[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now


VOIP over IPSEC tunnel - no voice after ringing

Posted on 2010-11-10
Medium Priority
Last Modified: 2012-05-10
Hello All,

We have a VOIP environment, please see the attached image. We use Asterix 1.6 VOIP server running on Debian Linux, 2 pcs of Juniper SSG-5 routers with 6.3.0r5 firmware, and a Linksys VOIP phones. We have been installed and configured the Asterix server, configured trust-untrust policies on the SSG-5 routers, and set up the phones. All phones in SITE1 have been registered on the Asterix server located in SITE2 via IPSEC tunnel.

Our problem is very strange, i try to explain it:

1. When phone turns on, registers well, incoming and outgoing calls works (rings and voice).

2. After approx 5 minutes, incoming calls will be fail, because the phone rings, but no voice when picks up, and the IP phone displays still "Answering ..." and the caller phone shows "Calling ...". After we take down the IP phone, the caller shows still "Calling ...", until call expires because time-out.
3. If I call back the caller from the IP phone, the call works  (rings and voice as well).
4. After the calling back the incoming calls work well, but after approx 5 minutes idle time still no voice of incoming calls, until I make a call from the IP phone to outside.
The phone has been registered continuously.

We checked the follows:
- turned off SIP feature in the ALG in the SSG-5;
- defined voice protocol group in SSG-5 (UDP traffic between port 10000:20000);
- created trust-to-untrust policy in each SSG-5 which allows ANY traffic between the IP phone and Asterix server in both side and vice-versa;
- turned off any iptables firewall in the Asterix Server (all packets accepted);
- logged traffic in SSG-5 by policy, and ensured no dropped packets.

Any idea or suggestions please?

Question by:Cook77
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 18

Expert Comment

ID: 34111156
It sounds like a routing issue from the server to the IP phone. when you turn on the IP phone it registers by initiating communication with the asterix server. the keep-alives from the phone to the server work because the phone knows how to get to the VOIP server. after a period of time the communication from the VOIP server times out and the communications from the outside fails.

Try this as a test. set up a continuous ping from the asterix server to the IP phone. wait five minutes and then try to make a call, if it works your have to do something on the VOIP server to aintain the route to the remote phone. This could be as simple as adding a static route to the IP phone network on the VOIP server using the SSG5-B as a gateway.

if this doesn't work I have more tricks up my sleeve.

let us know what you come up with.


Author Comment

ID: 34111635
I tried but when I made the second call the problem still here! The IP phone displays answering and no voice communication up ... Please search through your sleeve some more tricks! :)

Expert Comment

ID: 34111673
You're missing one important port related to VoIP.  5060 must also be allowed.

In your sip.conf entry for the phone,especially the one just connecting over the raw internet, make sure you have a nat=yes setting.

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

LVL 18

Expert Comment

ID: 34111909
Yes SIP needs to be allowed...

Also there are two parts to every IP phone call. the C&C and the audio stream(s). when a call gets initiated the C&C is responsible for setting up a call, this is what gives you your ringing and the presentation on the phone and then it connects the audio streams in both directions.

If the hone rings then you have call set up working that means that the VOIP server can receive input from both sides and communicate with both sides. After the call set up finishes the VOIP server drops out and lets the endpoints communicate directly with each other. My guess is that your voice gateway cannot initiate traffic to your remote IP phone.

Go to your public gateway and try to ping your IP phone. if that doesn't work add a static route and try again.

hope this helps,


Author Comment

ID: 34112442
I think the 5060/tcp port thing is only a joke! :) Of course these ports open (now the asterix side iptalbles is all ACCEPT, only for testing time) and no service restricting in the ssg5 policies.

I try to add the nat=yes line in sip.conf I hope I put it in the right section:

callerid=PAC <xxxxxxx>

I check decoleur suggesion and I write back!

Accepted Solution

Cook77 earned 0 total points
ID: 34810848
The solution: we moved the Asterisk server to SITE1, and redirected all VOIP traffic to SITE1 in out ISP - it solved the problem. It seems, the VOIP does not work well within a IPSEC tunnel in our environment.
Thanks all!
LVL 71

Expert Comment

ID: 34811651
Asker provided a workaround useful for the PAQ.

Cleanup Volunteer

Expert Comment

ID: 34849970
Starting the auto-close procedure on behalf of the question asker.

Community Support Moderator

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Juniper VPN devices are a popular alternative to using Cisco products. Last year I needed to set up an international site-to-site VPN over the Internet, but the client had high security requirements -- FIPS 140. What and Why of FIPS 140 Federa…
Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question