VOIP over IPSEC tunnel - no voice after ringing

Posted on 2010-11-10
Medium Priority
Last Modified: 2012-05-10
Hello All,

We have a VOIP environment, please see the attached image. We use Asterix 1.6 VOIP server running on Debian Linux, 2 pcs of Juniper SSG-5 routers with 6.3.0r5 firmware, and a Linksys VOIP phones. We have been installed and configured the Asterix server, configured trust-untrust policies on the SSG-5 routers, and set up the phones. All phones in SITE1 have been registered on the Asterix server located in SITE2 via IPSEC tunnel.

Our problem is very strange, i try to explain it:

1. When phone turns on, registers well, incoming and outgoing calls works (rings and voice).

2. After approx 5 minutes, incoming calls will be fail, because the phone rings, but no voice when picks up, and the IP phone displays still "Answering ..." and the caller phone shows "Calling ...". After we take down the IP phone, the caller shows still "Calling ...", until call expires because time-out.
3. If I call back the caller from the IP phone, the call works  (rings and voice as well).
4. After the calling back the incoming calls work well, but after approx 5 minutes idle time still no voice of incoming calls, until I make a call from the IP phone to outside.
The phone has been registered continuously.

We checked the follows:
- turned off SIP feature in the ALG in the SSG-5;
- defined voice protocol group in SSG-5 (UDP traffic between port 10000:20000);
- created trust-to-untrust policy in each SSG-5 which allows ANY traffic between the IP phone and Asterix server in both side and vice-versa;
- turned off any iptables firewall in the Asterix Server (all packets accepted);
- logged traffic in SSG-5 by policy, and ensured no dropped packets.

Any idea or suggestions please?

Question by:Cook77
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 18

Expert Comment

ID: 34111156
It sounds like a routing issue from the server to the IP phone. when you turn on the IP phone it registers by initiating communication with the asterix server. the keep-alives from the phone to the server work because the phone knows how to get to the VOIP server. after a period of time the communication from the VOIP server times out and the communications from the outside fails.

Try this as a test. set up a continuous ping from the asterix server to the IP phone. wait five minutes and then try to make a call, if it works your have to do something on the VOIP server to aintain the route to the remote phone. This could be as simple as adding a static route to the IP phone network on the VOIP server using the SSG5-B as a gateway.

if this doesn't work I have more tricks up my sleeve.

let us know what you come up with.


Author Comment

ID: 34111635
I tried but when I made the second call the problem still here! The IP phone displays answering and no voice communication up ... Please search through your sleeve some more tricks! :)

Expert Comment

ID: 34111673
You're missing one important port related to VoIP.  5060 must also be allowed.

In your sip.conf entry for the phone,especially the one just connecting over the raw internet, make sure you have a nat=yes setting.

Ransomware Attacks Keeping You Up at Night?

Will your organization be ransomware's next victim?  The good news is that these attacks are predicable and therefore preventable. Learn more about how you can  stop a ransomware attacks before encryption takes place with our Ransomware Prevention Kit!

LVL 18

Expert Comment

ID: 34111909
Yes SIP needs to be allowed...

Also there are two parts to every IP phone call. the C&C and the audio stream(s). when a call gets initiated the C&C is responsible for setting up a call, this is what gives you your ringing and the presentation on the phone and then it connects the audio streams in both directions.

If the hone rings then you have call set up working that means that the VOIP server can receive input from both sides and communicate with both sides. After the call set up finishes the VOIP server drops out and lets the endpoints communicate directly with each other. My guess is that your voice gateway cannot initiate traffic to your remote IP phone.

Go to your public gateway and try to ping your IP phone. if that doesn't work add a static route and try again.

hope this helps,


Author Comment

ID: 34112442
I think the 5060/tcp port thing is only a joke! :) Of course these ports open (now the asterix side iptalbles is all ACCEPT, only for testing time) and no service restricting in the ssg5 policies.

I try to add the nat=yes line in sip.conf I hope I put it in the right section:

callerid=PAC <xxxxxxx>

I check decoleur suggesion and I write back!

Accepted Solution

Cook77 earned 0 total points
ID: 34810848
The solution: we moved the Asterisk server to SITE1, and redirected all VOIP traffic to SITE1 in out ISP - it solved the problem. It seems, the VOIP does not work well within a IPSEC tunnel in our environment.
Thanks all!
LVL 70

Expert Comment

ID: 34811651
Asker provided a workaround useful for the PAQ.

Cleanup Volunteer

Expert Comment

ID: 34849970
Starting the auto-close procedure on behalf of the question asker.

Community Support Moderator

Featured Post

Want to be a Web Developer? Get Certified Today!

Enroll in the Certified Web Development Professional course package to learn HTML, Javascript, and PHP. Build a solid foundation to work toward your dream job!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For a while, I have wanted to connect my HTC Incredible to my corporate network to take advantage of the phone's powerful capabilities. I searched online and came up with varied answers from "it won't work" to super complicated statements that I did…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question