Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
zeki893
New Contributor II

Panasonic VOIP Remote Phones not working over VPN nor VIP/NAT Problem

I was going through this thread and I think I'm running into a similar situation. This thread is unresolved. https://forum.fortinet.com/tm.aspx?m=65009&high=panasonic

 

Currently all the phones are connected through vpn tunnel through Cisco Meraki to Cisco Meraki. Phones are registered and can make calls. 

I migrated one Meraki to Fortigate. Now it is connected VPN tunnel through Meraki to Fortigate. 

Phones stopped working.

 

I also have remote phones that use NAT (Virtual IP) from public to private on the Meraki. After removing the Meraki and porting the NAT rules to the Fortigate, phones stopped working.  I did a packet capture and when they dial out, the destination to the voice server are using some high range ports UDP/50000+. The ports should be using UDP/16000-16511. I switched it back to the Meraki and the ports started using UDP/16000-16511 again. Is this something that has to do with the way Fortigate is handling the NAT? 

 

I've tried changing the SIP-ALG to kernel and disable sip-nat-trace, sip-helper, delete port from session-helper changes people recommend for SIP don't help. I applied them anyways and did a reboot just to see if it does but it didn't.

 

Many hours spent with migration and migrating back. I'm stumped and any help is appreciated. 

 

1 REPLY 1
pmm
New Contributor

Hi,

 

I am curious if you are using any portable Softphone applications as extensions? I have a challenge with ensuring the solutions works for SIP configured devices over forticlient VPN.  

So with Meraki this works well?

 

Regards,

 

zeki893 wrote:

I was going through this thread and I think I'm running into a similar situation. This thread is unresolved. https://forum.fortinet.com/tm.aspx?m=65009&high=panasonic

 

Currently all the phones are connected through vpn tunnel through Cisco Meraki to Cisco Meraki. Phones are registered and can make calls. 

I migrated one Meraki to Fortigate. Now it is connected VPN tunnel through Meraki to Fortigate. 

Phones stopped working.

 

I also have remote phones that use NAT (Virtual IP) from public to private on the Meraki. After removing the Meraki and porting the NAT rules to the Fortigate, phones stopped working.  I did a packet capture and when they dial out, the destination to the voice server are using some high range ports UDP/50000+. The ports should be using UDP/16000-16511. I switched it back to the Meraki and the ports started using UDP/16000-16511 again. Is this something that has to do with the way Fortigate is handling the NAT? 

 

I've tried changing the SIP-ALG to kernel and disable sip-nat-trace, sip-helper, delete port from session-helper changes people recommend for SIP don't help. I applied them anyways and did a reboot just to see if it does but it didn't.

 

Many hours spent with migration and migrating back. I'm stumped and any help is appreciated. 

 

Labels
Top Kudoed Authors