We help IT Professionals succeed at work.

NO AUDIO ON VOICEFLEX SIP TRUNK WITH ALCATEL OMNI PCX (WATCHGUARD X750e)

1,889 Views
Last Modified: 2012-05-10
Hello all - I have an annoying problem with SIP calls. the call goes through but no audio in both directions. Apparently you cant add a stun setting on the omni PCX? Apparently the PABX is passing the local 192.168.1.x address to the SIP provider, however noone seems to know a resolution! Will give 500 points as rtearing my hair out now!

Thanks
Comment
Watch Question

Istvan KalmarHead of IT Security Division
CERTIFIED EXPERT
Top Expert 2010

Commented:
HI,

Please show the netwrork topology...

Commented:
Place/Enable Session Border Controller in between Provider and your PBX.
I know cisco has device for SBC.
HTH
CERTIFIED EXPERT
Top Expert 2007

Commented:
Do you get any deny messages in the System Manager->Traffic monitor when this happens; this would help understand if firewall is blocking any traffic.

Few questions:
1. Is NAT configured for PBX.
2. If yes, then what type, dynamic or 1-1.
3. Which policy is configured on firewall.

If feasible for testing configure ANY policy and 1-1 NAT and check if this helps.

Thank you.

Author

Commented:
Hi,
Yes - tried ANY first - calls come up but no Audio. Tried Dynamic & 1 to 1 NAT...
have set logging but nothing seems to get allowed or denied in traffic manager.
Thanks
CERTIFIED EXPERT
Top Expert 2007

Commented:
If possible put PBX outside the firewall and then check the behavior.

Thank you.

Author

Commented:
Hi,
Not really possible. Voiceflex are saying the PABX is advertising its internal IP & this is clearly what the problem is... What I need to know is how to get it to display the external IP.
However, Alcatel doesnt have a STUN setting & Watchguard say this isnt possible?
 
Any one any ideas?
CERTIFIED EXPERT
Top Expert 2007

Commented:
Sorry dont think this comment is of much help to you but still putting it:

As you said PABX is on private IP; so it must be using firebox external interface IP by default; if you setup 1-1 NAT then it would advertise the 1-1 NAT public IP.

Am not sure if this is an option; but can you open web browser on PABX and go to http://www.whatismyip.com; this would show the public IP of PABX as seen to everyone. OR may be initiate any session from PABX and do packet capture on external interface of firebox and see what the packets have as the source IP for the specific port/protocol/destination.

Thank you.

Author

Commented:
The SIP Provider states that it is advertising the PRIVATE ip....
Thanks

policy.PNG
advanced.PNG

Author

Commented:
When I change to 1 to 1 NAT it no longer makes or receives calls....
CERTIFIED EXPERT
Top Expert 2007

Commented:
Do not configure policy based NAT. Revert to "Use Network NAT Settings".

Current policy only allows outbound traffic from internal host 192.168.1.246 to external host 146.x.x.x.

Assuming you wish to allow all inbound traffic from 146.x.x.x to 217.y.y.202, add 1-1 NAT and add one more ANY service and configure as below:
Enabled and allowed; from 146.x.x.x; to 217.y.y.202

To ensure 1-1 NAT is configured properly, please look at link below:
http://watchguard.custhelp.com/app/answers/detail/a_id/1545/kw/1-1%20NAT/p/214%2C215/sno/1

Finally make sure that 217.y.y.202 IP is not listed under external alias [used for static NAT]:
http://watchguard.custhelp.com/app/answers/detail/a_id/1497/kw/adding%20external%20alias

Thank you.

Author

Commented:
202 is the main IP address - i.e. not an alias. Is this what you mean?

Author

Commented:
So I have created a separate outbound policy as below... with 1 to 1 NAT
nat-SIPRTP.JPG

Author

Commented:
Policy
sip-RTP.JPG
CERTIFIED EXPERT
Top Expert 2007
Commented:
Unlock this solution and get a sample of our free trial.
(No credit card required)
UNLOCK SOLUTION

Author

Commented:
Are you saying I need a spare IP that is not an alias? I dont have any spare.

Author

Commented:
Great! Thanks for that. I think it was just the alias thing I hadnt tried... works fine with an aliased IP.

Thanks for your help!
CERTIFIED EXPERT
Top Expert 2007

Commented:
Welcome; Happy to be of assistance.

Thank you.
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a sample view!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.