Hi all,
We have a problem with the Mitel Telework setup at our offices, where we are able to dial connections from remote handsets (Mitel 5340's - switch is a 3300) and which ring through, but when awnsered we get no voice traffic either way. Before I continue, I should point out that I'm a data network engineer and have very limited experience with the telephone system. The Mitel setup is managed by an external company, who normally do not configure the MAS to run behind an external firewall.
Basically, the way we have it setup is as follows.
We have a perimited firewall (Cisco PIX 515) with a public IP address statically mapped through to the MAS in the DMZ (I have been told that it is actually a MSL running version 8.2.15.0, with a teleworker blade in it). The MAS is running in gateway mode, with it's external interface patched into the DMZ subnet. The internal interface of the MAS is on the same subnet as the Mitel 3300 switch.
We have the following access-lists configured on the PIX to allow traffic through to the MAS on the following ports.
=> TFTP UDP 69
=> Voice Media UDP 20000 - 20999 (complete range)
=> SSL Minet TCP 6801
=> Secure Minet TCP 6802
=> YA Support TCP 8001
Whilst I know I could exclude the PIX and assign the external interface of the MAS a public IP address, I would prefer not to bypass the perimiter firewall. At this point, I should also mention that if I patch a handset into the DMZ directly I can make calls with out any problems. That said, did see a post somewhere, were it was suggested that the MAS running in gateway mode, may not like the NAT that the PIX is performing. I'm not really sure as to how the data flows between the 3300, MAS and remote handset, or the order in which the connections are made through the firewall. As such debugging with tcpdump hasn't really giving me any indication as to where the call is failing.
Has anyone experienced similar problems, or able to recommend a potential fix?
Many thanks!
Rob
We have a problem with the Mitel Telework setup at our offices, where we are able to dial connections from remote handsets (Mitel 5340's - switch is a 3300) and which ring through, but when awnsered we get no voice traffic either way. Before I continue, I should point out that I'm a data network engineer and have very limited experience with the telephone system. The Mitel setup is managed by an external company, who normally do not configure the MAS to run behind an external firewall.
Basically, the way we have it setup is as follows.
We have a perimited firewall (Cisco PIX 515) with a public IP address statically mapped through to the MAS in the DMZ (I have been told that it is actually a MSL running version 8.2.15.0, with a teleworker blade in it). The MAS is running in gateway mode, with it's external interface patched into the DMZ subnet. The internal interface of the MAS is on the same subnet as the Mitel 3300 switch.
We have the following access-lists configured on the PIX to allow traffic through to the MAS on the following ports.
=> TFTP UDP 69
=> Voice Media UDP 20000 - 20999 (complete range)
=> SSL Minet TCP 6801
=> Secure Minet TCP 6802
=> YA Support TCP 8001
Whilst I know I could exclude the PIX and assign the external interface of the MAS a public IP address, I would prefer not to bypass the perimiter firewall. At this point, I should also mention that if I patch a handset into the DMZ directly I can make calls with out any problems. That said, did see a post somewhere, were it was suggested that the MAS running in gateway mode, may not like the NAT that the PIX is performing. I'm not really sure as to how the data flows between the 3300, MAS and remote handset, or the order in which the connections are made through the firewall. As such debugging with tcpdump hasn't really giving me any indication as to where the call is failing.
Has anyone experienced similar problems, or able to recommend a potential fix?
Many thanks!
Rob