I was going through this thread and I think I'm running into a similar situation. This thread is unresolved. https://forum.fortinet.com/tm.aspx?m=65009&high=panasonic
Currently all the phones are connected through vpn tunnel through Cisco Meraki to Cisco Meraki. Phones are registered and can make calls.
I migrated one Meraki to Fortigate. Now it is connected VPN tunnel through Meraki to Fortigate.
Phones stopped working.
I also have remote phones that use NAT (Virtual IP) from public to private on the Meraki. After removing the Meraki and porting the NAT rules to the Fortigate, phones stopped working. I did a packet capture and when they dial out, the destination to the voice server are using some high range ports UDP/50000+. The ports should be using UDP/16000-16511. I switched it back to the Meraki and the ports started using UDP/16000-16511 again. Is this something that has to do with the way Fortigate is handling the NAT?
I've tried changing the SIP-ALG to kernel and disable sip-nat-trace, sip-helper, delete port from session-helper changes people recommend for SIP don't help. I applied them anyways and did a reboot just to see if it does but it didn't.
Many hours spent with migration and migrating back. I'm stumped and any help is appreciated.
Hi,
I am curious if you are using any portable Softphone applications as extensions? I have a challenge with ensuring the solutions works for SIP configured devices over forticlient VPN.
So with Meraki this works well?
Regards,
zeki893 wrote:I was going through this thread and I think I'm running into a similar situation. This thread is unresolved. https://forum.fortinet.com/tm.aspx?m=65009&high=panasonic
Currently all the phones are connected through vpn tunnel through Cisco Meraki to Cisco Meraki. Phones are registered and can make calls.
I migrated one Meraki to Fortigate. Now it is connected VPN tunnel through Meraki to Fortigate.
Phones stopped working.
I also have remote phones that use NAT (Virtual IP) from public to private on the Meraki. After removing the Meraki and porting the NAT rules to the Fortigate, phones stopped working. I did a packet capture and when they dial out, the destination to the voice server are using some high range ports UDP/50000+. The ports should be using UDP/16000-16511. I switched it back to the Meraki and the ports started using UDP/16000-16511 again. Is this something that has to do with the way Fortigate is handling the NAT?
I've tried changing the SIP-ALG to kernel and disable sip-nat-trace, sip-helper, delete port from session-helper changes people recommend for SIP don't help. I applied them anyways and did a reboot just to see if it does but it didn't.
Many hours spent with migration and migrating back. I'm stumped and any help is appreciated.
User | Count |
---|---|
2028 | |
1159 | |
770 | |
448 | |
315 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.