Protect SIP on Fortigate 5.4.3
Hi everyone,
I am hoping that someone has hit this issue before.
We have an Avaya telephony system on our premise on which we have 2 SIP trunks from one SIP provider.
We configured a VIP with the required ports DNat-ed to the telephony system
We've created firewall rules to only accept traffic on that VIP from a few ip addreses of our SIP provider and to only send replies to the provider.
Still, we receive a lot of SIP login attempts from bots, and on the telephony system i keep getting authentication attempts from multiple IP's
With our former router (without UTM/NGFW) we just created a simple rule and we never had this issue with a simple statefull inspection firewall.
Can anyone point me in the right direction? Our SIP's are in use 24/7 so it is hard to just randomly test to disable SIp-helper, than SIP-ALG, etc sicne that will disrupt traffic and cause a lot of issues.
We had a case opened for this and the support reply was that it is not possible, since even if we specify a firewall rule on our VIP, the port will still be listening and reply on the internet
I am really hoping that someone can point me in the right direction.
Thank you
