?
Solved

Cisco CME SIP issue

Posted on 2012-03-18
6
Medium Priority
?
942 Views
Last Modified: 2013-02-05
Hi,

I have a Cisco 2811 (CME) and it is registering with an external SIP provider (ITSP) for external calls.

I am also trying to setup SIP extensions to run over a VPN to a remote site. The 2811 ISR is doing the SIP trunk termination, CME SIP registrations and the IPSec VPN Tunnel.  

What is happening, unless I add the command below, the SIP phones cannot register

voice service voip
sip
 bind all source-interface fa0/0.1 (which is the internal VLAN)

However, when I add this command the SIP trunk to the ITSP drops and doesn't work.

Does anyone know how to fix this?

Thanks

Mark
0
Comment
Question by:mark_06
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
6 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 37735226
If it is currently bound to the outside interface, just add that address to the IPSEC VPN tunnel access-list so it will be encrypted..
0
 
LVL 6

Author Comment

by:mark_06
ID: 37735571
Thanks for the response!

I am not sure I follow 100%.

So I need to configure the public IP of the remote site to the access-list of the VPN tunnel, is that what you are saying?
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 1500 total points
ID: 37735967
Yes. For example:

bind all source-interface fa0/1  <- WAN Interface

interface fast 0/1
 ip address 1.1.1.1 255.255.255.0

interface fast 0/0.1  <- LAN interface
 ip address 192.168.100.1 255.255.255.0

# Acl 106 defines traffic to be encrypted and applied to the crypto map
access-list 106 permit ip 192.168.100.0 0.0.0.255 192.168.200.0 0.0.0.255
access-list 106 permit ip host 1.1.1.1 192.168.200.0 0.0.0.255
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 
LVL 6

Author Comment

by:mark_06
ID: 37737087
That has worked. Except I am now getting one way audio. The caller in the remote site cannot hear the person from the main site. However the user at the main site can hear the remote site.

This is the config (assuming WAN IP is 1.1.1.1), the remote site is 192.168.12.0/24

voice register global
 mode cme
 source-address 1.1.1.1 port 5060
 max-dn 10
 max-pool 10
 authenticate register
 voicemail 150
!
voice register dn  1
 number 400
!
voice register pool  1
 id mac 0000.0000.0400
 number 1 dn 1
 username 400 password 1234PW
 codec g711ulaw


access-list 118 permit ip 192.168.1.0 0.0.0.255 192.168.12.0 0.0.0.255
access-list 118 permit ip 192.168.4.0 0.0.0.255 192.168.12.0 0.0.0.255
access-list 118 permit ip host 1.1.1.1 192.168.12.0 0.0.0.255


In terms of my NAT (as one way voice can often be caused by it) this is what I have. (not there are more subnets as there are multiple VPN sites)

ip nat inside source list 100 interface FastEthernet0/1 overload

access-list 100 deny   ip 192.168.1.0 0.0.0.255 192.168.8.0 0.0.0.255
access-list 100 deny   ip 192.168.1.0 0.0.0.255 192.168.168.0 0.0.0.255
access-list 100 deny   ip 192.168.1.0 0.0.0.255 192.168.12.0 0.0.0.255
access-list 100 deny   ip 192.168.4.0 0.0.0.255 192.168.8.0 0.0.0.255
access-list 100 deny   ip 192.168.4.0 0.0.0.255 192.168.168.0 0.0.0.255
access-list 100 deny   ip 192.168.4.0 0.0.0.255 192.168.12.0 0.0.0.255
access-list 100 permit ip 192.168.1.0 0.0.0.255 any
access-list 100 permit ip 192.168.4.0 0.0.0.255 any
access-list 100 permit ip 192.168.20.0 0.0.0.255 any
access-list 100 deny   ip any any
0
 
LVL 6

Author Comment

by:mark_06
ID: 37737159
Looking through the SIP debugs it looks as if it's sending the packets over the external WAN rather than through the VPN tunnel.
0
 
LVL 6

Author Closing Comment

by:mark_06
ID: 38854608
Technically correct. As all the research I have done supports this. However I am still having some funny issues.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Ever wanted to query Cisco Call Manager CDR records from MS SQL Server? Here's how! CUCM can be configured to upload a CDR file to a given FTP server every minute. This article will show you how to set this up, schedule the import of this data an…
Implementing Avaya's One-X portal is pretty painless, until you want to deploy this to the Android and iPhone clients when these clients are outside of your network. The clients will also work within your local network. Here is our experience and so…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
Do you want to know how to make a graph with Microsoft Access? First, create a query with the data for the chart. Then make a blank form and add a chart control. This video also shows how to change what data is displayed on the graph as well as form…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question