Solved

Cisco CME SIP issue

Posted on 2012-03-18
6
895 Views
Last Modified: 2013-02-05
Hi,

I have a Cisco 2811 (CME) and it is registering with an external SIP provider (ITSP) for external calls.

I am also trying to setup SIP extensions to run over a VPN to a remote site. The 2811 ISR is doing the SIP trunk termination, CME SIP registrations and the IPSec VPN Tunnel.  

What is happening, unless I add the command below, the SIP phones cannot register

voice service voip
sip
 bind all source-interface fa0/0.1 (which is the internal VLAN)

However, when I add this command the SIP trunk to the ITSP drops and doesn't work.

Does anyone know how to fix this?

Thanks

Mark
0
Comment
Question by:mark_06
  • 4
  • 2
6 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 37735226
If it is currently bound to the outside interface, just add that address to the IPSEC VPN tunnel access-list so it will be encrypted..
0
 
LVL 6

Author Comment

by:mark_06
ID: 37735571
Thanks for the response!

I am not sure I follow 100%.

So I need to configure the public IP of the remote site to the access-list of the VPN tunnel, is that what you are saying?
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 37735967
Yes. For example:

bind all source-interface fa0/1  <- WAN Interface

interface fast 0/1
 ip address 1.1.1.1 255.255.255.0

interface fast 0/0.1  <- LAN interface
 ip address 192.168.100.1 255.255.255.0

# Acl 106 defines traffic to be encrypted and applied to the crypto map
access-list 106 permit ip 192.168.100.0 0.0.0.255 192.168.200.0 0.0.0.255
access-list 106 permit ip host 1.1.1.1 192.168.200.0 0.0.0.255
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 6

Author Comment

by:mark_06
ID: 37737087
That has worked. Except I am now getting one way audio. The caller in the remote site cannot hear the person from the main site. However the user at the main site can hear the remote site.

This is the config (assuming WAN IP is 1.1.1.1), the remote site is 192.168.12.0/24

voice register global
 mode cme
 source-address 1.1.1.1 port 5060
 max-dn 10
 max-pool 10
 authenticate register
 voicemail 150
!
voice register dn  1
 number 400
!
voice register pool  1
 id mac 0000.0000.0400
 number 1 dn 1
 username 400 password 1234PW
 codec g711ulaw


access-list 118 permit ip 192.168.1.0 0.0.0.255 192.168.12.0 0.0.0.255
access-list 118 permit ip 192.168.4.0 0.0.0.255 192.168.12.0 0.0.0.255
access-list 118 permit ip host 1.1.1.1 192.168.12.0 0.0.0.255


In terms of my NAT (as one way voice can often be caused by it) this is what I have. (not there are more subnets as there are multiple VPN sites)

ip nat inside source list 100 interface FastEthernet0/1 overload

access-list 100 deny   ip 192.168.1.0 0.0.0.255 192.168.8.0 0.0.0.255
access-list 100 deny   ip 192.168.1.0 0.0.0.255 192.168.168.0 0.0.0.255
access-list 100 deny   ip 192.168.1.0 0.0.0.255 192.168.12.0 0.0.0.255
access-list 100 deny   ip 192.168.4.0 0.0.0.255 192.168.8.0 0.0.0.255
access-list 100 deny   ip 192.168.4.0 0.0.0.255 192.168.168.0 0.0.0.255
access-list 100 deny   ip 192.168.4.0 0.0.0.255 192.168.12.0 0.0.0.255
access-list 100 permit ip 192.168.1.0 0.0.0.255 any
access-list 100 permit ip 192.168.4.0 0.0.0.255 any
access-list 100 permit ip 192.168.20.0 0.0.0.255 any
access-list 100 deny   ip any any
0
 
LVL 6

Author Comment

by:mark_06
ID: 37737159
Looking through the SIP debugs it looks as if it's sending the packets over the external WAN rather than through the VPN tunnel.
0
 
LVL 6

Author Closing Comment

by:mark_06
ID: 38854608
Technically correct. As all the research I have done supports this. However I am still having some funny issues.
0

Featured Post

3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Although VoiceOver IP has been around for a while, internet connections have only recently become fast enough to provide good call quality. Now, VoIP has become a real option for businesses looking at ways to improve their business model. In this ar…
If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
Along with being a a promotional video for my three-day Annielytics Dashboard Seminor, this Micro Tutorial is an intro to Google Analytics API data.
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now