Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

VOIP over IPSEC VPN has no audio

Posted on 2010-09-24
4
Medium Priority
?
2,627 Views
Last Modified: 2013-11-12
I have 2 pfsense firewalls with an IPSEC VPN between them.  everything seems to work fine except voip.  Sometimes I'll get two way audio, but generally its silent on both ends.  What's odd is that if I reset firewall states, or change settings and apply them, i can usually get the first call I try to work.  After that, it goes back to no audio.  

Here's the layout:

phones (192.168.10.0/24)  >>  pfsense  >>  VPN  >>  pfsense  >>  (192.168.0.0/24) asterisk

Phones are registering to the local IP of the PBX (192.168.0.25) just fine.  I do not have any static routes.  Automatic NAT is on (for ipsec passthrough).  All ports are open properly to my SIP trunks.  Any ideas?
0
Comment
Question by:lorsungcu
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 7

Expert Comment

by:namol
ID: 33753900
can we see your sip_nat.conf file and any logs so we can attempt to troubleshoot? Shooting from the hip I'd say one of the phones is sending some of the traffic to the internet after it makes a connection.
0
 
LVL 2

Author Comment

by:lorsungcu
ID: 33753933
I'd love to give you my sip_nat.conf file, but we're using Switchvox, which gives you no access to configuration files.  Also, as this should be all over the VPN, NAT shouldn't be an issue.  If it helps, I can take screenshots of my pfsense configuration.
0
 
LVL 2

Author Comment

by:lorsungcu
ID: 33754039
When I make a call, these are the states the firewall has for the phone:
Proto   	Source -> Router -> Destination   	State   	
udp	192.168.10.199:5060 -> 192.168.0.25:5060	MULTIPLE:MULTIPLE	
udp	192.168.0.25:5060 <- 192.168.10.199:5060	MULTIPLE:MULTIPLE	
udp	192.168.1.1:123 <- 192.168.10.199:1074	NO_TRAFFIC:SINGLE	
udp	192.168.10.199:1074 -> 173.165.229.145:5945 -> 192.168.1.1:123	SINGLE:NO_TRAFFIC	
udp	192.168.0.25:55244 <- 192.168.10.199:2250	NO_TRAFFIC:SINGLE	
udp	192.168.10.199:2250 -> 192.168.0.25:55244	SINGLE:NO_TRAFFIC	
udp	192.168.0.25:55245 <- 192.168.10.199:2251	NO_TRAFFIC:SINGLE	
udp	192.168.10.199:2251 -> 192.168.0.25:55245	SINGLE:NO_TRAFFIC

Open in new window

0
 
LVL 2

Accepted Solution

by:
lorsungcu earned 0 total points
ID: 33754820
I had 1:1 NAT for the PBX, with firewall rules deciding where things can go, but apparently that wasn't enough.  I added NAT entries for RTP ports, and everything works.  Not sure I get that, but I'll take it.
0

Featured Post

Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as the high-speed power of the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question