Juniper 5gt SIP configuration example

My customer bought a 5gt and wants to use it solely for voip.  Does anybody have a configuration example of what this needs to look like?  I don't have web access to the firewall.  It is sitting on a desk with a console cable on it.
dhuff2012Asked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
Sanga CollinsConnect With a Mentor Systems AdminCommented:
unset alg sip enable
set policy id 1 from "Trust" to "Untrust"  "Any" "Any" "ANY" nat src permit log
save

The above commands will accomplish the required setting
0
 
Phyo HTET AUNGNetwork Security AnalystCommented:
hope this might help.

Solution From Juniper Forum
0
 
Sanga CollinsSystems AdminCommented:
The setup will depend on where the VOIP server sits. Is the server and phones going to be behind the firewall? Or is the server going to be outside the firewall and the phones inside?
0
Improved Protection from Phishing Attacks

WatchGuard DNSWatch reduces malware infections by detecting and blocking malicious DNS requests, improving your ability to protect employees from phishing attacks. Learn more about our newest service included in Total Security Suite today!

 
dhuff2012Author Commented:
I'm not sure yet.  The customer is getting that info for me.  In the meanwhile I have put a config on the firewall to ship it to them.  I can continue configuration once it is in place.  Would you mind looking at the config and let me know if I'm missing anything?  I'm concerned about the default route as I'm used to Cisco cli and this is quite different.
voice-fw-config.docx
0
 
Sanga CollinsSystems AdminCommented:
Since this appears to be at least screenOS 6.x or newer the following statement in your config should be sufficient

set interface ethernet 0/0 gateway 63.x.x.x

But since you said you are sending the device to a client, just to be safe you can (from the webui) add the default route under Network > Routing > Destination, or from the command line using the following command

set route 0.0.0.0/0 interface ethernet0/0 gateway 63.x.x.x
save
0
 
dhuff2012Author Commented:
Thanks.  The phone server is outside of the customer network at a place called Next Level.  Does this help?
0
 
Sanga CollinsSystems AdminCommented:
Yes that is very important. With the VoIP server residing off site, what you want to do is:

A) disable sip ALG
B) enable 'source based NAT' in the advanced properties of the trust to untrust policy. You can get to properties for a policy by clicking on the edit link for the policy in question.

I will look up the correct CLI commands to enter and post them if you only have console access.
0
 
dhuff2012Author Commented:
That would be terrific.  Please provide the cli commands.  Thank you.
0
 
dhuff2012Author Commented:
Thanks.  The FW is going in today and I will try your suggestions.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.