Persistent One Way Audio Issues, no RTP packets on Trunk machines
Hello,
I am experiencing consistent one-way audio issues (inbound) with one of my main VOIP providers. It happens about 1 in every 20 calls. The provider says the calls look fine on their end, and every time I've done a network capture on our trunk servers, I can see outbound RTP traffic but I don't see any inbound for the one way audio calls. I suspect it has to do with NAT but we haven't made any changes recently. This started about 2 months ago (coincidentally around the time our firewall management company did a reboot for a security update). It happens sporadically but typically during high activity periods.
Our firewall cpu utilization gets high, about 75% but memory is consistently around 30%. It gets up to about 30,000 sessions during peak activity.
This is a Fortigate 200E running v7.0.14 build0601 (Mature). There are two machines set up in Active Passive configuration.
The main message in the log that stands out to me are these session clash messages due to the policy switching?
Policy 17:
| Policy ID | From | To | Source | Destination | Service | NAT |
| 17 | 192.168.1.1/24 | WAN1 | 192.168.1.0/24 | 0.0.0.0/0 | All | Enabled |
| 44 | WAN1 | 192.168.1.1/24 | 0.0.0.0/0 | vIPs (DNAT) (233.333.111.112 >> 192.168.1.10) | All_ICMP RTP (6000-31000) | Disabled |
Policy 17 has NAT enabled because our firewall provider said it will use vIPs as SNAT, so we have them mapped to use the outgoing interface.
Thank you for any help or advice!
Virtual Domain root
Log Description Session clashed
Protocol 17
Status Clash
| Time | 2024-05-03 07:57:28 |
| euid | 3 |
| epid | 3 |
| dsteuid | 3 |
| dstepid | 3 |
| logver | 700140601 |
| Log ID | 0100020085 |
| Type | event |
| Sub Type | system |
| Old Status | state=04050204 tuple-num=2 policyid=17 dir=0 act=1 hook=4 192.168.1.10:11255->34.278.901.15:49233(233.333.111.112:11255) dir=1 act=2 hook=0 34.278.901.15:49233->233.333.111.112:11255(192.168.1.10:11255) |
| New Status | state=00212204 tuple-num=3 policyid=44 dir=0 act=2 hook=0 34.278.901.15:49233->233.333.111.112:11255(192.168.1.10:11255) dir=1 act=1 hook=4 192.168.1.10:11255->34.278.901.15:49233(233.333.111.112:11255) dir=0 act=0 hook=4 34.278.901.15:49233->192.168.1.10:11255(0.0.0.0:0) |
| Log event original timestamp | 1714741048542189000 |
