Skip to main content
W4rh0und
New Member
April 16, 2018
Question

Protect SIP on Fortigate 5.4.3

  • April 16, 2018
  • 0 replies
  • 1537 views

Hi everyone,

 

I am hoping that someone has hit this issue before.

 

We have an Avaya telephony system on our premise on which we have 2 SIP trunks from one SIP provider.

We configured a VIP with the required ports DNat-ed to the telephony system

We've created firewall rules to only accept traffic on that VIP from a few ip addreses of our SIP provider and to only send replies to the provider.

Still, we receive a lot of SIP login attempts from bots, and on the telephony system i keep getting authentication attempts from multiple IP's

 

With our former router (without UTM/NGFW) we just created a simple rule and we never had this issue with a simple statefull inspection firewall.

 

Can anyone point me in the right direction? Our SIP's are in use 24/7 so it is hard to just randomly test to disable SIp-helper, than SIP-ALG, etc sicne that will disrupt traffic and cause a lot of issues.

We had a case opened for this and the support reply was that it is not possible, since even if we specify a firewall rule on our VIP, the port will still be listening and reply on the internet

 

I am really hoping that someone can point me in the right direction.

 

Thank you

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!