Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TobiasHan
New Contributor

Fortigate SIP Problem (or Portchange without NAT)

Hello,

 

i have a fortigate 500 with FortiOS 5.4.6 on it.

 

The Firewall works since over 2 years, but since friday i have the problem, that one Port change the destination port.

 

Normally the policy (and static route) says: all traffic destination xx.xxx.62.3 goes over vpn to destination (Source und Destination Port 5060). Now or since friday comes the traffic on source port 5060 and goes out at 15060.

The traffic now not goes in the VPN TUnnel, and directly into the wan and was blocked by policy violation.

 

What can i do, to fix the problem.

 

Interestingly it works between, without make a change at the firewall.

 

Thanks for any advise and kind regards

Tobias

 
2 REPLIES 2
razor
New Contributor III

Do you have SIP ALG enabled?

Fortinet Network Security Professional (NSE4)

Fortinet Network Security Professional (NSE4)
emnoc
Esteemed Contributor III

the cli cmd diag debug flow is your  friend here and what do you mean by policy and route ?  Is this policyBasedRoute?

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors