Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

No voice when pickup phone(Both end)

Status
Not open for further replies.

ciscomoon

IS-IT--Management
Sep 12, 2006
7
AU
Hi i have just installed ccm 4.1.2. I successfully registered 3 ip phones
=======================================
Tftp sever is pulling all three files from ip phones and getting registered in ccm. All the phones in ccm is registered and showing ip addresses of each phone. Given below more details:
=======================================
1. Call manager Ip Address: 192.168.2.150- Location Florida- Using Pix 520-Public Ip port forwarding to ccm(port 69 and 2000)
2. 7940 ip address 10.1.1.30 Location miami - No VPN Tunnel and PIX
3. 7940 ip address 192.168.0.50-Location Chicago - No VPN Tunnel and PIX
4. 30 Vip ip address 192.168.1.30 Location arizona - No VPN Tunnel and PIX

Above three phones are in different location as you can see above subnet.

=> From 1 i can call 2 and 3 and vice versa. All 3 phones can receive and make calls but no voice.

=========================================================
Please note i am not using gateway.

Here is my simple setup:
Call manager ip address is 192.168.2.150. Public Ip (209.64.121.xxx) is port forwarding to 192.168.2.150 which is call manager.

I have three phones on different locations which is registered in call manager. I am using tftp server as a public Ip (209.64.121.xxx)this Public ip port forwarding to my call manager and succefully registering all the above three phones in ccm.

Call manager is behind PIX firewall and my pix config is:

PIX Version 6.3(4)
interface ethernet0 auto
interface ethernet1 auto
nameif ethernet0 outside security0
nameif ethernet1 inside security100
enable password wbSW/UgMKKmZHcR6 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
hostname rafay
domain-name wasay
fixup protocol dns maximum-length 512
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol tftp 69
names
name 61.xx.xx.xx outside-malakpet
object-group service lexia tcp-udp
port-object range 10000 20000
port-object range 16384 32767
port-object eq 69
object-group service UDPList udp
port-object eq 2000
port-object eq 8000
port-object range 16384 32767
access-list RichmondIndia permit ip 192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0
access-list NATExempt permit ip 192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0
access-list NATExempt permit ip 192.168.2.0 255.255.255.0 192.168.0.0 255.255.255.0
access-list NATExempt permit ip 192.168.2.0 255.255.255.0 192.168.3.0 255.255.255.0
access-list RichmondFootscray permit ip 192.168.2.0 255.255.255.0 192.168.0.0 255.255.255.0
access-list Richmond2India permit ip 192.168.2.0 255.255.255.0 192.168.3.0 255.255.255.0
access-list outbound permit udp host 192.168.2.110 host 203.13.163.244 eq 4569
access-list outbound permit tcp host 192.168.2.110 host 203.13.163.244 eq 4569
access-list outbound permit udp host 192.168.2.210 host 203.13.163.244 eq 4569
access-list outbound permit tcp host 192.168.2.210 host 203.13.163.244 eq 4569
access-list outbound permit udp host 192.168.2.150 host 61.xx.xx.xx eq tftp
access-list outbound permit tcp host 192.168.2.150 host 61.xx.xx.xx eq 69
access-list inbound permit tcp any any eq ssh
access-list inbound permit tcp any any eq 4569
access-list inbound permit icmp any any
access-list inbound permit tcp any any eq www
access-list inbound permit tcp any any eq 1433
access-list inbound permit tcp any any eq 69
access-list inbound permit udp any any eq tftp
access-list inbound permit tcp any any eq 2000
access-list inbound permit tcp any any eq 3389
access-list inbound permit udp any interface outside object-group lexia
access-list Inbound permit udp any interface outside object-group lexia
pager lines 24
mtu outside 1500
mtu inside 1500
ip address outside 61.xx.xx.xx 255.255.255.252
ip address inside 192.168.2.1 255.255.255.0
ip audit info action alarm
ip audit attack action alarm
no failover
failover timeout 0:00:00
failover poll 15
no failover ip address outside
no failover ip address inside
pdm location 192.168.2.2 255.255.255.255 inside
pdm location 192.168.2.2 255.255.255.255 outside
pdm location 192.168.1.0 255.255.255.0 outside
pdm location 192.168.0.0 255.255.255.0 outside
pdm location 192.168.3.0 255.255.255.0 outside
pdm location 192.168.2.110 255.255.255.255 inside
pdm location 192.168.2.210 255.255.255.255 inside
pdm location 192.168.2.150 255.255.255.255 inside
pdm location 192.168.2.150 255.255.255.255 outside
pdm location 192.168.2.11 255.255.255.255 inside
pdm location 61.xx.xx.xx 255.255.255.252 inside
pdm location 61.xx.xx.xx 255.255.255.0 outside
pdm location 192.168.2.12 255.255.255.255 inside
pdm location outside-malakpet 255.255.255.255 outside
pdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 0 access-list NATExempt
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) udp interface 4569 192.168.2.110 4569 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 4569 192.168.2.110 4569 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface ssh 192.168.2.110 ssh netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 2427 192.168.2.210 2427 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 2427 192.168.2.210 2427 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1433 192.168.2.210 1433 netmask 255.255.255.255 0 0
static (inside,outside) udp interface tftp 192.168.2.150 tftp netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 69 192.168.2.150 69 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 255.255.255.255 0 0
static (inside,outside) tcp interface 2000 192.168.2.150 2000 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 3389 192.168.2.150 3389 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 10000 192.168.2.150 10000 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 8000 192.168.2.150 8000 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 16384 192.168.2.150 16384 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 16385 192.168.2.150 16385 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 16386 192.168.2.150 16386 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 32767 192.168.2.150 32767 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 5062 192.168.2.150 5062 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 5063 192.168.2.150 5063 netmask 255.255.255.255 0 0
static (inside,outside) outside-malakpet 192.168.2.12 netmask 255.255.255.255 0 0
access-group inbound in interface outside
route outside 0.0.0.0 0.0.0.0 outside-malakpet 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ max-failed-attempts 3
aaa-server TACACS+ deadtime 10
aaa-server RADIUS protocol radius
aaa-server RADIUS max-failed-attempts 3
aaa-server RADIUS deadtime 10
aaa-server LOCAL protocol local
http server enable
http 0.0.0.0 0.0.0.0 outside
http 0.0.0.0 0.0.0.0 inside
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
sysopt connection permit-ipsec
sysopt connection permit-l2tp
crypto ipsec transform-set SecuritySet esp-des esp-sha-hmac
crypto map rtpmap 1 ipsec-isakmp
crypto map rtpmap 1 match address RichmondFootscray
crypto map rtpmap 1 set peer 203.xx.xx.xx
crypto map rtpmap 1 set transform-set SecuritySet
crypto map rtpmap 1 set security-association lifetime seconds 3600 kilobytes 4608000
crypto map rtpmap 2 ipsec-isakmp
crypto map rtpmap 2 match address RichmondIndia
crypto map rtpmap 2 set peer 219.xx.xx.xx
crypto map rtpmap 2 set transform-set SecuritySet
crypto map rtpmap 2 set security-association lifetime seconds 3600 kilobytes 4608000
crypto map rtpmap 3 ipsec-isakmp
crypto map rtpmap 3 match address Richmond2India
crypto map rtpmap 3 set peer 203.xx.xx.xx
crypto map rtpmap 3 set transform-set SecuritySet
crypto map rtpmap 3 set security-association lifetime seconds 3600 kilobytes 4608000
crypto map rtpmap interface outside
isakmp enable outside
isakmp key ******** address 203.xx.xx.xx netmask 255.255.255.255
isakmp key ******** address 203.xx.xx.xx netmask 255.255.255.255
isakmp key ******** address 219.xx.xx.xx netmask 255.255.255.255
isakmp identity address
isakmp policy 2 authentication pre-share
isakmp policy 2 encryption des
isakmp policy 2 hash sha
isakmp policy 2 group 2
isakmp policy 2 lifetime 86400
telnet 61.xx.xx.xx 255.255.255.0 outside
telnet 61.xx.xx.xx 255.255.255.252 outside
telnet 61.xx.xx.xx 255.255.255.252 inside
telnet timeout 5
ssh timeout 5
console timeout 0
dhcpd address 192.168.2.11-192.168.2.127 inside
dhcpd dns 202.138.xx.xx 202.138.xx.xx
dhcpd lease 3600
dhcpd ping_timeout 750
dhcpd enable inside
terminal width 80
Cryptochecksum:5dedb16926cad3ea95c3240065e0ba11
: end
==========================================================

Please advise.
 
Voice traffic goes from IP Phone to IP Phone. It sounds like you are allowing the signaling traffic to get to the CCM server but the phones can't get directly to each other. Once the call is established the phones must have direct communication to each other or no voice will go in between them.
 
Thanks for replying pndscm

Is there any solution to my query

Thanks

 
We would need more information about the network. How does Miami, Chicago and Arizona communicate with each other? You say there is no VPN or PIX.
 
Thanks for replying. Miami, Chicago and Arizona phones are registering in the ccm.

CCM is assigning extension number to Miami, Chicago and Arizona.

This setup is like for example.

I am travelling and i like to speak to my family or employee i carry my IPphone with me and plugin to the any network . The ip phone registered in to call manager through tftp and i can dial extension to speak with family or employee.

I hope its clear Miami, Chicago and Arizona communicate each other via call manager.
 
The problem is more than likely a routing issue. I'm not a PIX expert but it looks like you are allowing incoming traffic on the voice UDP ports to get to CallManager but not anywhere else. To pass voice between phones, the PHONES must be able to get to each other directly, not through the CallManager. The CallManager is providing the signaling traffic correctly but voice packets do not go to the CallManager. They go directly between the 2 phones once CallManager has set up the signaling handshake. A simple PING test from subnet to subnet should go a long way to identifying the problem.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top