Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

No Audio over IPSec Tunnel Avaya 9620 / S8300 1

Status
Not open for further replies.

Eric7858

IS-IT--Management
Sep 28, 2020
4
US
Recently, we are no longer able to dial by extensions between offices. The offices are connected via ipsec tunnel with all ports allowed between the offices. I can dial direct numbers xxx-xxx-xxxx, and it works fine, but when dialing by extensions, it rings, when the person pick up, there is no audio on both sides. I know someone is there because the phone does not disconnect until the person hangs up. I checked the firewall on both ends, and all ports are allowed over the tunnel for both voice and LAN on both sides. I did a list trace and it shows the local and remote phone are connecting. Any ideas? Thank you.
 
You may need to move your post to avaya cm forum but anyway,

Seems like there is no direct network connectivity between the phones networks in both locations.

Otherwise, check hairpining/shuffling, network regions and ip-map.
 
When you do "list trace station" and the call connects you see which IPs are used for RTP so check if those can reach each other.

"Trying is the first step to failure..." - Homer
 
The two networks can reach each other. The vlans are all class c networks, but the tunnels are configured for class b or /16. Also for verification, I went over the network & tunnel setup with tac team, which verified the devices should all reach each other.
Meaning: networks setup as examples:
local Avaya PBX network: 192.168.5.0/24
local Phone network: 192.168.6.0./24
remote phone network: 192.168.10.0/24
ipsec Tunnel between networks: 192.168.0.0/16
All telephone networks are configured under ip-network-map
There is only 1 region, and has been in place for years.
When the other station picks up, the list trace stop at
rgn:1 [ipaddress]:2242
14:55:59 idle station theremoteextension cid 0x42

 
It doesn't make any sense that the IPSec network would be a /16 network that collides with the other /24 networks.

"Trying is the first step to failure..." - Homer
 
Not sure what devices make up the IPSEC VPN but you may want to check the H323 and SIP alg's

Kevin Wing
ACSS Small and Medium Enterprise (SME) Communications
ACS- Implement IP Office
ACA- Implement IP Office
Vive Communications
 
This is working now. Sorry, I overlooked the traffic path on the affected tunnel. It was missing a policy which for whatever reason TAC team did not identify as an issue.

Thank you all.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top