We recently discovered that our UTM was blocking packets that we needed for VoIP.
RTP packets were being discarded because IPS detected a UDP Flood Attack. The issue was difficult to find because the UTM was only discarding a relativly small number of packets. Telephone calls would sound fine for some time, but then the sound would become jumbled or stop. Sporatic problems are always difficult to find, but this was also difficult to detect because the only place this could be seen was in the Intrusion Prevention System logs.
We solved the issue by going to Network Protection | Intrusion Prevention | Exceptions and creating an exception for the appropriate ports, networks and hosts to fit our needs.
I think it might be a help if these events were displayed under Logging & Reporting | Network Protection and included in the Executive Report.
I hope this is a help for others having VoIP quality issues.
This thread was automatically locked due to age.