Changing the default external access ports
SIP communication commonly uses TCP or UDP port 5060 and/or 5061. Port 5060 is used for nonencrypted SIP signaling sessions and port 5061 is typically used for SIP sessions encrypted with Transport Layer Security (TLS).
![]() |
Avoid changing any of the protocol ports to four digit numbers, such as 5065 or 5070, as those are used by other brands and are commonly scanned port numbers. |
- Go to System > Advanced > External Access.
- You have the option to change the following SIP transport protocol ports:
- UDP: This is the default signaling port used for external extensions, VoIP trunking, and office peers. Choose a five digit number.
- TCP: This is the default signaling port used for the FortiFone softclient. Choose a five digit number.
- TLS: This is the default port for SIP sessions encrypted with Transport Layer Security (TLS). Choose a five digit number.
- WSS: WebSocket Secure is used to support the FortiFone desktop application. Choose a five digit number.
- Additionally, you can configure the service external ports. Click Apply when finished.