?
Solved

Trying to open port 5060 for SIP

Posted on 2008-10-16
4
Medium Priority
?
1,641 Views
Last Modified: 2008-11-10
Trying to configure an access list to allow port 5060 for SIP.
When I get to the eq 5060 command at the end of the line, I get unrecognized command.
I am running 12.4 IOS on a 2851 router.
what am I doing wrong? We are trying to get to the VOIP gateway. We are getting there, only the ports we need are not open. I am very new to setting up SIP. This is all being done on the inside network from an IVR server. I am running router on a stick, with the phone VLANS hanging off the router gateway interface.
0
Comment
Question by:Jack_Knight
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 8

Expert Comment

by:MrJemson
ID: 22738093
You will need to use an extended ACL in order to use eq.
Could you please cut and paste the exact line you are trying to implement?
0
 

Author Comment

by:Jack_Knight
ID: 22739318
Thanks! I was trying to use a standard.
Here is the line
permit tcp any any eq 5060
permit udp any any eq 50

I was also creating an accesss list for this. Do I need to attach this to the interface also?
Thanks for the quick response.
0
 

Author Comment

by:Jack_Knight
ID: 22739661
More problems.
I created a new access list.

access-list 150 permit tcp any any eq 5060
acess-list 150 permit udp any any eq 5060

I then proceeded to attach it to the interface of the network I want to use

ip access-group 150 in

After I did this the router died.

What the heck am I doing wrong?
0
 
LVL 8

Accepted Solution

by:
MrJemson earned 375 total points
ID: 22746775
Hello,

Yes you need to apply the Access List to an interface, but it looks like you figured that out in your second post.

The issue you are having is that at the end of ANY access-list, there is an implicit "DENY ANY ANY" statement. This is the default behaviour and cannot be changed. The problem I imagine, is that you are connecting remotely into the router, and you are applying the access list to the interface you are connecting through. If this is the case, you should modify your access list in order to still allow your connection method.
Eg. (If you are using SSH)
access-list 150 permit tcp any any eq 5060
acess-list 150 permit udp any any eq 5060
acess-list 150 permit tcp any any eq 22

THAT SAID, If you are actually trying to Port Forward to an internal SIP server, this will not achieve your goal...

If you want to Port Forward, you will need to issue:
ip nat inside source static tcp <INTERNAL IP> 5060 interface <EXTERNAL INT> 5060
ip nat inside source static udp <INTERNAL IP> 5060 interface <EXTERNAL INT> 5060

Eg: ip nat inside source static tcp 10.10.10.10 5060 interface Dialer0 5060

For this to work you will need to ensure NAT is operating on the router, but from your above description of your network it sounds like you would be NAT'ing correctly.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We've been using the Cisco/Linksys RV042 for years as: - an internet Gateway - a site-to-site VPN device - a leased line site-to-site subnet-to-subnet interface (And, here I'm assuming that any RV0xx behaves the same way as an RV042.  So that's …
Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question