PROBLEM SOLVED: SIP connection
I have a Grandstream UCM PBX that is behind my fortigate 100D. my local network is 10.15.20.x and my PBX wan port is 10.15.20.249. My gateway is configured with 69.231.225.154/29 with 69.231.225.154 my default IP.
I have a VIP labeled as [style="background-color: #00ccff;"]OffsitePhone[/style]: 69.231.225.157 -->10.15.20.249 port 5060
My policy ID 60 is configure to accept incoming traffic from specific IP Address from the WAN1 port TO internal [style="background-color: #00ccff;"]OffsitePhone[style="background-color: #ffffff;"] I also set the service type to SIP. I know this doesn't matter because of the VIP map with port... but I still set it.[/style][/style]
[style="background-color: #00ccff;"][style="background-color: #ffffff;"]I am running into a few problems.[/style][/style]
[style="background-color: #00ccff;"][style="background-color: #ffffff;"]1. The policy doesn't seem to prevent others from accessing the UCM on port 5060. As a result of this, I had to turn on the UCM firewall.[/style][/style]
[style="background-color: #00ccff;"][style="background-color: #ffffff;"]2. The connection works for some users and not for others. [/style][/style]
after reviewing the logs. I can see the packets coming through to the [style="background-color: #00ccff;"]OffsitePhone[/style] policy to the 10.15.20.249. However, the packets from the 10.15.20.249 IP is going to the private ip address of the user's network. It is suppose to go to the user's gateway public ip. I don't understand why it works for some users and not for others...