Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
W4rh0und
New Contributor

Protect SIP on Fortigate 5.4.3

Hi everyone,

 

I am hoping that someone has hit this issue before.

 

We have an Avaya telephony system on our premise on which we have 2 SIP trunks from one SIP provider.

We configured a VIP with the required ports DNat-ed to the telephony system

We've created firewall rules to only accept traffic on that VIP from a few ip addreses of our SIP provider and to only send replies to the provider.

Still, we receive a lot of SIP login attempts from bots, and on the telephony system i keep getting authentication attempts from multiple IP's

 

With our former router (without UTM/NGFW) we just created a simple rule and we never had this issue with a simple statefull inspection firewall.

 

Can anyone point me in the right direction? Our SIP's are in use 24/7 so it is hard to just randomly test to disable SIp-helper, than SIP-ALG, etc sicne that will disrupt traffic and cause a lot of issues.

We had a case opened for this and the support reply was that it is not possible, since even if we specify a firewall rule on our VIP, the port will still be listening and reply on the internet

 

I am really hoping that someone can point me in the right direction.

 

Thank you

0 REPLIES 0
Labels
Top Kudoed Authors