udp]
type=transport
protocol=udp
bind=0.0.0.0:5060
local_net=192.168.1.0/24
local_net=10.8.0.0/16        ; VPN users reach the PBX directly
external_media_address=203.0.113.25
external_signaling_address=203.0.113.25
```

List every range that reaches the PBX without NAT, including VPN subnets; a missing range makes those phones receive the public address and lose audio. Transport changes are not reloadable: in our lab Asterisk 20.6 reported `allow_reload: false` for the transport, so restart Asterisk (`core restart gracefully`) after changing them. If you use a hostname for the external address, Asterisk resolves it when the transport loads, so a changed dynamic IP needs a restart too.

## Phones behind NAT: endpoint settings

Phones behind their own routers send their private address and port in the Contact and Via headers and in the SDP. These endpoint options make Asterisk use the address the packets really came from:

```
[201]
type=endpoint
; ...
rtp_symmetric=yes      ; send audio back to where audio comes from
force_rport=yes        ; reply to the source port of the request
rewrite_contact=yes    ; store the real public address and port
direct_media=no        ; keep audio through Asterisk

[201]
type=aor
qualify_frequency=25   ; keepalive inside the router's UDP timeout
max_contacts=1
remove_existing=yes
```

`qualify_frequency` matters more than it looks: many routers drop an idle UDP mapping after 30 to 60 seconds, after which incoming calls cannot reach the phone. A keepalive every 25 seconds keeps the mapping open. We loaded exactly these settings into Asterisk 20.6 and confirmed with `pjsip show endpoint` and `pjsip show aor` that they took effect.

## Router, firewall and SIP ALG

- **RTP range:** forward UDP 10000-20000 (or your `rtpstart`–`rtpend`) to the PBX when it is behind NAT. Without it, audio from the provider may never arrive.

- **SIP port:** a trunk that registers keeps its own mapping open, so 5060 does not need forwarding. IP-authenticated trunks and remote phones that connect in do need it, ideally limited to known source addresses.

- **SIP ALG:** turn it off. It rewrites SIP headers on the way through and fights with the settings above. See [how to disable SIP ALG](/guides/disable-sip-alg/) on common routers.

- **UDP timeout:** at least 60 seconds, better 120 to 180.

- **Carrier-grade NAT:** if the router’s WAN address is in 100.64.0.0/10, the ISP is doing NAT as well and port forwards cannot work. Ask for a public IP or host the PBX on a VPS.

## FreePBX: where the settings live

- **Settings > Asterisk SIP Settings > General SIP Settings:** External Address and Local Networks (NAT Settings), and the RTP port range.

- **Settings > Asterisk SIP Settings > SIP Settings [chan_pjsip]:** which transports listen and on which ports.

- **Each extension, Advanced tab:** Rewrite Contact, RTP Symmetric, Force rport and Direct Media.

- **Each trunk, pjsip Settings > Advanced:** Qualify Frequency and the same NAT options.

Submit and Apply Config; transport and local network changes need `fwconsole restart`. The [generator](/tools/pjsip-nat-generator/) has a FreePBX mode that lists these fields with the values to enter.

We checked where these values end up on a FreePBX 17 test server (Asterisk 22.11, 6 October 2026), using 203.0.113.25 as the example external address and 192.168.1.0/24 as the local network. FreePBX writes them to `/etc/asterisk/pjsip.transports.conf` in a transport named `[0.0.0.0-udp]`, with `allow_reload=no`: a plain reload does not change a transport, so run `fwconsole restart` after changing NAT settings.

[](https://srvscripts.com/wp-content/uploads/2026/10/fpbx-nat-1006.png)FreePBX 17 NAT settings as written to pjsip.transports.conf and as Asterisk sees them. 203.0.113.25 is a documentation address used as the example.

## Check it with the PJSIP logger

```
asterisk -rx "pjsip show transports"     # external addresses as expected
asterisk -rx "pjsip set logger on"       # then make a test call
asterisk -rx "pjsip show contacts"       # remote phones with public IPs and Avail
asterisk -rx "rtp set debug on"          # audio sent to the address it comes from
```

In the logger output, an INVITE to your provider should carry the public address in its Via, Contact and SDP `c=` line; a call to a phone on the LAN should carry the private one. A private address in anything sent to the internet is the bug. Paste the call into the [SIP trace analyzer](/tools/sip-trace-analyzer/), which flags private addresses in the SDP automatically.

## PJSIP NAT settings at a glance

Covers: Which side is behind NAT?, PBX behind NAT: transport settings, Phones behind NAT: endpoint settings and Router, firewall and SIP ALG.

Answers: Why do I get one-way audio when the PBX is behind NAT? Do I need both external_media_address and external_signaling_address?

**Official documentation:** [Asterisk PJSIP configuration](https://docs.asterisk.org/), [RFC 3581: symmetric response routing (rport)](https://www.rfc-editor.org/rfc/rfc3581), [RFC 4961: symmetric RTP](https://www.rfc-editor.org/rfc/rfc4961).

**Related:** [PJSIP NAT settings generator](/tools/pjsip-nat-generator/) · [Fix one-way audio](/guides/voip-one-way-audio/) · [Disable SIP ALG](/guides/disable-sip-alg/) · [SIP firewall rules generator](/tools/voip-firewall-generator/).

## Frequently asked questions

### Why do I get one-way audio when the PBX is behind NAT?

The far end sends audio to the address in your SDP. Without external_media_address it is your private address, which the internet cannot reach. Set the external addresses on the transport and forward the RTP range to the PBX.

### Do I need both external_media_address and external_signaling_address?

Normally yes, both set to the same public IP. Media covers the SDP (where audio goes); signalling covers the Via and Contact headers (where replies, re-INVITEs and BYE go). Missing the signalling address is a classic cause of calls dropping after 32 seconds.

### Should direct_media be off?

For phones behind NAT, yes. Direct media tells two phones to send audio straight to each other, which fails when either is behind a router. Keep audio through Asterisk unless every phone is on the same LAN.

### Can I use a hostname for a dynamic IP?

Yes, external_media_address and external_signaling_address accept a hostname, but Asterisk resolves it when the transport loads. After the IP changes, restart Asterisk (FreePBX: fwconsole restart) once the DNS has updated.
