# SIP Ports Firewall Rules: 4 Setups for CSF, firewalld and pfSense

Source: https://srvscripts.com/guides/sip-ports-firewall/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

A PBX that registers but has no audio, or that gets hammered by SIP scanners within minutes of going online, almost always has a SIP ports firewall problem. VoIP uses two kinds of traffic: SIP signalling, which sets up and ends calls, and RTP media, which carries the actual voice on a range of UDP ports chosen per call. Both must be allowed, and SIP should be locked down to the addresses that genuinely need it. This guide lists the ports each common PBX uses and gives working rules for CSF, firewalld and pfSense.

**Short answer:** Allow SIP on UDP and TCP 5060 (and TCP 5061 if you use TLS) only from your SIP trunk provider and remote office IPs, and allow the RTP range on UDP from anywhere: 10000-20000 for Asterisk and FreePBX, 9000-10999 for 3CX. In CSF use `csf.allow` port-and-IP rules for SIP and `UDP_IN` for RTP; in firewalld use rich rules for SIP and `--add-port` for RTP; on pfSense forward both to the PBX and set Outbound NAT to static port.

In short: Allow SIP on UDP and TCP 5060 (and TCP 5061 if you use TLS) only from your SIP trunk provider and remote office IPs, and allow the RTP range on UDP from anywhere: 10000-20000 for Asterisk and FreePBX, 9000-10999 for 3CX.

## Which ports a PBX needs

| Traffic | Asterisk / FreePBX | 3CX | Direction |
| --- | --- | --- | --- |
| SIP signalling (UDP/TCP) | 5060 | 5060 | Inbound from trunk and remote phones |
| SIP over TLS (TCP) | 5061 | 5061 | Inbound, if TLS is enabled |
| RTP media (UDP) | 10000-20000 (rtp.conf) | 9000-10999 | Both directions |
| Provisioning / web client | HTTPS 443 or custom | 5001 or 443 | Inbound from phones and apps |

Always confirm the real values on your system rather than trusting defaults. On Asterisk check the media range and the listening sockets:

```
grep -E 'rtpstart|rtpend' /etc/asterisk/rtp.conf
ss -lunp | grep -E '5060|5061'
ss -ltnp | grep -E '5060|5061'
```

On 3CX the ports are shown in the admin console under the network or firewall checker section; a custom install may have moved them.

## CSF on cPanel or plain AlmaLinux

Keep SIP out of the global `TCP_IN` and `UDP_IN` lists so the whole internet cannot reach it. Open only the RTP range globally in `/etc/csf/csf.conf`, using a colon for ranges:

```
UDP_IN = "20,21,53,853,10000:20000"
```

Then allow SIP per source address in `/etc/csf/csf.allow` with the advanced filter syntax. Replace the example addresses with your trunk provider’s signalling IPs:

```
udp|in|d=5060|s=203.0.113.10
tcp|in|d=5060|s=203.0.113.10
tcp|in|d=5061|s=198.51.100.0/24
csf -r
```

Add remote offices the same way. If phones roam on dynamic addresses, use TLS on 5061 plus strong extension passwords and fail2ban instead of opening 5060 to everyone.

## firewalld on AlmaLinux, Rocky or RHEL

firewalld ships `sip` and `sips` service definitions, but adding them opens SIP to every source. Use rich rules instead and open the media range normally:

```
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="203.0.113.10/32" port port="5060" protocol="udp" accept'
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="203.0.113.10/32" port port="5060" protocol="tcp" accept'
firewall-cmd --permanent --add-port=10000-20000/udp
firewall-cmd --reload
firewall-cmd --list-rich-rules
```

## pfSense in front of the PBX

When the PBX sits behind pfSense, create port forwards under Firewall » NAT » Port Forward for UDP 5060 (source restricted to the trunk alias) and for the RTP range, both pointing at the PBX’s LAN address, and let pfSense add the matching WAN rules. Then switch Firewall » NAT » Outbound to hybrid mode and add a rule for the PBX address with Static Port ticked. Without it pfSense rewrites the source port of outgoing SIP and RTP, which is a classic cause of one-way audio and registrations that drop after a few minutes. Also raise the UDP state timeout, or the trunk’s registration can expire between refreshes.

## Test and harden

Watch a call set up while you test from a mobile phone on 4G, outside your network:

```
sngrep port 5060
tcpdump -ni any udp portrange 10000-20000 -c 50
fail2ban-client status asterisk
```

If SIP arrives but no RTP packets show, the media range is blocked or NAT is wrong; see the one-way audio guide. Log lines from user agents such as `friendly-scanner` or `sipvicious` mean SIP is still reachable from the internet. Tighten the source rules until those stop.

## Or avoid inbound ports altogether

A hosted phone system removes this work: the desk phones and apps connect outbound to the provider, so no inbound SIP or RTP ports are opened on your network. [JustCall](/justcall/) and [CloudTalk](/cloudtalk/) are two cloud phone systems we review on this site; both only need outbound HTTPS and UDP media allowed from your office network.

Affiliate note: links marked “sponsored” earn srvScripts a commission if you buy, at no cost to you. See our [affiliate disclosure](/affiliate-disclosure/).

## SIP ports firewall at a glance

**Official documentation:** [Asterisk documentation](https://docs.asterisk.org/), [3CX documentation](https://www.3cx.com/docs/), [RFC 3261: SIP](https://www.rfc-editor.org/rfc/rfc3261).

**Related guides:** [Disable SIP ALG](/guides/disable-sip-alg/) · [VoIP one-way audio fix](/guides/voip-one-way-audio/) · [SIP SRV records](/guides/sip-srv-records/).

## Frequently asked questions

### Should SIP port 5060 be open to the whole internet?

No. Allow 5060 only from your SIP trunk provider and known office IPs. An open 5060 is scanned within minutes and attackers try to brute-force extension passwords to make fraudulent international calls.

### Why is the RTP range so large?

Each call uses two UDP ports per direction, and the PBX picks free ports from the range for every concurrent call. A wide range avoids running out; it is safe to open because the PBX only listens on ports for active calls.

### Do I need to open ports for a cloud phone system?

Usually not. Hosted systems connect outbound, so allowing outbound HTTPS and UDP from the office is enough. Check the provider’s network requirements page for their media IP ranges if your firewall filters outbound traffic.
