Hello dear friends from Fortinet,
Sorry for my tone but I have no normal words.
I spent several nights trying to understand why my Asterisk PBX can't register on SIP provider. So finally I found in captured packets the makings of a failed intellect.
1. PBX sends register packet
src:int_IP:5060 to dst:SIP_prov_IP:5060
Message Header
Via: SIP/2.0/UDP ext_IP:5060;branch=z9hG4bK6a3e42f7
2. Fortigate translats by NAT ........ BUT!!!!!!......it changes packet's content
src:ext_IP:5060 to dst:SIP_prov_IP:5060
Message Header
Via: SIP/2.0/UDP ext_IP:5170;branch=z9hG4bK6a3e42f7
3. Evidently SIP provider response to the fake port presented by Fortigate
src:SIP_prov_IP:5060 to dst:ext_IP:5170
Message Header
Via: SIP/2.0/UDP ext_IP:5170;branch=z9hG4bK6a3e42f7
And NOTHING MORE !!!! Because this port in not listen and even is blocked as it is not permitted by policy and therefore this packet doesn't returned to PBX. And the same thing happens with RTP packets!!!
I don't understand this half-baked intelligence. How was it tested before sale to end users?!!! Why do I have to pay and then have to be stressed reading thousands forums and manuals?!!!!! Who will pay me more than 20 loused hours of sleepless nights and my life I could passed with my family or my friends?!!!!
And I haven’t found any solution for this problem other than disabling all this intelligence.
Thank you very much. Hope you will help me briefly.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi
I'm not a SIP specialist but I know that to avoid SIP headaches we usually disable SIP ALG, You may need to know that Fortinet doesn't recommend to disable SIP ALG while SIP providers usually recommend to disable it.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Disabling-VoIP-Inspection/ta-p/194131
Hi
I'm not a SIP specialist but I know that to avoid SIP headaches we usually disable SIP ALG, You may need to know that Fortinet doesn't recommend to disable SIP ALG while SIP providers usually recommend to disable it.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Disabling-VoIP-Inspection/ta-p/194131
Thank you very much.
But! The sad fact is that there are a lot of modern technologies that work well when they are disabled :) ;)
Hi @teccart,
In addition to disabling SIP ALG, you can also enable 'preserve source port' option to prevent source ports from being modified. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-Fixedport-or-Preserve-Source-Port-on...
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.