Fortinet black logo

FortiVoice Cookbook

Configuring FortiFone softclient for mobile settings on FortiVoice

Configuring FortiFone softclient for mobile settings on FortiVoice

Perform the following procedures to configure FortiFone softclient for mobile settings on the FortiVoice phone system:

Note

Prior to starting the configuration, make sure to complete the recipes in Licensing.

Note

Unless otherwise specified, steps in this FortiFone softclient section apply to SIP over TCP, UDP, and TLS.

Configure external access settings

  1. On FortiVoice, go to System > Advanced > External Access.
  2. Set SIP server external hostname/IP address to the IP address or FQDN of the FortiVoice device and configure the following external access ports.
  3. Go to System > Advanced > SIP.
  4. Under Advanced Setting, make sure that SIP session helper is disabled.

Configure a SIP profile

FortiVoice includes a default SIP profile (sip_mobile_fortifone_default). If your deployment uses SIP over TCP, then you can use this default profile, and skip this procedure.

If your deployment requires SIP over UDP or TLS, then you can create a new SIP profile.

  1. On FortiVoice, go to Phone System > Profile > SIP.
  2. Click New > Mobile.
  3. In Name, enter a name for this SIP profile.
  4. Select a DTMF setting.
  5. Enable NAT.
  6. In Transport, select the protocol. If you select TLS, then enable Secure RTP.
  7. Click Create.

    Example for configuring a SIP profile for UDP:

    Example for configuring a SIP profile for TLS:

Assign the FortiFone softclient to a FortiVoice extension

  1. On FortiVoice, go to Extension > Extension > IP Extension and click New.
  2. Enter a Number.
  3. Under Device Setting, click the Soft FortiPhone tab.
  4. In License allocation, specify the value to configure.
  5. In Android/iOS, leave the default profile (sip_mobile_fortifone_default) or select the profile that you configured in Configure a SIP profile.
  6. Click Create.
  7. If your deployment uses SIP over TLS, go to Export the FortiVoice server certificate for SIP over TLS.

    If your deployment uses SIP over TCP or UDP, go to Configuring FortiGate for SIP over TCP or UDP.

Export the FortiVoice server certificate for SIP over TLS

  1. On FortiVoice, go to System > Certificate > Local Certificate.
  2. In the list, select FortiVoiceSIPServer. This is the default certificate for the SIP service. If you are using a custom certificate, select that one instead of the default.

  3. Click Download and select Download PKCS12 File.

    The PKCS12 Certificate Download dialog opens.

  4. In Password and Confirm password, enter a password to encrypt the key.
  5. To download the file, click OK.
  6. To save the file locally, click OK.
  7. Take note of the location where you save the file.
  8. Go to Configuring FortiGate for SIP over TLS.

Configuring FortiFone softclient for mobile settings on FortiVoice

Configuring FortiFone softclient for mobile settings on FortiVoice

Perform the following procedures to configure FortiFone softclient for mobile settings on the FortiVoice phone system:

Note

Prior to starting the configuration, make sure to complete the recipes in Licensing.

Note

Unless otherwise specified, steps in this FortiFone softclient section apply to SIP over TCP, UDP, and TLS.

Configure external access settings

  1. On FortiVoice, go to System > Advanced > External Access.
  2. Set SIP server external hostname/IP address to the IP address or FQDN of the FortiVoice device and configure the following external access ports.
  3. Go to System > Advanced > SIP.
  4. Under Advanced Setting, make sure that SIP session helper is disabled.

Configure a SIP profile

FortiVoice includes a default SIP profile (sip_mobile_fortifone_default). If your deployment uses SIP over TCP, then you can use this default profile, and skip this procedure.

If your deployment requires SIP over UDP or TLS, then you can create a new SIP profile.

  1. On FortiVoice, go to Phone System > Profile > SIP.
  2. Click New > Mobile.
  3. In Name, enter a name for this SIP profile.
  4. Select a DTMF setting.
  5. Enable NAT.
  6. In Transport, select the protocol. If you select TLS, then enable Secure RTP.
  7. Click Create.

    Example for configuring a SIP profile for UDP:

    Example for configuring a SIP profile for TLS:

Assign the FortiFone softclient to a FortiVoice extension

  1. On FortiVoice, go to Extension > Extension > IP Extension and click New.
  2. Enter a Number.
  3. Under Device Setting, click the Soft FortiPhone tab.
  4. In License allocation, specify the value to configure.
  5. In Android/iOS, leave the default profile (sip_mobile_fortifone_default) or select the profile that you configured in Configure a SIP profile.
  6. Click Create.
  7. If your deployment uses SIP over TLS, go to Export the FortiVoice server certificate for SIP over TLS.

    If your deployment uses SIP over TCP or UDP, go to Configuring FortiGate for SIP over TCP or UDP.

Export the FortiVoice server certificate for SIP over TLS

  1. On FortiVoice, go to System > Certificate > Local Certificate.
  2. In the list, select FortiVoiceSIPServer. This is the default certificate for the SIP service. If you are using a custom certificate, select that one instead of the default.

  3. Click Download and select Download PKCS12 File.

    The PKCS12 Certificate Download dialog opens.

  4. In Password and Confirm password, enter a password to encrypt the key.
  5. To download the file, click OK.
  6. To save the file locally, click OK.
  7. Take note of the location where you save the file.
  8. Go to Configuring FortiGate for SIP over TLS.