Skip to main content
Access1denied
New Member
July 30, 2020
Question

PROBLEM SOLVED: SIP connection

  • July 30, 2020
  • 1 reply
  • 12244 views

I have a Grandstream UCM PBX that is behind my fortigate 100D.  my local network is 10.15.20.x and my PBX wan port is 10.15.20.249.  My gateway is configured with 69.231.225.154/29  with 69.231.225.154 my default IP.

 

I have a VIP labeled as [style="background-color: #00ccff;"]OffsitePhone[/style]: 69.231.225.157 -->10.15.20.249 port 5060 

My policy ID 60 is configure to accept incoming traffic from specific IP Address from the WAN1 port TO internal [style="background-color: #00ccff;"]OffsitePhone[style="background-color: #ffffff;"] I also set the service type to SIP.  I know this doesn't matter because of the VIP map with port... but I still set it.[/style][/style]

 

[style="background-color: #00ccff;"][style="background-color: #ffffff;"]I am running into a few problems.[/style][/style]

[style="background-color: #00ccff;"][style="background-color: #ffffff;"]1.  The policy doesn't seem to prevent others from accessing the UCM on port 5060.  As a result of this, I had to turn on the UCM firewall.[/style][/style]

[style="background-color: #00ccff;"][style="background-color: #ffffff;"]2. The connection works for some users and not for others. [/style][/style]

    after reviewing the logs.  I can see the packets coming through to the [style="background-color: #00ccff;"]OffsitePhone[/style] policy to the 10.15.20.249.  However, the packets from the 10.15.20.249 IP is going to the private ip address of the user's network.  It is suppose to go to the user's gateway public ip.  I don't understand why it works for some users and not for others...

    1 reply

    Access1denied
    New Member
    July 31, 2020

    update, I am using Fortigate 60 and I am having the same problem.  The firewall policy doesn't appear to block UDP traffic. This is scary... Am i the only person having this problem.... I have also tried to set the source IP in the VIP policy... but it appears no effect. I am still finding IP address not assigned being able to access my end point.

    TheJaeene
    New Member
    July 31, 2020

    Hi!

     

    Please take a look at :

    https://kb.fortinet.com/kb/documentLink.do?externalID=FD36750

     

    and

     

    https://kb.fortinet.com/kb/documentLink.do?externalID=FD36405

     

    After disabling the SIP ALG you need to create a separate VIP for RTP Traffic with their respective UDP Port Range.

     

     

    Please also note that you need to create a outgoing rule from PBX to WAN with SNAT. (IP-Pool) 69.231.225.157 as the SNAT (not the interface IP as NAT) and place this policy above the general outbound NAT.

     

    Since you are using a VIP with Portforwarding, which is no 1:1 NAT, you need to do that (established traffic will flow correct though)

     

    Greetings,

     

    The Jane

     

    Access1denied
    New Member
    August 1, 2020

    Thank for the reply..

    Is there any way to undo this kb? in the event it doesn't work?  I wasn't sure if the changes is specific to the policy or global?

    https://kb.fortinet.com/kb/documentLink.do?externalID=FD36405