?
Solved

Juniper 5gt SIP configuration example

Posted on 2013-01-07
9
Medium Priority
?
720 Views
Last Modified: 2013-01-15
My customer bought a 5gt and wants to use it solely for voip.  Does anybody have a configuration example of what this needs to look like?  I don't have web access to the firewall.  It is sitting on a desk with a console cable on it.
0
Comment
Question by:dhuff2012
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
9 Comments
 
LVL 7

Expert Comment

by:Phyo HTET AUNG
ID: 38753428
hope this might help.

Solution From Juniper Forum
0
 
LVL 18

Expert Comment

by:Sanga Collins
ID: 38754796
The setup will depend on where the VOIP server sits. Is the server and phones going to be behind the firewall? Or is the server going to be outside the firewall and the phones inside?
0
 

Author Comment

by:dhuff2012
ID: 38756644
I'm not sure yet.  The customer is getting that info for me.  In the meanwhile I have put a config on the firewall to ship it to them.  I can continue configuration once it is in place.  Would you mind looking at the config and let me know if I'm missing anything?  I'm concerned about the default route as I'm used to Cisco cli and this is quite different.
voice-fw-config.docx
0
Learn how to optimize MySQL for your business need

With the increasing importance of apps & networks in both business & personal interconnections, perfor. has become one of the key metrics of successful communication. This ebook is a hands-on business-case-driven guide to understanding MySQL query parameter tuning & database perf

 
LVL 18

Expert Comment

by:Sanga Collins
ID: 38756801
Since this appears to be at least screenOS 6.x or newer the following statement in your config should be sufficient

set interface ethernet 0/0 gateway 63.x.x.x

But since you said you are sending the device to a client, just to be safe you can (from the webui) add the default route under Network > Routing > Destination, or from the command line using the following command

set route 0.0.0.0/0 interface ethernet0/0 gateway 63.x.x.x
save
0
 

Author Comment

by:dhuff2012
ID: 38756984
Thanks.  The phone server is outside of the customer network at a place called Next Level.  Does this help?
0
 
LVL 18

Expert Comment

by:Sanga Collins
ID: 38757055
Yes that is very important. With the VoIP server residing off site, what you want to do is:

A) disable sip ALG
B) enable 'source based NAT' in the advanced properties of the trust to untrust policy. You can get to properties for a policy by clicking on the edit link for the policy in question.

I will look up the correct CLI commands to enter and post them if you only have console access.
0
 

Author Comment

by:dhuff2012
ID: 38757095
That would be terrific.  Please provide the cli commands.  Thank you.
0
 
LVL 18

Accepted Solution

by:
Sanga Collins earned 2000 total points
ID: 38757539
unset alg sip enable
set policy id 1 from "Trust" to "Untrust"  "Any" "Any" "ANY" nat src permit log
save

The above commands will accomplish the required setting
0
 

Author Closing Comment

by:dhuff2012
ID: 38778961
Thanks.  The FW is going in today and I will try your suggestions.
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It’s 2016. Password authentication should be dead — or at least close to dying. But, unfortunately, it has not traversed Quagga stage yet. Using password authentication is like laundering hotel guest linens with a washboard — it’s Passé.
Keystroke loggers have been around for a very long time. While the threat is old, some of the remedies are new!
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
Suggested Courses

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question