SIP Header sending internal private IP instead of Public external IP address

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts
  • rteluk
    Member
    • Sep 2016
    • 6

    SIP Header sending internal private IP instead of Public external IP address

    Hello,

    We have an issue that our SIP provider states is a problem with the Avaya IP Office 500v2 (9.1.6) system and not with them. This SIP provider uses no credentials at all and only allows traffic from Specific IP addresses.

    With a trace from their end we receive a pcap file from them that never shows our source IP as a private IP, whenever anything originates from us it is the public IP address. However, when they respond the destination is from them is always going to the private ip address instead of our public IP address.

    The provider stated they are unable to assist as we are telling them to respond to 192.168.0.220 so we need to fix it.

    SIP URI information is all set to "Use Internal Data" as per the SIP providers documentation, changing this to * does not do anything. Registration is 0:<None>
    Incoming and Outgoing group is 0

    We can receive incoming calls, however, we cannot hear the person calling in, they can hear us. After about 40 seconds the calls is dropped. We cannot make any outbound calls, we get an fast busy stating "Unobtainable".

    In System Status the Active call never leaves the Incoming/Incoming Alert Status.

    The SIP is going out LAN1 using a NAT to the public IP address. LAN2 is used for the Voice VLAN so phones can communicate with the Phone system on a separate VLAN from data.

    Any help would be greatly appreciated.

    Thank you in advance.
  • furrerm
    Guru
    .
    • Nov 2010
    • 196

    #2
    Set up STUN.

    Comment

    • rteluk
      Member
      • Sep 2016
      • 6

      #3
      STUN is setup to a public stun server as the provider could not provide one. After running STUN and waiting 15 minutes it sometimes responds with 0.0.0.0 and blocking firewall, other times nothing changes at all. When I use the IPO system status to ping an public IP address I have a firewall at I do see the public IP trying to communicate.

      The Watchguard has a 1-to-1 NAT for the IPO going to the public IP which from what I can tell is fully working.

      Comment

      • furrerm
        Guru
        .
        • Nov 2010
        • 196

        #4
        Try different public stun servers until it finds the info automatically.

        Or try to manually set the IP with your WAN IP, and setting the firewall to Port restricted cone NAT.

        Comment

        • rteluk
          Member
          • Sep 2016
          • 6

          #5
          Originally posted by furrerm View Post
          Try different public stun servers until it finds the info automatically.

          Or try to manually set the IP with your WAN IP, and setting the firewall to Port restricted cone NAT.
          For some reason, not one of 5 STUN servers would work. After testing all modes, audio for inbound calls now is working on both ends with Blocking Firewall.

          Comment

          • gtelliott
            Hot Shot
            • Aug 2014
            • 15

            #6
            Depending on your router/firewall there will be a setting known as the following,
            it maybe ip sip helper / sip alg or sip transformations. Try disablable it.

            Comment

            Loading