Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

4620SWIP says...discover 192.xxx.xxx.xxx ?????

Status
Not open for further replies.

phneguy

Technical User
Dec 7, 2005
119
US
i have a remote phone (4620SWIP) at the house of a remote worker running VPNremote phone. we are trying to connect this via VPN tunnel.

we have the 406v2 4.1 with vpn remotephone user license which is valid. we are using VPNremote phone software on the 4620 as well.

we have the Netgear FVS338. i have created a policy using VPN and IKE Policy and can see the phone connect during boot up. the phone starts to download the files from the TFTP server and packets are being exchanged as well. when the phone gets done getting the files the phone shows... TFTP 1..2...3...4...5...6 and then says TFTP error TIME OUT, then a blank screen, then says discover 192.xxx.xxx.xxx (the ip address of the IP OFFICE).

am i doing anything wrong? i have followed the setup directions from Avaya on how to set up the FVS338.

i have also upgraded the firmware of the FVS338

any help would be great!!!!
 
once the VPN phone connects it sould show up as an internal address on the remote network. the way mine is set up i have 10.1.3.x network in my house. My VPN hands out 192.192.254.x addresses. so my IP route is

192.192.254.0
255.255.255.240
10.1.3.241
Lan1

Kevin Wing
ACA- Implement IP Office
Carousel Industries
 
Okay, and yes that is what it is doing.. I just tried it again, and THIS time, I do see registration requests in my log, but it still sits in discovery, almost like it sees the request come in, but never sees the request go back out to the phone.

It even recognizes the entered extension in the log..

very strange..
 
Here is a copy from the log. As you notice, my IP office is now 192.168.10.20 and the remote phone is 192.168.1.102

I have an IP route like above:

192.168.1.0
255.255.255.0
192.168.10.1
Lan1

Keep in mind that I am only using LAN1 on the IP office since I am not using it for routing or any other ports.

10039795mS RES: Thu 22/5/2008 23:08:50 FreeMem=2470992(28) CMMsg=6 (7) Buff=100 555 500 633 5 Links=2709
10043712mS RasRx: v=IFace=LAN1, Src=192.168.10.153:49303, Dst=192.168.10.20:1719 peb=0
RasMessage = registrationRequest

10043713mS H323Evt: Recv: RegistrationRequest c0a80a99; Endpoints registered: 1; Endpoints in registration: 0
10043716mS RasTx: v=Src=192.168.10.20:1719, Dst=192.168.10.153:49303 peb=0
RasMessage = registrationConfirm

10045180mS RasRx: v=IFace=LAN1, Src=192.168.1.102:49306, Dst=192.168.10.20:1719 peb=0
RasMessage = gatekeeperRequest

10045181mS H323Evt: Recv GRQ from c0a80166
10045182mS H323Evt: e_H225_AliasAddress_dialedDigits alias
10045182mS H323Evt: found number <330>
10045184mS RasTx: v=Src=192.168.1.20:1719, Dst=192.168.1.102:49306 peb=0
RasMessage = gatekeeperConfirm
 
So all that being said, the phone sits in discovery even after this. (also, just as an FYI, 192.168.10.153 which is the first registered phone is a local IP phone which works perfectly fine)
 
Are there any ports blocked on the vpn router ?
1719 is for registration and you see that in monitor
1720 is for data to that registerd phone


ACA - Implement IP Office
ACS - Implement IP Office
ACA - Voice Services Management
______________
Women and cats can do as they please and men and dogs should relax and get used to the idea!
 
Can you ping the IP of the phone from the network that the IPO is on.

Kevin Wing
ACA- Implement IP Office
Carousel Industries
 
Nothing that I know of blocked, although I havent put any special rules in place either. I have the FVS338.

I will try the ping test later this evening.
 
Should I be putting rules in place to allow the IP Office access to all ports?

SIP works for me fine (Outbound calls), so I am not sure why the H323 wouldnt.

I do notice my STUN does come back as a protected NAT

 
You can try to open all ports :)


ACA - Implement IP Office
ACS - Implement IP Office
ACA - Voice Services Management
______________
Women and cats can do as they please and men and dogs should relax and get used to the idea!
 
Wondering if I should do this in port triggering or forwarding for 1719 and 1720.

Being new to the FVS338, not sure if I should even have had to do this. I will test later on this evening and see where I end up.
 
But if VPN Passthrough is already opened up, wouldnt that allow ALL traffic to pass?
 
More of the same. I turned off my remote user's firewall too! No I cannot ping 192.168.1.102 which is what the phone is coming up as over the VPN, but as you can see below, it's trying and trying to register with extension 330 which is the proper extension with a VPN license checked. Any ideas?



83988297mS RES: Fri 23/5/2008 19:41:19 FreeMem=2421192(27) CMMsg=6 (7) Buff=100 555 500 633 5 Links=2586
83993284mS RasRx: v=IFace=LAN1, Src=192.168.1.102:49302, Dst=192.168.10.20:1719 peb=0
RasMessage = gatekeeperRequest

83993285mS H323Evt: Recv GRQ from c0a80166
83993286mS H323Evt: e_H225_AliasAddress_dialedDigits alias
83993286mS H323Evt: found number <330>
83993288mS RasTx: v=Src=192.168.1.20:1719, Dst=192.168.1.102:49302 peb=0
RasMessage = gatekeeperConfirm

83998284mS RasRx: v=IFace=LAN1, Src=192.168.1.102:49302, Dst=192.168.10.20:1719 peb=0
RasMessage = gatekeeperRequest

83998286mS H323Evt: Recv GRQ from c0a80166
83998286mS H323Evt: e_H225_AliasAddress_dialedDigits alias
83998287mS H323Evt: found number <330>
83998289mS RasTx: v=Src=192.168.1.20:1719, Dst=192.168.1.102:49302 peb=0
RasMessage = gatekeeperConfirm

83998294mS RES: Fri 23/5/2008 19:41:29 FreeMem=2421192(27) CMMsg=6 (7) Buff=100 555 500 633 5 Links=2586
 
What firmware/model is your IPO???

Jamie Green

ACA:Implement - IP Office
ACS:Implement - IP Office


Football is not a matter of life and death-It is far more important!!!!
 
Does anyone have msn messenger or something that can help me out? I been at this for weeks.. ugh..

give me a Definity! Please! :)
 
IS the VPN router the only router/firewall on your network? It is looking like the IPO does not know where to send the reply. The traffic is getting to the ipo but not getting back to the phone. How many IP Routes do you have what do they look like.

Kevin Wing
ACA- Implement IP Office
Carousel Industries
 
I only have the 1 route.. which is stated above..
Yes I agree with you.. but not sure what i am doing wrong
 
In your IP route, is the gateway you set the VPN terminator???

Jamie Green

ACA:Implement - IP Office
ACS:Implement - IP Office


Football is not a matter of life and death-It is far more important!!!!
 
When I stated MY gateway - I mean the same gateway the IPO is on.. not the remote end.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top