No success switching behind a firewall

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts
  • zaninf
    Member
    • Jul 2014
    • 4

    No success switching behind a firewall

    HI
    A customer running succesfully IPO500 with SIP trunk connection to a telephony service provider by public IP address, needs to move IPO500 behind a firewall.

    I changed LAN2 IP address from working public address to new private address and class
    I changed IP route 0.0.0.0 from working public router to new firewall lan address
    In network topology I tried all the "Firewall/NAT type" settings (the working one was "open internet") , working public ip address is entered in "Public IP" field
    A stun server is always been present (perhaps deprecated/no needed in previous public setup)
    Firewall maintainer granted me that ALL tcp and udp ports for the previous working IP address are forwarded directly from internet to the new IPO500 lan IP address.

    The problem : customer is able to place outgoing calls but he can't receive incoming ones
    The external caller receives an unavailable tone from public exchange, like IPO500 is not "viewed" by provider.

    Could it be a firewall issue or some IPO500 mistaken setting ??
    Any hint for troubleshooting ?

    Thank you
  • dgeersbt
    Hot Shot
    • Jul 2011
    • 16

    #2
    Hi
    Please check with WireShark what is going on there might be a port mismatch or blocking or the RTP stream gets lost , Firewalls and SIP can be notorious, ( that is why there are Session border controllers) , I would suggest and SBC rather than a firewall that would make thinks simpler ( not always easier though)

    Comment

    • zaninf
      Member
      • Jul 2014
      • 4

      #3
      Thanks, surely i'll go that way as soon as possible
      My question was also to know if there is a general rule of thumb in IPO LAN settings once placed behind a firewall,
      Forwarding all TCP and UDP ports for a specific public IP to a specific LAN IP is almost to have an open internet (except the translation...)

      Thank you

      Comment

      Loading