Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

One-X mobile for IPO thru VPN

Status
Not open for further replies.

teletomi

Vendor
Aug 31, 2013
276
PH
Hi all..Our customer is using IPO SE R9.0. The customer wouldn't like to use a Native IP Office SIP remote worker nor SIP remote worker with Avaya SBCE type of set up when using one-x mobile thru internet.. They would want to use their own VPN connection.. The customer is using Fortinet as their VPN server. What we did was we downloaded an application for smartphones which is FortiClient, configured the settings so we can connect to their VPN thru internet. From their, I can ping the IPO server but I can't register my samsung duos android version 4.0.4. It's working properly when using wifi but not with the internet. Port forwarding rule on the Fortinet has not been done yet. Do you think port forwarding could be the cause..??We haven't done port forwarding part yet due the Fortinet is being managed by other vendor and we're seeking their assistance. Has anyone tried using one-x mobile via VPN's customer set up..???Seeking for your kind response..Thank you..
 
Wont work, you will get more delay's. Tried with an iPhone and The build in cisco vpn client. Yours is an app so i guess it will even be worse.

Try a sip only client like 3cx to see if it registers and if you can make calls.

Avaya_Red.gif

___________________________________________
It works! Now if only I could remember what I did...

Dain Bramaged (Avaya Search tool )
______________________________________
 
3cx needs a 3rd party IP endpoints. The customer don't have these. But have you tried using any VPN client app and use one-x mobile thur internet..??
 
By the way Bas1234 .. One-x mobile must be working.. Not any other VOIP mobile app..
 
I suspect it's a DNS issue, unless you are using the IP address in the Server field?

What does Monitor show on the SIP trace? Do you see registration attempts?

I would set up port forwarding and try it without the VPN just to prove it working outside the firewall first.

ACSS (SME)

One of these days everything will work as it should, and then we'll all be out of a job!
 
Thank TheSmash dor the response.. Unfortunately,the customer is worried to use their public ip that they might be hacked.. What can you suggest for them to use their public ip add.. What can be the threats using public ip add..Any assurance..?
 
You need to use different ports then 5060/5061 and you can configure that.
You need to use different RTP ports and you can also configure that.
You need to uncheck "auto create extension" for SIP.
You need to set secure user passwords.
Then it is save to use as it checks multiple things like password and mobile twinning.
If the mobile number is not correct then it won't connect the first time.


BAZINGA!

I'm not insane, my mother had me tested!

 
Hi tlpeter.. Just a clarification. When using One-x mobile thru internet, does the call facility must be set "Work" as well...?? Because mobile twinning will be set if you would want to use your own mobile number and setting you One-X call facility to "Mobile" right..? If you set "Mobile" as call facility on One-X and you are connected thru internet and you make a call, the IPO will use its trunk to call your One-X and will bridge you to one that you are calling thus not a free call anymore..
 
Alternatively you can look at using the SBC to secure this. Not sure if this supports SRTP on the One-X mobile yet or if that feature is coming.

Heed all Tlpeter's advice on securing your IP Office. This is very important.

ACSS (SME)

One of these days everything will work as it should, and then we'll all be out of a job!
 
Thanks TheSmash for the note. Will really sure to do what Tlpeter's advice. Hope Tlpeter will reply from my last post.. =)
 
TheSmash SBC is not an option for now. The client is sticking to their VPN as of now. Maybe if all else failed, SBC might be the last resort.. I hope someone could help me on this.
 
I don't use a SBC as we only have a couple users for this now.
If the customer only wants to use a VPN then try it but if it fails then tell them that you can only use a SBC or port forwarding.
If they do not want that then walk away.
But this should have been talked through when the sales guy/girl had the meetings with the customer.


BAZINGA!

I'm not insane, my mother had me tested!

 
If you don't use SBCs for some customers,how do you assure them that simple port forwarding/NAT on firewall/router won't be hacked. What do you tell them..??
 
You need to make sure to use good passwords and not the default ports.
But yes a SBC would be safer but this costs extra money :)

BAZINGA!

I'm not insane, my mother had me tested!

 
You only said that and the customer just approved..???? That's how you assured them..??? Amazing..! =D My customer is not like that unfortunately. They're really scared to do NAT on one-x mobile. Is configuring a SBC hard..?? You can configure that alone..??? =D
 
You assume something that is not true!
I tell them the options and they decide.
Port forwarding is not always a security issue.

BAZINGA!

I'm not insane, my mother had me tested!

 
Thanks Tlpeter for the advise..What a bout my previous post..What can you say about it..

When using One-x mobile thru internet, does the call facility must be set "Work" as well...?? Because mobile twinning will be set if you would want to use your own mobile number and setting you One-X call facility to "Mobile" right..? If you set "Mobile" as call facility on One-X and you are connected thru internet and you make a call, the IPO will use its trunk to call your One-X and will bridge you to one that you are calling thus not a free call anymore.. Hope you'll reply on this.. Thank you..
 
When you use work and you use the voip option then it wil lring through voip on the mobile phone.
When you also turn on twinning then it will try both (that is not good)


BAZINGA!

I'm not insane, my mother had me tested!

 
So setting twinning on 'Mobility' tab at the IPO manager is useless when using VOIP right..??
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top