Skip to main content
francoma
New Member
October 25, 2023
Solved

VoIP profile is not visible on Firewall rule

  • October 25, 2023
  • 11 replies
  • 8474 views

Hi All,

 

Hope you can give some light on the following issue which I'm facing with some fortigates, we have some Fortigates 101F, 100F, 60F and 40F, where after update to OS 7.4.1 we are not able to select VoIP profile on firewall rules, before update it was working fine and VoIP service was ok. This is only happeing on 60F and 40F fortigates, on 100F and 101F we are capable to still using VoIP profile on firewall profiles (this is being used on the IPSEC rules created)

 

These are the settings we have on fortigates for VoIP:

config system settings
set sip-expectation enable
set sip-nat-trace disable
set h323-direct-model enable
set default-voip-alg-mode kernel-helper-based
set gui-implicit-policy disable
set gui-voip-profile enable

Currently VoIP service is not operational between remote office due to this, traffic is passing on tunnels but SIP sessions looking not be linked as expected.

Can someone can let kmoe if maybe there is a command to force/reload VoIP profile be visible on firewall rules? Fortigates are operating on profile-based mode

Best answer by Anonymous_User

@francoma If your policy is in flow mode, try changing it to proxy mode and test.

 

Regards.

11 replies

hbac
Staff
Staff
October 25, 2023

Hi @francoma,

 

Can you check under System > Feature Visibility and make sure VoIP is enabled. 

 

Regards, 

francoma
francomaAuthor
New Member
October 25, 2023

Hi hbac,

Thank you for your time and support, yes, it is enabled in the Feature Visibility on all the fortigates.

Voip.png

hbac
Staff
Staff
October 25, 2023

@francoma,

 

Are you able to see VoIP under Security Profiles?

 

Regards,

mle2802
Staff
Staff
October 25, 2023

Hi @francoma,

Can you please refer to this article for more information "https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-apply-VoIP-profile-to-policy-where-no-SIP/ta-p/246687"

Regards,
Minh

francoma
francomaAuthor
New Member
October 25, 2023

Hi @mle2802 ,

 

Let me try this and will let you know if it worked

Contributor III
October 25, 2023

@francoma If your policy is in flow mode, try changing it to proxy mode and test.

 

Regards.

francoma
francomaAuthor
New Member
October 26, 2023

Hi @Anonymous ,

 

I changed inspection mode for Firewall policy on CLI, let me test and I'll share with you the results, Thank you so much for your time and support on this.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.