Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sovrin-James
New Contributor

OpenScape PBX behind FGT 80E

Hi all

 

I'm setting up and OpenScape PBX behind my 80E and am having trouble with incoming calls.

 

I've disabled the ALG and SIP helper as directed by the provider and set up the requirements as best as I can understand.

 

I need a set of ports open to allow the required traffic and have configured a set of VIPs mapping my external IP to my internal IP, filtering by the SIP providers IP address, and forwarding to the same ports the traffic is arriving on.

 

We have SD-WAN enabled, so I've set a rule to place all traffic on the relevant ports onto a single IP address so that it always comes from the same WAN IP.

 

I've finally con figured a firewall policy to permit incoming traffic from the SIP providers server to go through the firewall when it matches the rules I used for the VIPs.

 

I'm not seeing any hits on my new policy and if I look at the log for the implicit deny all, I can't see any blocked traffic coming from the SIP provider either.

 

The provider says that they've been able to make outgoing calls but can't receive an incoming call and the successful outgoing calls have no media.

 

I'm really scratching my head on this one, I'd greatly appreciate some assistance.

1 REPLY 1
AlexC-FTNT
Staff
Staff

It is very dififcult to guess what is happening with SIP calls without packet capture.

But it is more strange that you have disabled SIP inspection on the unit. Did you follow any of the Fortinet KB guides to do that? (1. why was done? 2. was it done correctly?)
Without SIP inspection the FortiGate will not know what audio ports to open for the media. So if your VIP is not configured correctly, you will not have any incoming audio.

First make sure that the traffic from a phone is over the same sdwan interface (both control and audio traffic). Remove any unnecessary NAT, like ippools. And if the DoS policy is not blocking the UDP stream, then a packet capture will tell you what is going on. 


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
Labels
Top Kudoed Authors