Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Avaya IP Trunks are not working when the ports are limited

Dear All, I have configured a Site to Site VPN between FortiGate and Checkpoint. Both end' s of the Firewalls we have Avaya IP telephone setup. our aim is to achive the IP Trunk beween these to offices through VPN. We achived the task by applying the corresponding rule at both the ends. The problem comes here is, on both the Firewalls (FortiGate & CP) if I allow ANY as a service, The IP Trunk starts working and when I filtered the logs I found that the service that in user are icmp/8 and tcp/5020. When I put these to ports on the services option, The IP Trunk is not working. I don' t know where the problem is????? Could any one help me in this case, That will be a good thing for me. Thanks in advance, Regards, Basha
2 REPLIES 2
doshbass
New Contributor III

Basha, Clearly there is something else trying that got missed on the logs. You can try several things, 1) run the diag sniffer command to see what other traffic is being sent from your phones 2) create an explicit devy rule after your allow rule and tick the " log violation traffic" option to see what is beiing bloicked.
Still learning to type " the"
Still learning to type " the"
g3rman
New Contributor

If it is a SIP trunk it will very likely also need port 5060 for SIP signalling. Typically the media stream between the two devices is on some random high ports which are negotiated during call setup.
A Real World Fortinet Guide Configuration Examples & Frequently Asked Questions http://firewallguru.blogspot.com
A Real World Fortinet Guide Configuration Examples & Frequently Asked Questions http://firewallguru.blogspot.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors