ADAM PULSE Knowledge Base
Zoom administration · SIP ALG · QoS · DSCP · Firewall

SIP ALG, QoS and DSCP for Zoom Phone: what should you configure on the firewall?

Short answer

For a healthy Zoom Phone deployment, the firewall should do three things well:

  1. **Allow the current Zoom Phone signaling, media, provisioning, and

supporting traffic documented by Zoom**

  1. **Avoid interfering with SIP and media flows through unnecessary

application layer manipulation**

  1. **Prioritize real time voice traffic inside the network when

congestion can occur**

For QoS, Zoom Phone supports DSCP marking. Zoom's recommended values are EF / 46 for real-time telephony media and CS3 / 24 for signaling — those are the values in Zoom's own Zoom Phone Bluepaper network configuration guidance, in both its four-queue and twelve-queue models.

You will also see 56 and 40 attributed to Zoom Phone in a great deal of secondary material. Those are real numbers from Zoom's documentation, but they are not platform defaults and using them as your design target is a mistake. See the section on where 56 and 40 come from, below — it matters more than it sounds.

Whatever values you choose, the markings configured in Zoom must match the policy that your switches, wireless infrastructure, routers, and firewalls actually honor.

The critical concept is:

DSCP marking does not create bandwidth.

It identifies traffic so network equipment can give that traffic preferential treatment when congestion exists.

Also remember:

DSCP markings normally do not survive the public Internet.

QoS is therefore most useful inside the network you control.

For SIP ALG, do not blindly enable a firewall's SIP transformation features simply because Zoom Phone uses SIP. SIP ALG, SIP Helper, VoIP inspection, SIP transformation, and similar features can alter signaling or media behavior. Zoom's technical guidance identifies SIP ALG interference as a potential source of desk phone problems. If one way audio, registration failures, transfers, or other SIP related symptoms appear, include SIP ALG and related VoIP inspection in the troubleshooting path.

Important:

Firewall vendors change firmware, menus, defaults, and VoIP inspection behavior. Zoom also changes IP ranges and service requirements. Use this article as an architecture and troubleshooting guide, then verify the current Zoom first party firewall documentation and the current documentation for your firewall platform before changing production policy.

------------------------------------------------------------------------

SIP ALG: what it is and why it breaks calls

What Is SIP ALG?

SIP ALG means Session Initiation Protocol Application Layer Gateway.

A traditional SIP ALG attempts to understand SIP signaling as it passes through a firewall or router.

Depending on the product, it may:

This was historically intended to help SIP systems traverse NAT.

The problem is that modern cloud communications platforms already have sophisticated mechanisms for handling signaling, media, encryption, NAT traversal, and session establishment.

An intermediary that modifies traffic can sometimes make things worse instead of better.

------------------------------------------------------------------------

Is SIP ALG the Same on Every Firewall?

No.

This is extremely important.

Different vendors use terms such as:

The implementation also differs by firmware version.

Therefore, a statement such as:

"Disable SIP ALG."

is incomplete unless you know:

------------------------------------------------------------------------

Should I Disable SIP ALG for Zoom Phone?

Treat SIP ALG as a specific inspection item to verify, not as a universal button to change without testing.

Zoom's technical library identifies SIP ALG interference among common causes of desk phone issues.

In practical troubleshooting, if Zoom Phone experiences symptoms such as:

inspect SIP ALG, SIP Helper, and related VoIP inspection behavior.

If those functions are modifying Zoom Phone signaling or media unexpectedly, the appropriate remedy may be to bypass or disable that processing for the relevant traffic.

Always document the existing setting before changing it.

------------------------------------------------------------------------

Why Can SIP ALG Cause One Way Audio?

A phone call has signaling and media components.

The call can successfully establish while the media path is wrong.

For example:

SIP signaling succeeds

→ phone rings

→ user answers

→ call shows connected

but:

Media path fails in one direction

→ one person hears audio

→ the other hears silence

If a firewall rewrites signaling or media information incorrectly, the endpoints can establish the call while sending media to the wrong destination or through an invalid path.

That is why:

"The call connects"

does not prove the firewall is handling the media correctly.

------------------------------------------------------------------------

Signaling versus media

What Is the Difference Between SIP Signaling and Voice Media?

Think of a phone call as two conversations.

Signaling

Signaling establishes and controls the call.

It handles events such as:

Media

Media carries the actual conversation.

That includes the audio packets flowing between endpoints and the Zoom Phone service.

A firewall can allow signaling while blocking or mishandling media.

That creates classic symptoms such as:

Phone rings but no audio

or:

Audio works only one direction

------------------------------------------------------------------------

Is RTP the Same as SIP?

No.

SIP is associated with call signaling.

RTP is associated with real time media transport.

Zoom Phone also uses secure media technologies, so administrators should follow Zoom's current service specific firewall requirements rather than building policies from generic SIP assumptions.

------------------------------------------------------------------------

Firewall rules: what Zoom Phone actually needs

Should I Open SIP Port 5060 to the Entire Internet?

No.

Do not build Zoom Phone firewall policy from generic VoIP folklore.

Use Zoom's current Zoom Phone firewall rules.

Zoom publishes service specific protocols, ports, and destination ranges.

Those requirements should be the authoritative starting point.

A rule such as:

Allow UDP 5060 from anywhere

is not a responsible substitute for Zoom's documented requirements.

------------------------------------------------------------------------

Should I Port Forward SIP to Every Desk Phone?

No.

A normal cloud Zoom Phone deployment should not be treated like an old on premises PBX where administrators expose individual phones to unsolicited Internet SIP traffic.

Follow Zoom's documented outbound and return connection model.

Do not create inbound port forwards to phones simply because someone says "VoIP needs SIP ports."

------------------------------------------------------------------------

What Firewall Rules Does Zoom Phone Need?

Zoom maintains a dedicated section in its network firewall documentation for Zoom Phone.

The exact ports and destination IP ranges can change.

Therefore, the correct procedure is:

  1. Open Zoom's current firewall documentation
  2. Locate the Zoom Phone section
  3. Identify the endpoint type
  4. Identify signaling requirements
  5. Identify media requirements
  6. Identify provisioning and supporting services
  7. Apply the rules to outbound traffic as documented
  8. Permit the associated return traffic
  9. Document the rule
  10. Monitor Zoom for IP range updates

Do not copy a five year old port list from a blog into a production firewall.

------------------------------------------------------------------------

Why Should I Avoid Hard Coding an Old Zoom IP List?

Cloud infrastructure changes.

Zoom explicitly notes that its firewall article contains current IP ranges and directs customers to Zoom Status for planned IP address updates.

A firewall rule that worked last year can become incomplete later.

For restrictive environments, build a process for reviewing Zoom network changes.

------------------------------------------------------------------------

Does Zoom Phone Work Through a Web Proxy?

Do not assume the normal Zoom proxy behavior applies to Phone.

Zoom's general firewall documentation specifically notes that its HTTPS/SSL proxy support statement does not apply to the Zoom Phone service.

That distinction is easy to miss.

If your organization requires authenticated proxy traversal for Internet traffic, test the Zoom Phone architecture carefully rather than assuming the desktop application's web connectivity proves Phone media will work.

------------------------------------------------------------------------

QoS and DSCP: the basics

What Is QoS?

QoS means Quality of Service.

It is a set of network mechanisms used to classify and prioritize traffic.

Voice is highly sensitive to:

A large file download can tolerate a short delay.

A human conversation cannot.

QoS lets network devices treat those traffic types differently.

------------------------------------------------------------------------

What Is DSCP?

DSCP means Differentiated Services Code Point.

It is a marking in an IP packet that can be used by network equipment to classify traffic.

Think of DSCP as a label.

The label says:

"This packet belongs to this traffic class."

The switch, router, firewall, or wireless system then decides what treatment that class receives.

------------------------------------------------------------------------

Which DSCP values to use, and where 56 and 40 came from

What DSCP Values Does Zoom Phone Use?

There are two different answers circulating, and conflating them is how QoS designs go wrong.

What Zoom recommends is on Zoom's own Zoom Phone Bluepaper network configuration page:

Those are the values in both the four-queue and the twelve-queue models Zoom publishes. They are also the values a traditional enterprise voice design already uses, which means Zoom Phone slots into most existing QoS policies without argument.

Where 56 and 40 come from is a different question. Zoom's "Implementing Quality of Service for Zoom Phone" article documents that the Windows Zoom Workplace client assigns markings through the Windows native API:

the Zoom Workplace app utilizes the Windows native API to assign the following DSCP markings: 56 for Zoom Phone media, 40 for Zoom Phone signaling

Read where that sentence lives: it is in the Windows section, and it describes what a Windows client marks when nothing overrides it. It is a client-side behaviour, not a Zoom Phone platform default, and it is precisely why Windows needs a Group Policy or PowerShell QoS policy to bring it into line with an enterprise design.

Zoom allows administrators to configure the values. The important requirement is consistency: if Zoom marks media one way and the network expects another, the intended QoS policy does not work.

------------------------------------------------------------------------

Is DSCP 56 the Same as EF 46?

No — and the difference is not academic. Run the arithmetic before you build a policy on either number.

DSCP values map to classes in blocks of eight:

CS7 is the one class you least want voice sitting in. On most switches an access port is untrusted by default, and CS7 arriving from a user device is re-marked to zero or dropped at the trust boundary — because a user device is not supposed to be originating network control traffic. An administrator who marks Zoom Phone media 56 and then builds a switch policy around it has done real work to place voice in a class the network is configured to strip.

So the rule is not:

"Voice always equals 46."

And it is certainly not "voice equals 56 because a Windows client marks it that way." The rule is:

Choose a QoS model, configure Zoom to match it, and make the network honor that model end to end.

If your organisation already has an enterprise QoS standard, align Zoom to that standard. If it does not, Zoom's own EF/46 and CS3/24 recommendation is the sane starting point, because it is what the rest of the industry's default configurations already expect.

------------------------------------------------------------------------

Can I Change the Zoom Phone DSCP Values?

Yes.

Zoom allows administrators to configure media and signaling DSCP values for Zoom Phone.

That is useful when the organization already has an established enterprise QoS model.

For example, if the network standard uses:

Voice media → DSCP 46

the Zoom Phone configuration can be aligned with that architecture when appropriate.

------------------------------------------------------------------------

Enabling QoS, and what enabling it does not do

Where Do I Enable Zoom Phone QoS?

Zoom currently documents the account level path as:

Account Management

→ Account Settings

→ Zoom Phone

→ General

→ Enable QoS with DSCP marking

The administrator can then configure the media and signaling values.

After enabling QoS, certified desk phones may need to be resynced.

Verify the current Zoom administrative interface because menus can change.

------------------------------------------------------------------------

Does Enabling QoS in Zoom Automatically Prioritize Calls?

No.

This is one of the biggest misconceptions.

Enabling DSCP marking in Zoom tells the endpoint to mark packets.

Your network must still:

QoS is an end to end design inside the network you control.

------------------------------------------------------------------------

What Does "Trust DSCP" Mean?

A switch or network device can decide whether it trusts the DSCP marking received from an endpoint.

If the network does not trust the endpoint, it may:

This can be desirable for security because otherwise any endpoint could mark all of its traffic as high priority.

A mature QoS design defines where classification and trust occur.

------------------------------------------------------------------------

Should I Trust DSCP From Every User Device?

Usually not without a policy.

If every endpoint can mark arbitrary traffic as highest priority, QoS loses meaning.

Common strategies include:

The correct approach depends on the environment.

------------------------------------------------------------------------

Platform differences: Windows, macOS, mobile and desk phones

Does Zoom Phone QoS Work on Windows?

Yes, but Windows requires special consideration.

Zoom documents that Windows does not normally permit the Zoom Workplace app to configure DSCP markings on outgoing traffic without the required privileges.

Zoom identifies several options, including:

This is also the reason the 56 and 40 values exist at all: absent one of those policies, the Windows client falls back to marking media 56 and signaling 40 through the native API. A Group Policy or PowerShell QoS policy is how you replace those with the values your network actually honours.

For managed enterprise environments, Group Policy or PowerShell policy is generally more operationally realistic than asking users to run Zoom as administrator every day.

------------------------------------------------------------------------

Does Zoom Phone QoS Work on macOS and Mobile Devices?

Zoom documents that non Windows Zoom Workplace clients, including supported mobile platforms and macOS/Linux, can apply the DSCP values configured in the Zoom admin portal, subject to the environment.

Network infrastructure must still preserve and honor those markings.

------------------------------------------------------------------------

Does QoS Work on Zoom Phone Desk Phones?

Zoom supports DSCP marking on certified desk phones that support the functionality.

Zoom can push defined DSCP values to supported certified devices.

For desk phones, verify:

------------------------------------------------------------------------

Do I Need to Resync Desk Phones After Enabling QoS?

Zoom's current QoS workflow provides an option to resync certified desk phones after QoS is enabled.

If a phone is expected to receive updated provisioning values, verify that the device has successfully resynced before testing packet markings.

------------------------------------------------------------------------

Verifying it works, and what happens at the WAN edge

How Do I Verify DSCP Is Actually Working?

Capture packets.

Do not rely solely on the admin portal.

A proper validation can include packet captures at multiple points:

Endpoint

→ Access switch

→ Distribution layer

→ Firewall

Verify:

If the marking disappears between two points, you have found the trust or remark boundary.

------------------------------------------------------------------------

Does DSCP Work Across the Public Internet?

Usually not in a way you can depend on.

Zoom explicitly notes that DSCP markings are typically not preserved once traffic leaves the customer's network and enters the public Internet.

Internet traffic is generally handled as best effort.

Therefore, QoS can protect Zoom Phone traffic from congestion on:

It cannot force the public Internet to prioritize your call.

------------------------------------------------------------------------

Why Configure QoS if the Internet Ignores It?

Because congestion often happens before the packet reaches the Internet.

For example:

User starts 5 GB upload

→ office Internet uplink saturates

→ voice packets wait behind bulk traffic

→ caller hears delay, jitter, or loss

QoS on the customer edge can prioritize voice before the packet enters the Internet.

That can make a major difference.

------------------------------------------------------------------------

Can QoS Fix a Bad Internet Circuit?

No.

QoS manages contention.

It does not repair:

If the circuit itself is bad, QoS cannot create a good path.

------------------------------------------------------------------------

Can QoS Create More Bandwidth?

No.

If you have 100 Mbps, DSCP does not turn it into 200 Mbps.

QoS decides which packets receive preferred treatment when demand exceeds available capacity.

------------------------------------------------------------------------

Latency, jitter and packet loss

What Is Latency?

Latency is the time required for traffic to travel between endpoints.

Zoom's current Zoom Phone QoS guidance says round trip delay should not exceed 300 ms for optimal performance.

Lower latency generally produces a more natural conversation.

------------------------------------------------------------------------

What Is Jitter?

Jitter is variation in packet arrival time.

Voice packets should arrive at predictable intervals.

If some arrive quickly and others arrive late, audio can sound:

QoS can help when jitter is caused by local congestion, but it cannot correct every source of jitter on the Internet.

------------------------------------------------------------------------

What Is Packet Loss?

Packet loss means packets never reach the destination.

Voice applications can conceal some loss, but excessive loss creates:

Before blaming Zoom, determine where loss begins.

------------------------------------------------------------------------

Wi-Fi, VPN and split tunnelling

Should Zoom Phone Use WiFi?

It can.

But wireless networks require careful design for real time voice.

Review:

A firewall QoS rule cannot repair an overloaded wireless channel.

------------------------------------------------------------------------

What Is WMM?

WiFi Multimedia, or WMM, provides traffic prioritization mechanisms for wireless networks.

If your Zoom Phone users rely heavily on WiFi, wired QoS alone is incomplete.

The wireless design must also recognize and prioritize real time traffic appropriately.

------------------------------------------------------------------------

What About VPN Users?

VPNs add another layer.

Potential impacts include:

Zoom's QoS guidance specifically tells administrators to consider VPN overhead.

If corporate policy permits, architecture that avoids unnecessary media hairpinning can improve real time communications.

------------------------------------------------------------------------

Should Zoom Phone Traffic Be Split Tunneled?

That is an enterprise security and network architecture decision.

Do not change VPN routing solely to improve a speed test.

Evaluate:

Then test call quality.

------------------------------------------------------------------------

Transport, ports and NAT traversal

Does Zoom Phone Use UDP?

Yes, Zoom Phone uses UDP for real time media in applicable workflows.

Zoom's current QoS documentation states that Zoom Phone on Zoom Workplace desktop and mobile apps uses UDP source ports 9000 through 9999 for outbound traffic in the described configuration.

That can help administrators classify traffic where port based identification is appropriate.

Always verify current documentation before hard coding a production rule.

------------------------------------------------------------------------

Can I Customize Zoom Phone Media Ports?

Zoom supports custom source port configuration in certain endpoint scenarios.

However, this requires careful planning.

Zoom notes that customization availability differs among:

For desk phones, consult the vendor documentation and use provisioning templates where supported.

------------------------------------------------------------------------

What About ICE, STUN, and TURN?

Zoom Phone supports peer to peer media capabilities that can use ICE, STUN, and TURN.

These technologies help determine media paths and NAT traversal.

Zoom notes that when ICE/STUN/TURN is used, client QoS marking behavior and custom media port assumptions have limitations.

In particular, custom media port ranges do not control the ports selected by ICE candidate gathering.

This is another reason not to build a firewall around one simplistic port assumption.

------------------------------------------------------------------------

Designing the policy: priority, bandwidth and shaping

Should I Prioritize Signaling and Media the Same Way?

Not necessarily.

Media and signaling have different traffic characteristics.

Zoom exposes separate DSCP values for:

The network design can therefore classify them differently.

Media generally has the stronger real time sensitivity.

------------------------------------------------------------------------

Should Voice Get Unlimited Priority?

No.

A priority queue should be engineered.

An incorrectly designed strict priority queue can starve other traffic or behave badly during congestion.

Estimate voice bandwidth and configure reasonable queue behavior.

------------------------------------------------------------------------

How Much Bandwidth Does a Zoom Phone Call Use?

The exact consumption varies with codec, signaling, encryption, endpoint, and call behavior.

Do not size a network from one generic number.

For capacity planning, consider:

Concurrent calls

× Expected per call bandwidth

Then validate with actual measurements.

------------------------------------------------------------------------

Why Do Calls Become Bad Only at Certain Times of Day?

That strongly suggests contention or path variability.

Look for:

Compare Zoom call quality data with WAN utilization at the same timestamp.

------------------------------------------------------------------------

Why Are Calls Bad Only When Someone Uploads a Large File?

That is a classic upstream congestion symptom.

Many business Internet circuits have much less upload capacity than download capacity.

When the upstream becomes saturated, voice packets can queue behind bulk traffic.

QoS and traffic shaping at the edge can help protect real time voice.

------------------------------------------------------------------------

Is Traffic Shaping the Same as DSCP?

No.

DSCP labels traffic.

Traffic shaping controls traffic rates and queue behavior.

They are often used together.

For example:

Zoom Phone packet marked as voice

→ firewall recognizes class

→ traffic shaper places it in priority queue

→ bulk upload receives lower priority during congestion

The DSCP value alone did not create that behavior.

------------------------------------------------------------------------

Where to configure it, by platform

Should I Configure QoS on the Firewall or the Switch?

Potentially both.

QoS should be designed across the points where congestion can occur.

That can include:

Zoom explicitly recommends an end to end QoS implementation within the controlled network.

Partial QoS can produce unpredictable results.

------------------------------------------------------------------------

What Should I Do on a FortiGate?

For a FortiGate environment, evaluate:

Do not paste a CLI command from an old forum post into a production FortiGate without checking the FortiOS version and current Fortinet documentation.

The correct setting can differ by firmware and inspection mode.

------------------------------------------------------------------------

What Should I Do on Meraki?

For a Meraki environment, evaluate:

Make sure the configured WAN bandwidth accurately represents the usable circuit capacity if shaping depends on those values.

------------------------------------------------------------------------

What Should I Do on SonicWall?

For a SonicWall environment, evaluate:

The exact menu names vary by SonicOS release.

------------------------------------------------------------------------

What Should I Do on Ubiquiti?

For a Ubiquiti environment, evaluate:

Do not enable Smart Queues automatically on every connection. Understand the gateway model, circuit speed, and performance impact.

------------------------------------------------------------------------

What Should I Do on a Home Router?

Home routers are less predictable.

They may include hidden or poorly documented:

If one remote employee has Zoom Phone trouble while the rest of the company works normally:

  1. Test the Zoom Workplace app on another network
  2. Compare wired and WiFi
  3. Reboot the router
  4. Check for firmware updates
  5. Review SIP ALG if accessible
  6. Review ISP security features
  7. Test without VPN if policy permits
  8. Escalate to the ISP if the gateway is provider managed

The goal is to isolate whether the problem follows the user, endpoint, or network.

------------------------------------------------------------------------

Symptom to cause

Why Does Zoom Phone Work on My Hotspot but Not Office WiFi?

That is strong evidence that the Zoom service and endpoint may be functional.

Compare the office network for:

Do not reinstall Zoom repeatedly if changing the network makes the problem disappear.

------------------------------------------------------------------------

Why Does the Zoom App Work but the Desk Phone Does Not?

Different endpoint types can use different:

A successful Zoom Workplace call does not prove that a Poly or Yealink phone has the network access it needs.

This is why endpoint type matters during troubleshooting.

------------------------------------------------------------------------

Why Does the Desk Phone Work but the Zoom Workplace App Does Not?

Reverse the logic.

Check:

The shared Internet connection may be fine.

------------------------------------------------------------------------

What Causes One Way Audio?

Common investigation areas include:

Do not assume one way audio has one universal cause.

------------------------------------------------------------------------

What Causes Choppy Audio?

Investigate:

Choppy audio is primarily a media quality problem, not automatically a SIP problem.

------------------------------------------------------------------------

What Causes Calls to Drop?

Investigate:

Record whether calls drop after a repeatable amount of time.

A consistent interval can provide a useful clue.

------------------------------------------------------------------------

What Causes Delayed Audio?

Look for:

QoS can reduce queuing delay inside your network but cannot remove geographic distance.

------------------------------------------------------------------------

Tools and what to monitor

What Is the Zoom Phone Call Quality Dashboard?

Zoom provides a Call Quality Dashboard to help administrators evaluate Zoom Phone calls.

Use it to correlate user complaints with measurable call data.

Instead of:

"Zoom sounded bad at 2 PM."

capture:

That turns a subjective complaint into a troubleshooting event.

------------------------------------------------------------------------

What Is the Zoom Network Connectivity Tool?

Zoom provides a Network Connectivity Tool that can help validate connectivity to Zoom services.

Use it as part of the troubleshooting process.

It should complement, not replace:

------------------------------------------------------------------------

What Should I Monitor on the Firewall?

At minimum, monitor:

If you only look at the firewall after the user complains, you may miss the event.

Historical monitoring is valuable.

------------------------------------------------------------------------

What Should I Monitor on the Switch?

Review:

A voice quality problem can begin several devices before the firewall.

------------------------------------------------------------------------

What Should I Monitor on WiFi?

Review:

A perfect firewall cannot compensate for a poor RF environment.

------------------------------------------------------------------------

Triage procedure

How Should I Troubleshoot a Zoom Phone Quality Complaint?

Use this order.

Step 1: Define the Symptom

Is it:

Do not call everything "bad quality."

Step 2: Define the Scope

One user?

One site?

One phone model?

All users?

Only WiFi?

Only VPN?

Only inbound calls?

Only call queue calls?

Step 3: Capture the Time

Get the exact timestamp.

Without a timestamp, correlation becomes much harder.

Step 4: Check Zoom Call Quality

Review the relevant call in Zoom.

Step 5: Check WAN and Network Monitoring

Was there congestion, packet loss, or an outage?

Step 6: Check Firewall Logs

Were Zoom flows denied, reset, inspected, or translated unexpectedly?

Step 7: Check SIP ALG and VoIP Inspection

Especially for signaling, registration, transfer, or one way audio symptoms.

Step 8: Check QoS

Are packets marked?

Are markings preserved?

Are queues configured?

Are queues dropping?

Step 9: Isolate the Network

Compare:

Step 10: Capture Packets

If the issue persists, packet captures can reveal where signaling or media behavior diverges.

------------------------------------------------------------------------

The 15 Minute Zoom Phone Firewall Triage

Minute 1

Get exact user, site, and timestamp.

Minute 2

Identify endpoint: Zoom Workplace, Poly, Yealink, Zoom Phone Appliance, SBC.

Minute 3

Define symptom: registration, no audio, one way audio, choppy, drop, delay.

Minute 4

Check whether other users are affected.

Minute 5

Check WAN utilization.

Minute 6

Check ISP health and monitoring.

Minute 7

Check Zoom Call Quality Dashboard.

Minute 8

Check firewall denies.

Minute 9

Verify current Zoom Phone firewall requirements.

Minute 10

Review SIP ALG, SIP Helper, or VoIP inspection.

Minute 11

Check VPN and routing.

Minute 12

Check DSCP marking and QoS policy.

Minute 13

Compare another network or endpoint.

Minute 14

Capture logs or packets.

Minute 15

Classify the problem:

Endpoint

or

LAN/WiFi

or

Firewall

or

WAN/ISP

or

Zoom configuration/service

or

SBC/carrier path

That classification is more valuable than another reboot.

------------------------------------------------------------------------

Checklists

Firewall Change Checklist

Before changing a firewall:

After changing it:

------------------------------------------------------------------------

QoS Implementation Checklist

Design

Zoom

LAN

Edge

Validation

------------------------------------------------------------------------

Frequently asked questions

Should I disable SIP ALG for Zoom Phone?

SIP ALG should be reviewed whenever it can alter Zoom Phone SIP or media behavior. Zoom's technical guidance identifies SIP ALG interference as a potential cause of desk phone issues. Do not change production firewall behavior blindly. Verify the firewall, firmware, traffic path, and symptoms, then bypass or disable interfering VoIP inspection where appropriate.

What DSCP value should Zoom Phone use for voice?

Zoom recommends EF / 46 for real-time telephony media in its Zoom Phone Bluepaper network configuration guidance. The value 56 that circulates widely is what the Windows client marks natively when nothing overrides it, not a platform default, and 56 is CS7, the network control class, which most switches strip at an untrusted edge.

What DSCP value should Zoom Phone use for signaling?

CS3 / 24, per Zoom's Bluepaper guidance. The 40 that circulates is the Windows client's native marking, and 40 is CS5 rather than CS3.

Should Zoom Phone media use DSCP 46?

Yes in most designs. EF / 46 is what Zoom recommends and what most enterprise QoS policies already expect. If your organisation has an established QoS standard that uses something else, align Zoom to that standard instead, and make sure the network honours it end to end.

Does Zoom Phone QoS work over the Internet?

You should not depend on DSCP being preserved across the public Internet. Zoom states that markings are typically lost once traffic leaves the customer's network.

Does QoS increase bandwidth?

No. QoS prioritizes traffic during contention.

Can QoS fix packet loss from my ISP?

Not if the packet loss occurs in the provider network. QoS can help protect traffic from congestion inside the network you control.

Can SIP ALG cause one way audio?

It can be a contributing cause when the firewall alters signaling or media behavior. Include SIP ALG and related VoIP inspection in one way audio troubleshooting.

Should I open port 5060 to the Internet for Zoom Phone?

Do not create generic SIP exposure rules. Use Zoom's current Zoom Phone firewall requirements for the applicable endpoints and service.

Should I port forward to Zoom desk phones?

Normally no. Follow Zoom's documented cloud Phone connectivity model rather than exposing individual phones through generic SIP port forwarding.

Why does my Zoom Phone call connect but have no audio?

Signaling may be succeeding while the media path fails. Check firewall rules, NAT, SIP/VoIP inspection, media reachability, VPN, routing, and endpoint networking.

Why does Zoom Phone work on a hotspot but not the office network?

That strongly suggests the office network path deserves investigation. Check firewall policy, DNS, WiFi, VLANs, inspection, VPN, QoS, and packet loss.

Why does Zoom Phone sound bad when someone uploads a large file?

The upstream Internet circuit may be congested. QoS and traffic shaping can prioritize real time voice before bulk traffic.

Does Windows automatically apply Zoom Phone DSCP?

Windows has additional restrictions. Zoom documents administrative privileges, PowerShell QoS policy, and Group Policy as methods for applying the intended markings.

Can desk phones receive Zoom QoS settings?

Supported certified desk phones can receive DSCP configuration through Zoom. Verify the exact model and current support.

What should I check first for choppy audio?

Check packet loss, jitter, latency, WAN utilization, WiFi quality, VPN path, and ISP performance before changing SIP settings.

What should I check first for one way audio?

Check the media path, firewall policy, NAT, SIP ALG or VoIP inspection, VPN, SBC behavior, and routing. ------------------------------------------------------------------------

References

Zoom's own documentation. Where this article contradicts a widely repeated figure, the reference is the page that figure actually came from — read the section it sits in.

  1. Zoom Technical Library — Zoom Phone Bluepaper: network configuration— Zoom's recommended QoS model: EF / 46 for real-time telephony and CS3 / 24 for signaling, in both the four-queue and twelve-queue designs.
  2. Zoom — Implementing Quality of Service for Zoom Phone— the source of the 56 and 40 figures: "the Zoom Workplace app utilizes the Windows native API to assign the following DSCP markings: 56 for Zoom Phone media, 40 for Zoom Phone signaling." Note the section it sits in.
  3. Zoom — Managing Zoom Phone QoS with DSCP marking— where the account-level DSCP settings live and how they reach clients and devices.
  4. Zoom — Using QoS DSCP marking— the general Zoom DSCP behaviour across clients.
  5. Zoom Technical Library — Quality of Service and network best practices— the wider QoS explainer, including why markings do not survive the public Internet.
  6. Zoom — Network firewall or proxy server settings for Zoom— the current address ranges and ports. Use this rather than a hard-coded list copied from an older article.
  7. Zoom — Zoom Phone certified hardware— which desk phones support provisioned DSCP marking.

ADAM Pulse is the network side of a Zoom Phone deployment: SIP inspection off, current address-range rules, and an end-to-end DSCP model the switches actually honour.

Prepared by ADAM Pulse (USA Telecom Consulting LLC)

Managed Zoom Phone and network services, SDVOSB. We do the firewall and QoS side of a Zoom Phone deployment: SIP inspection audits, current-address-range rule sets rather than stale copies, an end-to-end DSCP model your switches actually honour, and the packet capture when it turns out to be none of those. Support: (888) 989-4872 · support@adampulse.us