Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations John Tel on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

9.1 firewall breaks SIP

Status
Not open for further replies.

AACon

Programmer
Feb 20, 2008
3,040
US
Upgraded an 8.1 system to 9.1 this evening (well, yesterday evening). Started at 9:30PM, it's now 3:30 AM and it's done.
What was the issue? Well one, dot net 4 is a pain in the ass (1 hour sitting there spinning in circles, ended up throwing 4.5.2 on it).

Other problem, the firewall in 9.1 breaks SIP; specifically RTP. Undocumented security feature perhaps?

Had the firewall blocking all services...as it was directly connected to the WAN for SIP (please don't lynch me). Worked fine on 8.1, but then comes 9.1, and and SIP fails to work anylonger with the firewall. As soon as it's disabled RTP is a joy. No SIP settings in firewall, yet monitor shows inbound 49152 RTP being blocked blocked blocked.

Ended up just creating static routes to the customers SIP provider (lets hope they don't have another range for RTP that I don't know about...) after hours of troubleshooting.

I wonder if this firewall is the cause of their dropped calls...hmmmm.

But still, just FYI.

So far, I have strong negative feelings towards 9.1.
It broke #XXX voicemail collect on one system, broke the firewall on another, the $CLI_NAME vm variable is broken, and one of the nice features it touts does not work well (other user vvm buttons).
Though, the user web management feature for changing your vm passcode, twinning, etc, is pretty damn nice.

I'm tired.

-Austin
I used to be an ACE. Now I'm just an Arse.
qrcode.png
 
That's what you don't need when you should be sitting back with a beer with the BBQ in this heat.

A gnome will come to cut you.
 
I think upgrading to 9.1 breaks a lot.
I rather reprogram the lot then upgrading.

BAZINGA!

I'm not insane, my mother had me tested!

 
Make a custom rule for the RTP, that should take care of it.

Kind regards

Gunnar
_______
B.U.B.F

2cnvimggcac8ua2fg.jpg
 
Yeah, or, Avaya could just stop breaking things. Though really just limiting the routes to what their ITSP uses solves the problem and I don't have to decode the matrix to get the firewall to work.

-Austin
I used to be an ACE. Now I'm just an Arse.
qrcode.png
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top