UDP traffic issue in Site to Site VPN
Setup: I've got a FG 40C with a VLAN that we have an IP PBX on. 192.168.81.0/24 On the other side of the VPN we have a Juniper SSG 20 with a subnet of 192.168.200.0/24. We've got a couple of SIP phones on the Juniper side that connect back to the IP PBX. This setup was created with the 40C at 5.2.2 and worked great for months. We made no changes on the Juniper, but upgraded the FW on the 40C to 5.2.3 and the phones can no longer register to the PBX. The tunnel is up and passes traffic. What I've done to troubleshoot: TCP, ICMP, and NTP seem to pass just fine since I can connect to web interfaces of varying equipment from both sides and make RDP connections through. In pulling packet captures from the IP PBX I can see the phones getting NTP info from the PBX, but I never see a SIP registration make it to the PBX. Using the packet sniffer from the FG I can see the sip traffic on the VPN Tunnel interface, but I never see it on the VLAN interface. I've tried recreating the policy between the two interfaces, ensuring that all services are passed with no luck. I've verified that routing info is correct on both devices. Has anyone else seen anything similar or have any ideas on further troubleshooting?
