Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Port 5060

Hello, we' re configuring SIP in a fortigate 60b v4.0,build0194,100121 (MR1 Patch 3). In virtual ip we create the group to port forward to the central 5060 tcp/udp 5090 tcp/udp 9000-9015 tcp/udp We test in the VOIP central the ports and all of them pass except 5060. <14:48:55>: UDP SIP Port is set to 5060. Response received WITH TRANSLATION 54082::5060. Phase 2a check passed with WARNINGS. Some functionality will be LIMITED. For more information, please visit http://www.3cx.com/support/firewall-checker.html <14:48:55>: Phase 2b. Check Port Forwarding to TCP SIP port, please wait... <14:48:55>: TCP SIP Port is set to 5060. Response received WITH TRANSLATION 54082::5060. Phase 2b check passed with WARNINGS. Some functionality will be LIMITED. For more information, please visit http://www.3cx.com/support/firewall-checker.html <14:48:55>: Phase 3. Check Port Forwarding to TCP Tunnel port, please wait... <14:48:55>: TCP TUNNEL Port is set to 5090. Response received correctly with no translation. Phase 3 check passed. We add a policy route wan --> internal Source Interface/Zone wan1 Source Address all Destination Interface/Zone internal Destination Address all Schedule always Service SIP Action ACCEPT NAT cheked I' m missing something. I' m doing this all wrong? Any ideas? Thanks in advance. Regards
3 REPLIES 3
ddskier
Contributor

Do I quick search for SIP-ALG. You will see a bunch of posts on how to get this working.

-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D

-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
Not applicable

That' s true, but everything I tried didn' t work out. All ports pass but 5060 doesn' t and I didn' t understand why. It might be something I' m doing wrong or I' m missing. As did the following 1) delete everything I had to do with 3CX 2) restart the forti unit 3) addall ports again 4) I made a policy WAN1 -> internal with virtual ip ports + SIP service and nothing else Now the ports passed. But I have no logs, where I fixed that? Because the policy is enabled, allow traffic log Thanks for the answer. Regards
ddskier
Contributor

Did you follow the SIP-ALG posts. 1. Disabled SIP Helper 2. Created a SIP Application Control 3. Created a protection profile that used that Application Control 4. Set the protection profile on the policy for the VIP 5060 access?

-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D

-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors