Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Watchguard with remote worker phone

Status
Not open for further replies.

Spekkert

Programmer
Feb 19, 2008
51
NL
Hi Guys,

im having trouble to get the remote worker phone solution to work with watchguard XTM series. Has anybody got this to work? Or is this a device thats on the list that do not work?

Thanks!
 
i bet its the broadband at the other end....

are you using a proxy or just a packet filter for you policies?

ACSS - SME
General Geek

 
I just use packet filtering, and the other end is also a watchguard XTM.

You have this working? Just with forwrding the ports with SNAT?
 
What is the problem you have?


BAZINGA!

I'm not insane, my mother had me tested!

 
I know i could use a site to site but this is just for testing. We use the watchguard almost evry time with a ip office install. So i would like to know if this works with the remote worker solution. So HSM did you get this to work?

Peter, the phone tries to register and switches between screens of registering and "phone screen" (im useing a 9608).

this is the message i get in monitor:
156628655mS H323Evt: Recv GRQ from d97ab6f0
156628655mS H323Evt: e_H225_AliasAddress_dialedDigits alias
156628655mS H323Evt: found number <240>

This keeps repeating.

User settings and extetion settings are correct. Port forwarding is correct. Als tried this:
REMOTE_H323=1800

Thanks!

 
Did it make any difference?
When you used port 1800 did you change the 1720 tcp port to 1800?
If you don't then it won't work

BAZINGA!

I'm not insane, my mother had me tested!

 
Peter,

i added the port in the policy. BUt there is no difference. I dont see anything being blocked in the firewall..
 
But did you remove 1720?
If you don't then odd things happen (no speech is one of them)

BAZINGA!

I'm not insane, my mother had me tested!

 
Ok, a changed the policy to this:
udp 1719
TCP 1800
Rtp port
UDP 5005

Also the puplic ip is pingable.
Firmware ip office 8.1.69 with the correct firmware in 9608

Stil the same problem...
 
Did you run stun?

BAZINGA!

I'm not insane, my mother had me tested!

 
Yes, you need STUN to be running to re-write your packets from Private / NAT IP to your public interface IP. Hence no speech.

Yes, I have had the WG working with remote phones. VPN mode works even better though.

ACSS - SME
General Geek

 
I havent tried stun yet. Peter which stun server do you use?

HSM, for the watchguard config, you only use the SNAT port forwarding or is there something else that you change in the watchguard?

 
I use stunserver.org


BAZINGA!

I'm not insane, my mother had me tested!

 
Ok, tried the stun server, but as soon as i enable the stun option my sip trunk goes down...

Do I have to use the Stun server option... With mitel and panasonic this is way easier... or is it just me...
 
It's not just you, Avaya have made a hash of it. And they seem to have abandoned it in favour of SIP endpoints in R9 rather than improving it :)

 
And with SIP remote phones you might as well have an analogue phone attached to an ATA for all the functionality you get.

Stick to VPN phones. Best method still by far.

ACSS - SME
General Geek

 
Ok, the stun is working and the sip trunk is up to. It took some time for stun to work, like almost 10 minutes. Is this normal?

And there is no way to do this without STUN?
 
The STUN just detects the information and fills it in for you, if nothing has changed/will change you needn't run it again, just statically programme the info :)

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top