Skip to main content
RolandBaumgaertner72
New Member
November 7, 2022
Question

VoiP Packet Loss

  • November 7, 2022
  • 20 replies
  • 10236 views

Hello,

 

this is new, like for one week we have problems with voip in our central FG 300D cluster. From other offices with other FGs we didnt get any reports of problems while calling.

 

First we tried to route the traffic with another route and internet access but we got the same problems. Capturing with Wireshark the connections we didnt see any package loss but our provider sent us some package loss samples where there are like 8% package loss.

 

We didnt change anything in the FG policies so we really dont know what can cause the problem. Since we only have it on our central FW, it seems that the problem is there.

 

Any suggestions?

 

Thanks!

 

20 replies

distillednetwork
Explorer II
November 7, 2022

You could run a packet capture on the ingress and the egress (internal and external) interfaces of your FG300D and see if you can identify any packet loss on either interface.  If it's on both, then the problem is between the VoIP client and the firewall.  If are you losing packets on the egress but not the ingress then you may have an issue with packets being dropped in the fortigate.

RolandBaumgaertner72
New Member
November 7, 2022

Hi,

 

thanks...still completely in the dark. We never had problems with these conections and also we dont have issues in the other FGs offices.

 

> checked the interfaces and they are all OK (diag hardware deviceinfo nic portX)

> checked if SIP ALG is on (diag sys sip status) but I dont get why it should affect now.

> we did package capture from the host to the FG via the MPLS (we got like 2% Package loss)

> we did package capture from WAN port to the Voip IP (we did not get pakacge loss but the provider sent us data with 8% package loss from his WAN to our public IP.

 

So we are not sure if the problem is with micro disconnections on the MPLS conection from all small office to the FG300D Cluster.

 

What else can we try? Disable SIP ALG (can we do it without starting all sessions new? Could it affect all the telefon traffic?)

 

Thanks again!

gfleming
Staff
Staff
November 7, 2022

SIP ALG will not cause packet loss.

 

If you are having packet loss even after switching your ISP paths.

 

If your provider is showing packet loss but you yourself are not seeing any on two different links then the problem exists upstream either at your provider or an intermediary.

RolandBaumgaertner72
New Member
November 17, 2022

Hi,

 

checking in Fortiview in this policy we see these failed connections:

RolandBaumgaertner72_0-1668691964621.png

 

Session ID 231092761
Virtual Domain root

Source
IP 128.1.38.161
Source Port 11793
Source Interface port6

Destination
IP 185.130.155.165
Host Name sipcc5.meetip.net
Port 17989
Destination Interface port7

Application
Application Name UDP/17989
Category unscanned
Protocol udp
Service udp/17989

Action
Action ip-conn
Threat 262144
Policy 112
Policy UUID 910398d0-4378-51ea-3d36-4785cd1d9e9b
Policy Type policy

Security
Level
Threat Level low
Threat Score 5
Threat Type Failed Connection

Other
Source Interface Role undefined
Destination Interface Role wan
Protocol Number 17
roll 48663
Log event original timestamp 1668691794
Threat Level Low
Event failed-connection
Log ID 11
Sub Type forward
Security Events []

 

gfleming
Staff
Staff
November 17, 2022

That looks like UDP RTP/RTPC traffic from your internal hosts to your VOIP provider. Why its being blocked we don't know. It could be stale connections. It could be something else. The fact that VOIP calls do work most of the time leads me to believe you don't have an overall problem with SIP/RTP traffic getting past the FGT. Your issue is that calls work but sometimes during the call the audio drops out, correct?

 

Do you have NAT enabled on your internet-facing (or MPLS-facing) traffic policies? Is the VOIP traffic being NATted at all?

 

What version of FortiOS are you running?

RolandBaumgaertner72
New Member
November 17, 2022

Hi,

 

FG300 cluster with 6.0.5 (I know it is a bit old but we hace to update this cluster soon beeing there in the data center).

 

Yes we have NAT in the policy to the Voip provider, without NAT it would not work (we tried).

 

Thanks

gfleming
Staff
Staff
November 18, 2022

Can you confirm you exact issue? My understanding is that calls connect and work for the most part but during the call sometimes users lose audio. Can you clarify if that's not correct?

RolandBaumgaertner72
New Member
November 21, 2022

Hi,

 

yes, most of the time we get problems communicated from the offices around 11-13PM. They get calls and than for like 3-6 seconds they dont hear the other person. After that it works fine.

 

We dont see any high peaks in either line (MPLS and both Internet Access). The provider is checking the lines but sofar he didnt find anything. The Voip provider just sent us again his statistics where he can confirm like 3% lost in RTP Streams (the same result we got from our capturing on the FG - but again like doing 9 of 10 captures are 100% fine).

 

Right now we are waiting for the answers from the provider about the lines.

 

Thanks!

 

 

RolandBaumgaertner72
New Member
November 22, 2022

Hi,

 

we have like 90-95% inbound (some call centers) and again, it happens usually in the morning (there should not be more traffic). Also it can happen in one office, that it affects like 1 user and other 4 users dont have a problem during the day. I really dont know if it happens at the beginning or in the middle of the call.

 

Any idea what we can do/try from the Fortigate side? 

 

Thanks!

 

gfleming
Staff
Staff
November 22, 2022

Can you find out those details from the users? Understanding the exact symptoms of the problem is key to troubleshooting.

BellamyDustin
New Member
December 5, 2022
Here is some steps you can apply to troubleshoot this problem
  1. Reboot Devices. Rebooting is a very simple technique yet people don't seem to do it right away. 
  2. Monitor VoIP Packet Loss. 
  3. Update/Upgrade Software. 
  4. Replace old/damaged hardware. 
  5. Apply QoS solution. 
  6. Increase Network Bandwidth. 
  7. Examine Physical Connections.

Thanks

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!