SIP ALG, QoS and DSCP for Zoom Phone: what should you configure on the firewall?
Short answer
For a healthy Zoom Phone deployment, the firewall should do three things well:
- **Allow the current Zoom Phone signaling, media, provisioning, and
supporting traffic documented by Zoom**
- **Avoid interfering with SIP and media flows through unnecessary
application layer manipulation**
- **Prioritize real time voice traffic inside the network when
congestion can occur**
For QoS, Zoom Phone supports DSCP marking. Zoom's recommended values are EF / 46 for real-time telephony media and CS3 / 24 for signaling — those are the values in Zoom's own Zoom Phone Bluepaper network configuration guidance, in both its four-queue and twelve-queue models.
You will also see 56 and 40 attributed to Zoom Phone in a great deal of secondary material. Those are real numbers from Zoom's documentation, but they are not platform defaults and using them as your design target is a mistake. See the section on where 56 and 40 come from, below — it matters more than it sounds.
Whatever values you choose, the markings configured in Zoom must match the policy that your switches, wireless infrastructure, routers, and firewalls actually honor.
The critical concept is:
DSCP marking does not create bandwidth.
It identifies traffic so network equipment can give that traffic preferential treatment when congestion exists.
Also remember:
DSCP markings normally do not survive the public Internet.
QoS is therefore most useful inside the network you control.
For SIP ALG, do not blindly enable a firewall's SIP transformation features simply because Zoom Phone uses SIP. SIP ALG, SIP Helper, VoIP inspection, SIP transformation, and similar features can alter signaling or media behavior. Zoom's technical guidance identifies SIP ALG interference as a potential source of desk phone problems. If one way audio, registration failures, transfers, or other SIP related symptoms appear, include SIP ALG and related VoIP inspection in the troubleshooting path.
Firewall vendors change firmware, menus, defaults, and VoIP inspection behavior. Zoom also changes IP ranges and service requirements. Use this article as an architecture and troubleshooting guide, then verify the current Zoom first party firewall documentation and the current documentation for your firewall platform before changing production policy.
------------------------------------------------------------------------
SIP ALG: what it is and why it breaks calls
What Is SIP ALG?
SIP ALG means Session Initiation Protocol Application Layer Gateway.
A traditional SIP ALG attempts to understand SIP signaling as it passes through a firewall or router.
Depending on the product, it may:
- Inspect SIP messages
- Rewrite IP addresses
- Rewrite ports
- Modify SDP
- Create dynamic media pinholes
- Track SIP sessions
- Alter NAT behavior
This was historically intended to help SIP systems traverse NAT.
The problem is that modern cloud communications platforms already have sophisticated mechanisms for handling signaling, media, encryption, NAT traversal, and session establishment.
An intermediary that modifies traffic can sometimes make things worse instead of better.
------------------------------------------------------------------------
Is SIP ALG the Same on Every Firewall?
No.
This is extremely important.
Different vendors use terms such as:
- SIP ALG
- SIP Helper
- SIP Transformations
- VoIP Inspection
- SIP Inspection
- SIP Application Gateway
- SIP Session Helper
- VoIP Profile
The implementation also differs by firmware version.
Therefore, a statement such as:
"Disable SIP ALG."
is incomplete unless you know:
- Which firewall
- Which firmware
- Which inspection engine
- Which SIP helper functions are active
- Whether an SBC is present
- Whether the policy actually traverses that inspection
------------------------------------------------------------------------
Should I Disable SIP ALG for Zoom Phone?
Treat SIP ALG as a specific inspection item to verify, not as a universal button to change without testing.
Zoom's technical library identifies SIP ALG interference among common causes of desk phone issues.
In practical troubleshooting, if Zoom Phone experiences symptoms such as:
- One way audio
- Registration failures
- Calls that connect but have no media
- Transfer failures
- Inbound calls behaving differently from outbound calls
- Calls dropping after a predictable interval
- Desk phones failing while the Zoom Workplace app works
inspect SIP ALG, SIP Helper, and related VoIP inspection behavior.
If those functions are modifying Zoom Phone signaling or media unexpectedly, the appropriate remedy may be to bypass or disable that processing for the relevant traffic.
Always document the existing setting before changing it.
------------------------------------------------------------------------
Why Can SIP ALG Cause One Way Audio?
A phone call has signaling and media components.
The call can successfully establish while the media path is wrong.
For example:
SIP signaling succeeds
→ phone rings
→ user answers
→ call shows connected
but:
Media path fails in one direction
→ one person hears audio
→ the other hears silence
If a firewall rewrites signaling or media information incorrectly, the endpoints can establish the call while sending media to the wrong destination or through an invalid path.
That is why:
"The call connects"
does not prove the firewall is handling the media correctly.
------------------------------------------------------------------------
Signaling versus media
What Is the Difference Between SIP Signaling and Voice Media?
Think of a phone call as two conversations.
Signaling
Signaling establishes and controls the call.
It handles events such as:
- Registration
- Call setup
- Ringing
- Answer
- Hold
- Transfer
- Disconnect
Media
Media carries the actual conversation.
That includes the audio packets flowing between endpoints and the Zoom Phone service.
A firewall can allow signaling while blocking or mishandling media.
That creates classic symptoms such as:
Phone rings but no audio
or:
Audio works only one direction
------------------------------------------------------------------------
Is RTP the Same as SIP?
No.
SIP is associated with call signaling.
RTP is associated with real time media transport.
Zoom Phone also uses secure media technologies, so administrators should follow Zoom's current service specific firewall requirements rather than building policies from generic SIP assumptions.
------------------------------------------------------------------------
Firewall rules: what Zoom Phone actually needs
Should I Open SIP Port 5060 to the Entire Internet?
No.
Do not build Zoom Phone firewall policy from generic VoIP folklore.
Use Zoom's current Zoom Phone firewall rules.
Zoom publishes service specific protocols, ports, and destination ranges.
Those requirements should be the authoritative starting point.
A rule such as:
Allow UDP 5060 from anywhere
is not a responsible substitute for Zoom's documented requirements.
------------------------------------------------------------------------
Should I Port Forward SIP to Every Desk Phone?
No.
A normal cloud Zoom Phone deployment should not be treated like an old on premises PBX where administrators expose individual phones to unsolicited Internet SIP traffic.
Follow Zoom's documented outbound and return connection model.
Do not create inbound port forwards to phones simply because someone says "VoIP needs SIP ports."
------------------------------------------------------------------------
What Firewall Rules Does Zoom Phone Need?
Zoom maintains a dedicated section in its network firewall documentation for Zoom Phone.
The exact ports and destination IP ranges can change.
Therefore, the correct procedure is:
- Open Zoom's current firewall documentation
- Locate the Zoom Phone section
- Identify the endpoint type
- Identify signaling requirements
- Identify media requirements
- Identify provisioning and supporting services
- Apply the rules to outbound traffic as documented
- Permit the associated return traffic
- Document the rule
- Monitor Zoom for IP range updates
Do not copy a five year old port list from a blog into a production firewall.
------------------------------------------------------------------------
Why Should I Avoid Hard Coding an Old Zoom IP List?
Cloud infrastructure changes.
Zoom explicitly notes that its firewall article contains current IP ranges and directs customers to Zoom Status for planned IP address updates.
A firewall rule that worked last year can become incomplete later.
For restrictive environments, build a process for reviewing Zoom network changes.
------------------------------------------------------------------------
Does Zoom Phone Work Through a Web Proxy?
Do not assume the normal Zoom proxy behavior applies to Phone.
Zoom's general firewall documentation specifically notes that its HTTPS/SSL proxy support statement does not apply to the Zoom Phone service.
That distinction is easy to miss.
If your organization requires authenticated proxy traversal for Internet traffic, test the Zoom Phone architecture carefully rather than assuming the desktop application's web connectivity proves Phone media will work.
------------------------------------------------------------------------
QoS and DSCP: the basics
What Is QoS?
QoS means Quality of Service.
It is a set of network mechanisms used to classify and prioritize traffic.
Voice is highly sensitive to:
- Delay
- Jitter
- Packet loss
- Congestion
A large file download can tolerate a short delay.
A human conversation cannot.
QoS lets network devices treat those traffic types differently.
------------------------------------------------------------------------
What Is DSCP?
DSCP means Differentiated Services Code Point.
It is a marking in an IP packet that can be used by network equipment to classify traffic.
Think of DSCP as a label.
The label says:
"This packet belongs to this traffic class."
The switch, router, firewall, or wireless system then decides what treatment that class receives.
------------------------------------------------------------------------
Which DSCP values to use, and where 56 and 40 came from
What DSCP Values Does Zoom Phone Use?
There are two different answers circulating, and conflating them is how QoS designs go wrong.
What Zoom recommends is on Zoom's own Zoom Phone Bluepaper network configuration page:
- EF / 46 for real-time telephony media
- CS3 / 24 for signaling
Those are the values in both the four-queue and the twelve-queue models Zoom publishes. They are also the values a traditional enterprise voice design already uses, which means Zoom Phone slots into most existing QoS policies without argument.
Where 56 and 40 come from is a different question. Zoom's "Implementing Quality of Service for Zoom Phone" article documents that the Windows Zoom Workplace client assigns markings through the Windows native API:
the Zoom Workplace app utilizes the Windows native API to assign the following DSCP markings: 56 for Zoom Phone media, 40 for Zoom Phone signaling
Read where that sentence lives: it is in the Windows section, and it describes what a Windows client marks when nothing overrides it. It is a client-side behaviour, not a Zoom Phone platform default, and it is precisely why Windows needs a Group Policy or PowerShell QoS policy to bring it into line with an enterprise design.
Zoom allows administrators to configure the values. The important requirement is consistency: if Zoom marks media one way and the network expects another, the intended QoS policy does not work.
------------------------------------------------------------------------
Is DSCP 56 the Same as EF 46?
No — and the difference is not academic. Run the arithmetic before you build a policy on either number.
DSCP values map to classes in blocks of eight:
- DSCP 46 is EF, Expedited Forwarding. This is the standard class for voice bearer traffic, and it is what Zoom recommends for Zoom Phone media.
- DSCP 56 is CS7. CS7 is the network control class — reserved for routing protocol traffic.
- DSCP 40 is CS5, not CS3. CS5 is broadcast video in the standard model. Signaling belongs in CS3 / 24.
CS7 is the one class you least want voice sitting in. On most switches an access port is untrusted by default, and CS7 arriving from a user device is re-marked to zero or dropped at the trust boundary — because a user device is not supposed to be originating network control traffic. An administrator who marks Zoom Phone media 56 and then builds a switch policy around it has done real work to place voice in a class the network is configured to strip.
So the rule is not:
"Voice always equals 46."
And it is certainly not "voice equals 56 because a Windows client marks it that way." The rule is:
Choose a QoS model, configure Zoom to match it, and make the network honor that model end to end.
If your organisation already has an enterprise QoS standard, align Zoom to that standard. If it does not, Zoom's own EF/46 and CS3/24 recommendation is the sane starting point, because it is what the rest of the industry's default configurations already expect.
------------------------------------------------------------------------
Can I Change the Zoom Phone DSCP Values?
Yes.
Zoom allows administrators to configure media and signaling DSCP values for Zoom Phone.
That is useful when the organization already has an established enterprise QoS model.
For example, if the network standard uses:
Voice media → DSCP 46
the Zoom Phone configuration can be aligned with that architecture when appropriate.
------------------------------------------------------------------------
Enabling QoS, and what enabling it does not do
Where Do I Enable Zoom Phone QoS?
Zoom currently documents the account level path as:
Account Management
→ Account Settings
→ Zoom Phone
→ General
→ Enable QoS with DSCP marking
The administrator can then configure the media and signaling values.
After enabling QoS, certified desk phones may need to be resynced.
Verify the current Zoom administrative interface because menus can change.
------------------------------------------------------------------------
Does Enabling QoS in Zoom Automatically Prioritize Calls?
No.
This is one of the biggest misconceptions.
Enabling DSCP marking in Zoom tells the endpoint to mark packets.
Your network must still:
- Preserve the marking
- Trust or remark it appropriately
- Classify the traffic
- Place it in the intended queue
- Give that queue the intended scheduling behavior
- Avoid stripping the marking downstream
QoS is an end to end design inside the network you control.
------------------------------------------------------------------------
What Does "Trust DSCP" Mean?
A switch or network device can decide whether it trusts the DSCP marking received from an endpoint.
If the network does not trust the endpoint, it may:
- Remove the marking
- Replace it
- Reclassify the traffic
- Assign a default class
This can be desirable for security because otherwise any endpoint could mark all of its traffic as high priority.
A mature QoS design defines where classification and trust occur.
------------------------------------------------------------------------
Should I Trust DSCP From Every User Device?
Usually not without a policy.
If every endpoint can mark arbitrary traffic as highest priority, QoS loses meaning.
Common strategies include:
- Trust known voice devices
- Classify by application
- Classify by port or source range
- Remark at the access switch
- Apply endpoint policy through management
- Reclassify at the firewall
The correct approach depends on the environment.
------------------------------------------------------------------------
Platform differences: Windows, macOS, mobile and desk phones
Does Zoom Phone QoS Work on Windows?
Yes, but Windows requires special consideration.
Zoom documents that Windows does not normally permit the Zoom Workplace app to configure DSCP markings on outgoing traffic without the required privileges.
Zoom identifies several options, including:
- Running Zoom Workplace with administrative privileges
- Windows PowerShell QoS policy
- Windows Group Policy QoS
This is also the reason the 56 and 40 values exist at all: absent one of those policies, the Windows client falls back to marking media 56 and signaling 40 through the native API. A Group Policy or PowerShell QoS policy is how you replace those with the values your network actually honours.
For managed enterprise environments, Group Policy or PowerShell policy is generally more operationally realistic than asking users to run Zoom as administrator every day.
------------------------------------------------------------------------
Does Zoom Phone QoS Work on macOS and Mobile Devices?
Zoom documents that non Windows Zoom Workplace clients, including supported mobile platforms and macOS/Linux, can apply the DSCP values configured in the Zoom admin portal, subject to the environment.
Network infrastructure must still preserve and honor those markings.
------------------------------------------------------------------------
Does QoS Work on Zoom Phone Desk Phones?
Zoom supports DSCP marking on certified desk phones that support the functionality.
Zoom can push defined DSCP values to supported certified devices.
For desk phones, verify:
- Model support
- Firmware
- Zoom certification
- Provisioning
- Device specific source port behavior
- Switch trust policy
------------------------------------------------------------------------
Do I Need to Resync Desk Phones After Enabling QoS?
Zoom's current QoS workflow provides an option to resync certified desk phones after QoS is enabled.
If a phone is expected to receive updated provisioning values, verify that the device has successfully resynced before testing packet markings.
------------------------------------------------------------------------
Verifying it works, and what happens at the WAN edge
How Do I Verify DSCP Is Actually Working?
Capture packets.
Do not rely solely on the admin portal.
A proper validation can include packet captures at multiple points:
Endpoint
→ Access switch
→ Distribution layer
→ Firewall
Verify:
- The endpoint marks the packet
- The switch preserves or intentionally remarks it
- The packet enters the expected queue
- The marking survives internal routing
- The edge treats the traffic as designed
If the marking disappears between two points, you have found the trust or remark boundary.
------------------------------------------------------------------------
Does DSCP Work Across the Public Internet?
Usually not in a way you can depend on.
Zoom explicitly notes that DSCP markings are typically not preserved once traffic leaves the customer's network and enters the public Internet.
Internet traffic is generally handled as best effort.
Therefore, QoS can protect Zoom Phone traffic from congestion on:
- LAN uplinks
- WAN links you control
- SD WAN
- Internal routed networks
- Wireless infrastructure
- Customer edge links
It cannot force the public Internet to prioritize your call.
------------------------------------------------------------------------
Why Configure QoS if the Internet Ignores It?
Because congestion often happens before the packet reaches the Internet.
For example:
User starts 5 GB upload
→ office Internet uplink saturates
→ voice packets wait behind bulk traffic
→ caller hears delay, jitter, or loss
QoS on the customer edge can prioritize voice before the packet enters the Internet.
That can make a major difference.
------------------------------------------------------------------------
Can QoS Fix a Bad Internet Circuit?
No.
QoS manages contention.
It does not repair:
- ISP packet loss
- High Internet latency
- Broken WiFi
- Bad cabling
- Duplex issues
- Failing firewall
- Saturated provider backbone
- Poor cellular signal
- Routing instability
If the circuit itself is bad, QoS cannot create a good path.
------------------------------------------------------------------------
Can QoS Create More Bandwidth?
No.
If you have 100 Mbps, DSCP does not turn it into 200 Mbps.
QoS decides which packets receive preferred treatment when demand exceeds available capacity.
------------------------------------------------------------------------
Latency, jitter and packet loss
What Is Latency?
Latency is the time required for traffic to travel between endpoints.
Zoom's current Zoom Phone QoS guidance says round trip delay should not exceed 300 ms for optimal performance.
Lower latency generally produces a more natural conversation.
------------------------------------------------------------------------
What Is Jitter?
Jitter is variation in packet arrival time.
Voice packets should arrive at predictable intervals.
If some arrive quickly and others arrive late, audio can sound:
- Choppy
- Robotic
- Broken
- Distorted
QoS can help when jitter is caused by local congestion, but it cannot correct every source of jitter on the Internet.
------------------------------------------------------------------------
What Is Packet Loss?
Packet loss means packets never reach the destination.
Voice applications can conceal some loss, but excessive loss creates:
- Missing words
- Choppy audio
- Robotic speech
- Dropouts
- Poor call quality
Before blaming Zoom, determine where loss begins.
------------------------------------------------------------------------
Wi-Fi, VPN and split tunnelling
Should Zoom Phone Use WiFi?
It can.
But wireless networks require careful design for real time voice.
Review:
- Signal strength
- Channel utilization
- Interference
- Roaming
- AP density
- Band steering
- Airtime contention
- QoS
- WMM
- Backhaul
- Client drivers
A firewall QoS rule cannot repair an overloaded wireless channel.
------------------------------------------------------------------------
What Is WMM?
WiFi Multimedia, or WMM, provides traffic prioritization mechanisms for wireless networks.
If your Zoom Phone users rely heavily on WiFi, wired QoS alone is incomplete.
The wireless design must also recognize and prioritize real time traffic appropriately.
------------------------------------------------------------------------
What About VPN Users?
VPNs add another layer.
Potential impacts include:
- Additional latency
- Encryption overhead
- Hairpin routing
- Concentrator congestion
- DSCP changes
- MTU issues
Zoom's QoS guidance specifically tells administrators to consider VPN overhead.
If corporate policy permits, architecture that avoids unnecessary media hairpinning can improve real time communications.
------------------------------------------------------------------------
Should Zoom Phone Traffic Be Split Tunneled?
That is an enterprise security and network architecture decision.
Do not change VPN routing solely to improve a speed test.
Evaluate:
- Security requirements
- Compliance
- Identity
- Internet breakout
- Zoom network requirements
- VPN capacity
- User location
- Monitoring requirements
Then test call quality.
------------------------------------------------------------------------
Transport, ports and NAT traversal
Does Zoom Phone Use UDP?
Yes, Zoom Phone uses UDP for real time media in applicable workflows.
Zoom's current QoS documentation states that Zoom Phone on Zoom Workplace desktop and mobile apps uses UDP source ports 9000 through 9999 for outbound traffic in the described configuration.
That can help administrators classify traffic where port based identification is appropriate.
Always verify current documentation before hard coding a production rule.
------------------------------------------------------------------------
Can I Customize Zoom Phone Media Ports?
Zoom supports custom source port configuration in certain endpoint scenarios.
However, this requires careful planning.
Zoom notes that customization availability differs among:
- Zoom Workplace apps
- Zoom Phone Appliances
- Zoom Rooms
- Desk phones
For desk phones, consult the vendor documentation and use provisioning templates where supported.
------------------------------------------------------------------------
What About ICE, STUN, and TURN?
Zoom Phone supports peer to peer media capabilities that can use ICE, STUN, and TURN.
These technologies help determine media paths and NAT traversal.
Zoom notes that when ICE/STUN/TURN is used, client QoS marking behavior and custom media port assumptions have limitations.
In particular, custom media port ranges do not control the ports selected by ICE candidate gathering.
This is another reason not to build a firewall around one simplistic port assumption.
------------------------------------------------------------------------
Designing the policy: priority, bandwidth and shaping
Should I Prioritize Signaling and Media the Same Way?
Not necessarily.
Media and signaling have different traffic characteristics.
Zoom exposes separate DSCP values for:
- Media
- Signaling
The network design can therefore classify them differently.
Media generally has the stronger real time sensitivity.
------------------------------------------------------------------------
Should Voice Get Unlimited Priority?
No.
A priority queue should be engineered.
An incorrectly designed strict priority queue can starve other traffic or behave badly during congestion.
Estimate voice bandwidth and configure reasonable queue behavior.
------------------------------------------------------------------------
How Much Bandwidth Does a Zoom Phone Call Use?
The exact consumption varies with codec, signaling, encryption, endpoint, and call behavior.
Do not size a network from one generic number.
For capacity planning, consider:
Concurrent calls
× Expected per call bandwidth
- Protocol overhead
- Other Zoom traffic
- Normal business traffic
- Growth
Then validate with actual measurements.
------------------------------------------------------------------------
Why Do Calls Become Bad Only at Certain Times of Day?
That strongly suggests contention or path variability.
Look for:
- Backups
- Cloud synchronization
- Security scans
- Large uploads
- Video meetings
- Software deployment
- Guest WiFi
- Camera uploads
- ISP congestion
- SD WAN path changes
Compare Zoom call quality data with WAN utilization at the same timestamp.
------------------------------------------------------------------------
Why Are Calls Bad Only When Someone Uploads a Large File?
That is a classic upstream congestion symptom.
Many business Internet circuits have much less upload capacity than download capacity.
When the upstream becomes saturated, voice packets can queue behind bulk traffic.
QoS and traffic shaping at the edge can help protect real time voice.
------------------------------------------------------------------------
Is Traffic Shaping the Same as DSCP?
No.
DSCP labels traffic.
Traffic shaping controls traffic rates and queue behavior.
They are often used together.
For example:
Zoom Phone packet marked as voice
→ firewall recognizes class
→ traffic shaper places it in priority queue
→ bulk upload receives lower priority during congestion
The DSCP value alone did not create that behavior.
------------------------------------------------------------------------
Where to configure it, by platform
Should I Configure QoS on the Firewall or the Switch?
Potentially both.
QoS should be designed across the points where congestion can occur.
That can include:
- Endpoint
- Access switch
- Wireless AP
- Wireless controller
- Core
- WAN router
- SD WAN appliance
- Firewall
Zoom explicitly recommends an end to end QoS implementation within the controlled network.
Partial QoS can produce unpredictable results.
------------------------------------------------------------------------
What Should I Do on a FortiGate?
For a FortiGate environment, evaluate:
- Current Zoom Phone firewall requirements
- SIP ALG or VoIP inspection
- SIP session helper behavior
- SSL inspection
- Application control
- DNS filtering
- Traffic shaping
- DSCP preservation or remarking
- SD WAN rules
- WAN utilization
- Session logs
Do not paste a CLI command from an old forum post into a production FortiGate without checking the FortiOS version and current Fortinet documentation.
The correct setting can differ by firmware and inspection mode.
------------------------------------------------------------------------
What Should I Do on Meraki?
For a Meraki environment, evaluate:
- Zoom required destinations and ports
- Traffic shaping
- Layer 7 rules
- DSCP tagging or preservation
- WAN utilization
- Uplink bandwidth settings
- MX security policies
- MR wireless QoS
- Voice VLAN configuration
Make sure the configured WAN bandwidth accurately represents the usable circuit capacity if shaping depends on those values.
------------------------------------------------------------------------
What Should I Do on SonicWall?
For a SonicWall environment, evaluate:
- Zoom firewall requirements
- SIP transformations or VoIP settings
- Access rules
- NAT policy
- Bandwidth management
- DSCP behavior
- DPI or security inspection
- WAN saturation
- Packet monitor results
The exact menu names vary by SonicOS release.
------------------------------------------------------------------------
What Should I Do on Ubiquiti?
For a Ubiquiti environment, evaluate:
- Zoom service reachability
- Smart Queues or traffic management
- WAN capacity
- VLANs
- WiFi quality
- Firewall rules
- IDS/IPS behavior
- DSCP handling
- Gateway utilization
Do not enable Smart Queues automatically on every connection. Understand the gateway model, circuit speed, and performance impact.
------------------------------------------------------------------------
What Should I Do on a Home Router?
Home routers are less predictable.
They may include hidden or poorly documented:
- SIP ALG
- Stateful inspection
- QoS
- Security filtering
- Parental controls
- ISP managed firmware
If one remote employee has Zoom Phone trouble while the rest of the company works normally:
- Test the Zoom Workplace app on another network
- Compare wired and WiFi
- Reboot the router
- Check for firmware updates
- Review SIP ALG if accessible
- Review ISP security features
- Test without VPN if policy permits
- Escalate to the ISP if the gateway is provider managed
The goal is to isolate whether the problem follows the user, endpoint, or network.
------------------------------------------------------------------------
Symptom to cause
Why Does Zoom Phone Work on My Hotspot but Not Office WiFi?
That is strong evidence that the Zoom service and endpoint may be functional.
Compare the office network for:
- Firewall policy
- DNS
- SSL inspection
- WiFi interference
- VLAN
- QoS
- NAT
- SIP inspection
- Proxy
- VPN
- Packet loss
Do not reinstall Zoom repeatedly if changing the network makes the problem disappear.
------------------------------------------------------------------------
Why Does the Zoom App Work but the Desk Phone Does Not?
Different endpoint types can use different:
- Provisioning mechanisms
- Firmware
- Source ports
- VLANs
- DNS settings
- Device policies
- SIP behavior
A successful Zoom Workplace call does not prove that a Poly or Yealink phone has the network access it needs.
This is why endpoint type matters during troubleshooting.
------------------------------------------------------------------------
Why Does the Desk Phone Work but the Zoom Workplace App Does Not?
Reverse the logic.
Check:
- Endpoint firewall
- Windows QoS policy
- VPN
- Client version
- Local security software
- User authentication
- Device posture
- WiFi
- Operating system network path
The shared Internet connection may be fine.
------------------------------------------------------------------------
What Causes One Way Audio?
Common investigation areas include:
- Firewall policy
- NAT
- SIP ALG or VoIP inspection
- Media ports
- VPN
- SBC configuration
- Asymmetric routing
- Endpoint firewall
- Network segmentation
- ICE/STUN/TURN behavior
Do not assume one way audio has one universal cause.
------------------------------------------------------------------------
What Causes Choppy Audio?
Investigate:
- Packet loss
- Jitter
- WAN saturation
- WiFi
- ISP quality
- VPN
- CPU utilization
- Firewall overload
- SD WAN path
- QoS
- Cabling
- Duplex or interface errors
Choppy audio is primarily a media quality problem, not automatically a SIP problem.
------------------------------------------------------------------------
What Causes Calls to Drop?
Investigate:
- Internet interruption
- Firewall session behavior
- SIP inspection
- NAT timeout
- WiFi roaming
- VPN changes
- ISP path
- Endpoint connectivity
- SBC behavior
- Device firmware
Record whether calls drop after a repeatable amount of time.
A consistent interval can provide a useful clue.
------------------------------------------------------------------------
What Causes Delayed Audio?
Look for:
- Latency
- VPN hairpinning
- Long Internet path
- Congestion
- WiFi retransmissions
- Firewall processing
- Cellular path
- SD WAN routing
QoS can reduce queuing delay inside your network but cannot remove geographic distance.
------------------------------------------------------------------------
Tools and what to monitor
What Is the Zoom Phone Call Quality Dashboard?
Zoom provides a Call Quality Dashboard to help administrators evaluate Zoom Phone calls.
Use it to correlate user complaints with measurable call data.
Instead of:
"Zoom sounded bad at 2 PM."
capture:
- User
- Call
- Timestamp
- Endpoint
- Network
- Jitter
- Latency
- Packet loss
- Site
- WAN utilization
That turns a subjective complaint into a troubleshooting event.
------------------------------------------------------------------------
What Is the Zoom Network Connectivity Tool?
Zoom provides a Network Connectivity Tool that can help validate connectivity to Zoom services.
Use it as part of the troubleshooting process.
It should complement, not replace:
- Firewall logs
- Packet captures
- Interface statistics
- ISP monitoring
- Endpoint testing
- Zoom call quality data
------------------------------------------------------------------------
What Should I Monitor on the Firewall?
At minimum, monitor:
- WAN utilization
- Packet loss
- Interface errors
- Latency where available
- Session failures
- Denied Zoom traffic
- CPU
- Memory
- SD WAN path changes
- ISP availability
If you only look at the firewall after the user complains, you may miss the event.
Historical monitoring is valuable.
------------------------------------------------------------------------
What Should I Monitor on the Switch?
Review:
- Port errors
- Drops
- Duplex
- Speed
- PoE
- VLAN
- Queue drops
- Interface utilization
- Link flaps
A voice quality problem can begin several devices before the firewall.
------------------------------------------------------------------------
What Should I Monitor on WiFi?
Review:
- RSSI
- SNR
- Channel utilization
- Retries
- Roaming
- AP load
- Interference
- Client band
- Packet loss
- Airtime
A perfect firewall cannot compensate for a poor RF environment.
------------------------------------------------------------------------
Triage procedure
How Should I Troubleshoot a Zoom Phone Quality Complaint?
Use this order.
Step 1: Define the Symptom
Is it:
- One way audio?
- No audio?
- Choppy audio?
- Delay?
- Dropped call?
- Registration?
- Transfer failure?
- Provisioning?
Do not call everything "bad quality."
Step 2: Define the Scope
One user?
One site?
One phone model?
All users?
Only WiFi?
Only VPN?
Only inbound calls?
Only call queue calls?
Step 3: Capture the Time
Get the exact timestamp.
Without a timestamp, correlation becomes much harder.
Step 4: Check Zoom Call Quality
Review the relevant call in Zoom.
Step 5: Check WAN and Network Monitoring
Was there congestion, packet loss, or an outage?
Step 6: Check Firewall Logs
Were Zoom flows denied, reset, inspected, or translated unexpectedly?
Step 7: Check SIP ALG and VoIP Inspection
Especially for signaling, registration, transfer, or one way audio symptoms.
Step 8: Check QoS
Are packets marked?
Are markings preserved?
Are queues configured?
Are queues dropping?
Step 9: Isolate the Network
Compare:
- Wired vs WiFi
- Office vs hotspot
- VPN vs permitted non VPN test
- Desk phone vs Zoom Workplace
- One ISP vs another
Step 10: Capture Packets
If the issue persists, packet captures can reveal where signaling or media behavior diverges.
------------------------------------------------------------------------
The 15 Minute Zoom Phone Firewall Triage
Minute 1
Get exact user, site, and timestamp.
Minute 2
Identify endpoint: Zoom Workplace, Poly, Yealink, Zoom Phone Appliance, SBC.
Minute 3
Define symptom: registration, no audio, one way audio, choppy, drop, delay.
Minute 4
Check whether other users are affected.
Minute 5
Check WAN utilization.
Minute 6
Check ISP health and monitoring.
Minute 7
Check Zoom Call Quality Dashboard.
Minute 8
Check firewall denies.
Minute 9
Verify current Zoom Phone firewall requirements.
Minute 10
Review SIP ALG, SIP Helper, or VoIP inspection.
Minute 11
Check VPN and routing.
Minute 12
Check DSCP marking and QoS policy.
Minute 13
Compare another network or endpoint.
Minute 14
Capture logs or packets.
Minute 15
Classify the problem:
Endpoint
or
LAN/WiFi
or
Firewall
or
WAN/ISP
or
Zoom configuration/service
or
SBC/carrier path
That classification is more valuable than another reboot.
------------------------------------------------------------------------
Checklists
Firewall Change Checklist
Before changing a firewall:
- [ ] Current configuration backed up
- [ ] Change window identified
- [ ] Zoom current documentation reviewed
- [ ] Firewall vendor current documentation reviewed
- [ ] Existing SIP ALG state documented
- [ ] Existing VoIP inspection state documented
- [ ] Existing NAT behavior documented
- [ ] Existing QoS policy documented
- [ ] Existing DSCP behavior documented
- [ ] Rollback plan created
- [ ] Test call plan created
- [ ] Monitoring open during test
- [ ] Packet capture available if needed
After changing it:
- [ ] Registration tested
- [ ] Inbound call tested
- [ ] Outbound call tested
- [ ] Hold tested
- [ ] Transfer tested
- [ ] Call queue tested
- [ ] Voicemail tested
- [ ] Long duration call tested
- [ ] Media in both directions verified
- [ ] Call quality reviewed
- [ ] Firewall logs reviewed
- [ ] Change documented
------------------------------------------------------------------------
QoS Implementation Checklist
Design
- [ ] WAN capacity measured
- [ ] Upload capacity measured
- [ ] Concurrent call estimate completed
- [ ] Congestion points identified
- [ ] QoS model selected
- [ ] Media DSCP selected
- [ ] Signaling DSCP selected
Zoom
- [ ] Zoom Phone QoS enabled
- [ ] Media marking configured
- [ ] Signaling marking configured
- [ ] Windows behavior reviewed
- [ ] macOS behavior reviewed
- [ ] Mobile behavior reviewed
- [ ] VDI behavior reviewed
- [ ] Desk phone support reviewed
- [ ] Desk phones resynced where required
LAN
- [ ] Access switch trust boundary defined
- [ ] DSCP preservation verified
- [ ] Voice queue configured
- [ ] Queue bandwidth reviewed
- [ ] Wireless QoS reviewed
- [ ] WMM reviewed
- [ ] Core QoS reviewed
Edge
- [ ] Firewall classification reviewed
- [ ] Traffic shaping reviewed
- [ ] DSCP preservation reviewed
- [ ] Upload congestion protected
- [ ] SD WAN policy reviewed
- [ ] VPN policy reviewed
Validation
- [ ] Packet capture confirms marking
- [ ] Marking verified at endpoint
- [ ] Marking verified at switch
- [ ] Marking verified at firewall
- [ ] Queue behavior verified under load
- [ ] Zoom call quality reviewed under load
- [ ] Large upload test performed in controlled environment
- [ ] Results documented
------------------------------------------------------------------------
Frequently asked questions
Should I disable SIP ALG for Zoom Phone?
SIP ALG should be reviewed whenever it can alter Zoom Phone SIP or media behavior. Zoom's technical guidance identifies SIP ALG interference as a potential cause of desk phone issues. Do not change production firewall behavior blindly. Verify the firewall, firmware, traffic path, and symptoms, then bypass or disable interfering VoIP inspection where appropriate.
What DSCP value should Zoom Phone use for voice?
Zoom recommends EF / 46 for real-time telephony media in its Zoom Phone Bluepaper network configuration guidance. The value 56 that circulates widely is what the Windows client marks natively when nothing overrides it, not a platform default, and 56 is CS7, the network control class, which most switches strip at an untrusted edge.
What DSCP value should Zoom Phone use for signaling?
CS3 / 24, per Zoom's Bluepaper guidance. The 40 that circulates is the Windows client's native marking, and 40 is CS5 rather than CS3.
Should Zoom Phone media use DSCP 46?
Yes in most designs. EF / 46 is what Zoom recommends and what most enterprise QoS policies already expect. If your organisation has an established QoS standard that uses something else, align Zoom to that standard instead, and make sure the network honours it end to end.
Does Zoom Phone QoS work over the Internet?
You should not depend on DSCP being preserved across the public Internet. Zoom states that markings are typically lost once traffic leaves the customer's network.
Does QoS increase bandwidth?
No. QoS prioritizes traffic during contention.
Can QoS fix packet loss from my ISP?
Not if the packet loss occurs in the provider network. QoS can help protect traffic from congestion inside the network you control.
Can SIP ALG cause one way audio?
It can be a contributing cause when the firewall alters signaling or media behavior. Include SIP ALG and related VoIP inspection in one way audio troubleshooting.
Should I open port 5060 to the Internet for Zoom Phone?
Do not create generic SIP exposure rules. Use Zoom's current Zoom Phone firewall requirements for the applicable endpoints and service.
Should I port forward to Zoom desk phones?
Normally no. Follow Zoom's documented cloud Phone connectivity model rather than exposing individual phones through generic SIP port forwarding.
Why does my Zoom Phone call connect but have no audio?
Signaling may be succeeding while the media path fails. Check firewall rules, NAT, SIP/VoIP inspection, media reachability, VPN, routing, and endpoint networking.
Why does Zoom Phone work on a hotspot but not the office network?
That strongly suggests the office network path deserves investigation. Check firewall policy, DNS, WiFi, VLANs, inspection, VPN, QoS, and packet loss.
Why does Zoom Phone sound bad when someone uploads a large file?
The upstream Internet circuit may be congested. QoS and traffic shaping can prioritize real time voice before bulk traffic.
Does Windows automatically apply Zoom Phone DSCP?
Windows has additional restrictions. Zoom documents administrative privileges, PowerShell QoS policy, and Group Policy as methods for applying the intended markings.
Can desk phones receive Zoom QoS settings?
Supported certified desk phones can receive DSCP configuration through Zoom. Verify the exact model and current support.
What should I check first for choppy audio?
Check packet loss, jitter, latency, WAN utilization, WiFi quality, VPN path, and ISP performance before changing SIP settings.
What should I check first for one way audio?
Check the media path, firewall policy, NAT, SIP ALG or VoIP inspection, VPN, SBC behavior, and routing. ------------------------------------------------------------------------
Related articles
- Grandstream phones on FortiSwitch: PoE, LLDP-MED and firmware — when the desk phone problem is below SIP entirely.
- BYOC vs BYOP with Zoom Phone — firewall and SBC requirements when you bring your own carrier.
- Firewall monitoring: what to watch — how to see these faults before a user reports them.
- Dual WAN and internet failover monitoring — because no QoS policy survives a circuit that is actually down.
- Zoom topic hub — every live Zoom Phone, E911 and Zoom administration article in one place.
References
Zoom's own documentation. Where this article contradicts a widely repeated figure, the reference is the page that figure actually came from — read the section it sits in.
- Zoom Technical Library — Zoom Phone Bluepaper: network configuration— Zoom's recommended QoS model: EF / 46 for real-time telephony and CS3 / 24 for signaling, in both the four-queue and twelve-queue designs.
- Zoom — Implementing Quality of Service for Zoom Phone— the source of the 56 and 40 figures: "the Zoom Workplace app utilizes the Windows native API to assign the following DSCP markings: 56 for Zoom Phone media, 40 for Zoom Phone signaling." Note the section it sits in.
- Zoom — Managing Zoom Phone QoS with DSCP marking— where the account-level DSCP settings live and how they reach clients and devices.
- Zoom — Using QoS DSCP marking— the general Zoom DSCP behaviour across clients.
- Zoom Technical Library — Quality of Service and network best practices— the wider QoS explainer, including why markings do not survive the public Internet.
- Zoom — Network firewall or proxy server settings for Zoom— the current address ranges and ports. Use this rather than a hard-coded list copied from an older article.
- Zoom — Zoom Phone certified hardware— which desk phones support provisioned DSCP marking.
ADAM Pulse is the network side of a Zoom Phone deployment: SIP inspection off, current address-range rules, and an end-to-end DSCP model the switches actually honour.
Managed Zoom Phone and network services, SDVOSB. We do the firewall and QoS side of a Zoom Phone deployment: SIP inspection audits, current-address-range rule sets rather than stale copies, an end-to-end DSCP model your switches actually honour, and the packet capture when it turns out to be none of those. Support: (888) 989-4872 · support@adampulse.us