I work at a rural nonprofit hospital where cellular service is weak or nonexistent inside the building. Users are asking why they still can't make calls or send texts when connected to Wi‑Fi calling through our public or BYOD networks. I suspect the traffic may be blocked on our Palo Alto firewalls, but I'm not sure whether there's a security or compliance reason for that policy. Has anyone dealt with this before, and is there a safe way to allow Wi‑Fi calling without creating problems for the hospital network?
3 Answers
There may be a legitimate compliance concern, especially in a healthcare environment. BYOD and guest networks should be isolated from clinical systems, and allowing encrypted tunnels without restrictions can make monitoring and data-loss prevention harder. That doesn’t necessarily mean Wi‑Fi calling must be blocked, but the network team should confirm the segmentation, logging, and acceptable-use requirements before making an exception.
Start by identifying who created the firewall rule and why. Also check the available bandwidth, since a rural connection may have limited capacity. Test on a controlled network while reviewing firewall logs and carrier requirements. If the traffic is being denied, create a narrowly scoped policy for the approved networks and devices, then monitor it for performance and security impact rather than opening the traffic broadly.
Wi‑Fi calling often relies on encrypted VPN-like tunnels, which many firewalls block because they can’t inspect the traffic. Check whether the Palo Alto rules are denying the mobile carriers’ Wi‑Fi calling services. You may be able to allow the required carrier hostnames and protocols specifically on the public and BYOD segments, rather than permitting all tunneling traffic. This will probably need a documented business and security justification.

It could also be an old rule that was created when the site had much slower internet and was never revisited. I’d verify the original reason for the block instead of assuming it is still necessary.