Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
danjacoyle
New Contributor

Routing VoIP traffic over a site to site VPN

I have one site 10.0.0.0/8 which connects to another site 192.168.24.0/24 with a site to site IPSEC VPN.

The phone system is located at the 10.0.0.0/8 site on the default LAN and VLAN5 192.168.130.0/24 is used for VoIP traffic at this site.  VoIP is used on the default VLAN at the 192.168.24.0/24 site.

Both sites when making calls between VoIP phones are able to make the phone ring on the remote site, but then the call cannot be heard on either side so it must be a routing issue between the 192.168.24.0 network talking to VLAN5 192.168.130.1 over the VPN.

Does anyone know what I need to do to this fix please?  I tried to create another VPN between 192.168.24.0 and VLAN5 192.168.130.0 but the FortiGate wouldn't let me as the IP address was already in use

 

Thanks

Dan

1 REPLY 1
Johan_Witters
Contributor

You are probably correct in your evaluation of the problem: signalling runs from client <> pbx <> pbx <> client so as long as the client can reach the local pbx, and the pbx's can reach each other, the phones will ring. Speech itself runs directly between the phones.

 

If your vpn-connection is up, you probably only need to add the correct routes to the remote voip subnets, and make sure it matches security policies etc.. Also don't forget to check the qm selectors on your vpn tunnel.

 

Easiest way to troubleshoot is to place a client in 1 voip subnet, and try to ping a phone at the other site.. If it words and no nat is involved, it should be possible to succesfully call the other site..

Johan Witters

Network & Security Engineer

FCNSP V4/V5

 

BKM NV

Johan Witters Network & Security Engineer FCNSP V4/V5 BKM NV
Labels
Top Kudoed Authors