Solved

Trying to open port 5060 for SIP

Posted on 2008-10-16
4
1,615 Views
Last Modified: 2008-11-10
Trying to configure an access list to allow port 5060 for SIP.
When I get to the eq 5060 command at the end of the line, I get unrecognized command.
I am running 12.4 IOS on a 2851 router.
what am I doing wrong? We are trying to get to the VOIP gateway. We are getting there, only the ports we need are not open. I am very new to setting up SIP. This is all being done on the inside network from an IVR server. I am running router on a stick, with the phone VLANS hanging off the router gateway interface.
0
Comment
Question by:Jack_Knight
  • 2
  • 2
4 Comments
 
LVL 8

Expert Comment

by:MrJemson
ID: 22738093
You will need to use an extended ACL in order to use eq.
Could you please cut and paste the exact line you are trying to implement?
0
 

Author Comment

by:Jack_Knight
ID: 22739318
Thanks! I was trying to use a standard.
Here is the line
permit tcp any any eq 5060
permit udp any any eq 50

I was also creating an accesss list for this. Do I need to attach this to the interface also?
Thanks for the quick response.
0
 

Author Comment

by:Jack_Knight
ID: 22739661
More problems.
I created a new access list.

access-list 150 permit tcp any any eq 5060
acess-list 150 permit udp any any eq 5060

I then proceeded to attach it to the interface of the network I want to use

ip access-group 150 in

After I did this the router died.

What the heck am I doing wrong?
0
 
LVL 8

Accepted Solution

by:
MrJemson earned 125 total points
ID: 22746775
Hello,

Yes you need to apply the Access List to an interface, but it looks like you figured that out in your second post.

The issue you are having is that at the end of ANY access-list, there is an implicit "DENY ANY ANY" statement. This is the default behaviour and cannot be changed. The problem I imagine, is that you are connecting remotely into the router, and you are applying the access list to the interface you are connecting through. If this is the case, you should modify your access list in order to still allow your connection method.
Eg. (If you are using SSH)
access-list 150 permit tcp any any eq 5060
acess-list 150 permit udp any any eq 5060
acess-list 150 permit tcp any any eq 22

THAT SAID, If you are actually trying to Port Forward to an internal SIP server, this will not achieve your goal...

If you want to Port Forward, you will need to issue:
ip nat inside source static tcp <INTERNAL IP> 5060 interface <EXTERNAL INT> 5060
ip nat inside source static udp <INTERNAL IP> 5060 interface <EXTERNAL INT> 5060

Eg: ip nat inside source static tcp 10.10.10.10 5060 interface Dialer0 5060

For this to work you will need to ensure NAT is operating on the router, but from your above description of your network it sounds like you would be NAT'ing correctly.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is a guide to configure bridging on Cisco Routers.  This is something I never knew was possible until after making a few phone calls to Cisco.  Using bridging saved our company money by not requiring us to purchase a new switch.  Bridgi…
The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question