Hi everyone,
I am hoping that someone has hit this issue before.
We have an Avaya telephony system on our premise on which we have 2 SIP trunks from one SIP provider.
We configured a VIP with the required ports DNat-ed to the telephony system
We've created firewall rules to only accept traffic on that VIP from a few ip addreses of our SIP provider and to only send replies to the provider.
Still, we receive a lot of SIP login attempts from bots, and on the telephony system i keep getting authentication attempts from multiple IP's
With our former router (without UTM/NGFW) we just created a simple rule and we never had this issue with a simple statefull inspection firewall.
Can anyone point me in the right direction? Our SIP's are in use 24/7 so it is hard to just randomly test to disable SIp-helper, than SIP-ALG, etc sicne that will disrupt traffic and cause a lot of issues.
We had a case opened for this and the support reply was that it is not possible, since even if we specify a firewall rule on our VIP, the port will still be listening and reply on the internet
I am really hoping that someone can point me in the right direction.
Thank you
User | Count |
---|---|
2047 | |
1170 | |
770 | |
448 | |
339 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.