Why doesn’t Wi‑Fi calling work on our public and BYOD networks?

0
3
Asked By MellowKite42 On

I work at a rural nonprofit hospital with little to no cellular coverage inside the building. Users are asking why they can't make calls or send texts even when Wi‑Fi calling is enabled and their devices are connected to either the public or BYOD network.

After investigating, it looks like the traffic may be blocked on our Palo Alto firewalls. I'm not sure whether there's a security or compliance reason to block it, especially since some of the calls and messages may be work-related. Could the firewall be preventing Wi‑Fi calling, and are there any healthcare-specific concerns I should consider before allowing it?

3 Answers

Answered By NimbleCactus6 On

Start by confirming the actual cause instead of assuming it’s the firewall. Test multiple carriers and devices, check firewall logs while placing a Wi‑Fi call, and verify that DNS, NAT, and outbound traffic are working normally. Then ask the network or security administrator who introduced the block and whether there’s an approved exception process. Healthcare compliance may be part of the rationale, but it doesn’t automatically mean Wi‑Fi calling has to be blocked if the networks are segmented correctly.

Answered By BrightOwl58 On

This could also be a legacy restriction. Rural sites sometimes had limited bandwidth in the past, so administrators blocked anything considered nonessential and the rule was never revisited. Before changing it, check the available bandwidth and ask whoever originally created the policy why it exists.

QuietHarbor31 -

I’d also be cautious with public and BYOD access in a healthcare environment. Make sure those networks are properly isolated from clinical systems and that enabling the traffic doesn’t create a path around required security or privacy controls.

Answered By CopperLynx7 On

If “PAs” means Palo Alto firewalls, Wi‑Fi calling may be getting blocked because mobile carriers use encrypted VPN-like tunnels for the service. Many organizations block that traffic because it bypasses inspection and could be used to move data through an encrypted connection. You’ll probably need to identify the carrier hostnames and required services, then work with your security team on a narrowly scoped allow rule and document the business justification.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.