Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
619Hiker
New Contributor

RingCentral blocked, Fortigate 50E FIOs 6.2.7

Please help,

We need to get this FortiGate installed ASAP.

I was able to get the Internet to work, but our VoIP RingCentral phones had no connection.

"URL Calling disabled"

 

Does anyone have a policy set up to allow our phones to work?

Thank you so much!

4 REPLIES 4
emnoc
Esteemed Contributor III

Did you follow ringcentral network requirements from their support page? Did you do a  "diag debug flow" to identify why it's blocked?

 

If you follow the requirements on their page it should work.

 

Knowledge Article: Network Requirements and Recommendations | RingCentral Office

 

I would also NOT enable tls-decryption fwiw.

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Toshi_Esumi

When one of our customers got the service from RingCentral, the customer got the same error, I think. But it turned out that the specific policy to handle the voip traffic didn't have NAT, so no reachability. A silly mistake. After that was fixed, it seemed to be working fine. I would suggest just use a simple NAT policy first.

 

Only when/if you need to set up QoS properly as described in the doc Ken pointed to, it's a little complicated because their SIP ports are not regular 5060 range and the potential server destination subnets are quite wide ranges, etc. We implemented an abbreviated version of it.

619Hiker

Simple NAT is set up already, I can get to web sites without issue. It's just the VoIP Phones that use Ringcentral.com could not get to the internet.

I have entered all those RingCentral servers into the whitelist for web filtering. I will test again on Thursday.

 

emnoc
Esteemed Contributor III

"diag debug flow" is your best friend.

 

A summary of ports used in RC;

 

5060-6000 UDP and TCP (These ports allow the phones to register) 8000-8200 UDP only (These ports are used by the Softphones for message synchronization) 16384-65535 UDP only (These ports carry voice traffic - the RTP streams) 8801-8802 UDP and TCP (These ports are for RC Meetings & Rooms signaling via SIP) Port 80 and 443 TCP only (These ports are used for initial phone provisioning) Port 123 UDP only (This port allows NTP: date and time updates) 4000-5000 UDP (Mobile App Media) 2000060000 UDP (RTP and SRTP Soft phone) Corporate Directory (LDAP) TCP client-side 443 & 636 server-side 443 & 636

 

that should be a complete list

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors