Skip to main content
New Contributor III
May 11, 2010
Question

Port 5060

  • May 11, 2010
  • 3 replies
  • 3255 views
Hello, we' re configuring SIP in a fortigate 60b v4.0,build0194,100121 (MR1 Patch 3). In virtual ip we create the group to port forward to the central 5060 tcp/udp 5090 tcp/udp 9000-9015 tcp/udp We test in the VOIP central the ports and all of them pass except 5060. <14:48:55>: UDP SIP Port is set to 5060. Response received WITH TRANSLATION 54082::5060. Phase 2a check passed with WARNINGS. Some functionality will be LIMITED. For more information, please visit http://www.3cx.com/support/firewall-checker.html <14:48:55>: Phase 2b. Check Port Forwarding to TCP SIP port, please wait... <14:48:55>: TCP SIP Port is set to 5060. Response received WITH TRANSLATION 54082::5060. Phase 2b check passed with WARNINGS. Some functionality will be LIMITED. For more information, please visit http://www.3cx.com/support/firewall-checker.html <14:48:55>: Phase 3. Check Port Forwarding to TCP Tunnel port, please wait... <14:48:55>: TCP TUNNEL Port is set to 5090. Response received correctly with no translation. Phase 3 check passed. We add a policy route wan --> internal Source Interface/Zone wan1 Source Address all Destination Interface/Zone internal Destination Address all Schedule always Service SIP Action ACCEPT NAT cheked I' m missing something. I' m doing this all wrong? Any ideas? Thanks in advance. Regards

    3 replies

    ddskier
    New Member
    May 12, 2010
    Do I quick search for SIP-ALG. You will see a bunch of posts on how to get this working.
    New Contributor III
    May 12, 2010
    That' s true, but everything I tried didn' t work out. All ports pass but 5060 doesn' t and I didn' t understand why. It might be something I' m doing wrong or I' m missing. As did the following 1) delete everything I had to do with 3CX 2) restart the forti unit 3) addall ports again 4) I made a policy WAN1 -> internal with virtual ip ports + SIP service and nothing else Now the ports passed. But I have no logs, where I fixed that? Because the policy is enabled, allow traffic log Thanks for the answer. Regards
    ddskier
    New Member
    May 20, 2010
    Did you follow the SIP-ALG posts. 1. Disabled SIP Helper 2. Created a SIP Application Control 3. Created a protection profile that used that Application Control 4. Set the protection profile on the policy for the VIP 5060 access?