Skip to main content
AEK
SuperUser
SuperUser
February 16, 2025
Solved

SIP and NAT

  • February 16, 2025
  • 5 replies
  • 4300 views

Hi FG admins

 

From this tech tip:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Most-common-cases-of-SIP-implementation/ta-p/190676

 

I have this scenario (phones behind NAT):

 

Did all the required config, and even more:

config system settings
set sip-expectation disable
set sip-nat-trace disable
set default-voip-alg-mode kernel-helper-based
end

config system session-helper
delete 13
end

config voip profile
edit "default"
config sip
set rtp disable
set contact-fixup disable
end
end

...

 

Played with the above parameters and FG reboot but didn't work. I mean I have this behavior:

  • Calling from internal IP phone to external mobile cell phone (GSM): It rings but no voice
  • Calling from internal IP phone to internal IP phone: IP phone doesn't even ring

In the traffic logs I could see some "TCP reset from server" on SIP connections.

So I'm starting to think that probably on server side must be somehow configured to accept calls from IP phones behind NAT. Anyone knows something about that?

Best answer by AEK

Hi BJ & MB

The issue has been fixed by enabling proxy-based inspection mode in the related firewall rule. All worked just fine after that.

Thanks again to both.

5 replies

BJ_Prakash_Ghising
New Member
February 16, 2025

Are you using VOIP profile on firewall policy? If so then SIP traffic is processed by SIP-ALG and you have RTP disabled on your VOIP config which means it will block automatic pinhole creation for SIP traffic.

 

AEK
SuperUser
AEKAuthor
SuperUser
February 16, 2025

Thanks for your feedback.

Tried both, using and without using VoIP profile, but got the same result.

AEK
BJ_Prakash_Ghising
New Member
February 16, 2025

Can you share the system config of your firewall. 

 

sh full system settings

or 

config system settings

sh full

 

You can also verify if traffic is processed by SIP or SIP-ALG

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-confirm-if-FortiGate-is-using-SIP-Session/ta-p/190757?externalID=FD38087

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-verify-if-SIP-traffic-is-being-inspected-by/ta-p/332325

 

MZBZ
Staff
Staff
February 16, 2025

By default, all SIP traffic is processed by the SIP ALG. If the policy that accepts the SIP traffic includes a VoIP profile, the SIP traffic is processed by that profile. If the policy does not include a VoIP profile, the SIP traffic is processed by the SIP ALG using the default VoIP profile.
https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/147933/sip-alg-and-sip-session-helper

 

AEK
SuperUser
AEKAuthorAnswer
SuperUser
February 27, 2025

Hi BJ & MB

The issue has been fixed by enabling proxy-based inspection mode in the related firewall rule. All worked just fine after that.

Thanks again to both.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!