We are facing with very strange symtomp of FG-800F,when working with SIP.
At present, we deploy SIP through IPSec VPN Tunnel through FG-800F and FG-60A units.
SIP Server(Asterik) is located at HeadQuarter, while SIP Phone(Grandstream)are distributed at all sites.
Everytime we config the Policy Route, SIP Phones will take longer than usual for registerring to SIP Server. Besides, after successfully registerred, the SIP conversation only can happen within 20s only...then drop...Can you feel the uncomfortable feeling of end-users,included my Boss....?
Pls spend time to support us overcome this symtomp...
Many tks and Brgds
Never Stop Learning...
I' m facing the same problem.
I have IPSec VPN tunnels between four locations. The office has a 60B and others have 50Bs. The problem is that the line is dropped after exactly 20 seconds. Tried to add the reinvite (or update or nonat or combination) to the extensions that are connecting over VPN but without any result.
Any other suggestion?
Thanks in advance
We have fixed the symtomp.It' s related to some restriction of FGT.
In order to quickly fix symtomp,we move to another network design.It works quite well,Mladen.
If you have time in more discussion,pls reach me.
Looking foward to hearing you soon!
Never Stop Learning...
I' m also interested how did You solve this...
I find out that if I change design of the network to layer 2 (please consider this very limited options) so that all phones are on the same layer 2 network as FG, in this scenario all phones register successfully and SIP translations works.
If phones are in different layer 2 network (any other subnet) beside one which is on FG unit' s You may expirence slower registration process, one party is not able to hear other (even in scenario where no NAT i deployed and all phones are public IP addres.
You may search for SIP on that Forum - there were many discussions on this already.
In short - make sure that for your SIP policy (UDP || TCP 5060) you apply a Protection profile that has " SIP" ticked on under the respective " VoIP" Trinagle.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.