Skip to main content
teccart
New Member
April 17, 2024
Solved

Fortigate SIP translation malefunction

  • April 17, 2024
  • 3 replies
  • 1577 views

Hello dear friends from Fortinet,

Sorry for my tone but I have no normal words.

I spent several nights trying to understand why my Asterisk PBX can't register on SIP provider. So finally I found in captured packets the makings of a failed intellect.

1. PBX sends register packet 

src:int_IP:5060 to dst:SIP_prov_IP:5060

 Message Header

Via: SIP/2.0/UDP ext_IP:5060;branch=z9hG4bK6a3e42f7

 

2. Fortigate translats by NAT ........ BUT!!!!!!......it changes packet's content

src:ext_IP:5060 to dst:SIP_prov_IP:5060

Message Header

Via: SIP/2.0/UDP ext_IP:5170;branch=z9hG4bK6a3e42f7

 

3. Evidently SIP provider response to the fake port presented by Fortigate

src:SIP_prov_IP:5060 to dst:ext_IP:5170

Message Header

Via: SIP/2.0/UDP ext_IP:5170;branch=z9hG4bK6a3e42f7

 

And NOTHING MORE !!!! Because this port in not listen and even is blocked as it is not permitted by policy and therefore this packet doesn't returned to PBX. And the same thing happens with RTP packets!!!

 

I don't understand this half-baked intelligence. How was it tested before sale to end users?!!! Why do I have to pay and then have to be stressed reading thousands forums and manuals?!!!!! Who will pay me more than 20 loused hours of sleepless nights and my life I could passed with my family or my friends?!!!!

 

And I haven’t found any solution for this problem other than disabling all this intelligence.

 

Thank you very much. Hope you will help me briefly.

 

Best answer by AEK

Hi

I'm not a SIP specialist but I know that to avoid SIP headaches we usually disable SIP ALG, You may need to know that Fortinet doesn't recommend to disable SIP ALG while SIP providers usually recommend to disable it.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Disabling-VoIP-Inspection/ta-p/194131

3 replies

AEK
SuperUser
AEKAnswer
SuperUser
April 17, 2024

Hi

I'm not a SIP specialist but I know that to avoid SIP headaches we usually disable SIP ALG, You may need to know that Fortinet doesn't recommend to disable SIP ALG while SIP providers usually recommend to disable it.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Disabling-VoIP-Inspection/ta-p/194131

AEK
teccart
teccartAuthor
New Member
April 23, 2024

Thank you very much.

But! The sad fact is that there are a lot of modern technologies that work well when they are disabled :) ;)

hbac
Staff & Editor
Staff & Editor
April 17, 2024

Hi @teccart,

 

In addition to disabling SIP ALG, you can also enable 'preserve source port' option to prevent source ports from being modified. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-Fixedport-or-Preserve-Source-Port-on/ta-p/195738

 

Regards, 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!