Solved

Juniper 5gt SIP configuration example

Posted on 2013-01-07
9
713 Views
Last Modified: 2013-01-15
My customer bought a 5gt and wants to use it solely for voip.  Does anybody have a configuration example of what this needs to look like?  I don't have web access to the firewall.  It is sitting on a desk with a console cable on it.
0
Comment
Question by:dhuff2012
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
9 Comments
 
LVL 7

Expert Comment

by:Phyo HTET AUNG
ID: 38753428
hope this might help.

Solution From Juniper Forum
0
 
LVL 18

Expert Comment

by:Sanga Collins
ID: 38754796
The setup will depend on where the VOIP server sits. Is the server and phones going to be behind the firewall? Or is the server going to be outside the firewall and the phones inside?
0
 

Author Comment

by:dhuff2012
ID: 38756644
I'm not sure yet.  The customer is getting that info for me.  In the meanwhile I have put a config on the firewall to ship it to them.  I can continue configuration once it is in place.  Would you mind looking at the config and let me know if I'm missing anything?  I'm concerned about the default route as I'm used to Cisco cli and this is quite different.
voice-fw-config.docx
0
Now Available: Firebox Cloud for AWS and FireboxV

Firebox Cloud brings the protection of WatchGuard’s leading Firebox UTM appliances to public cloud environments. It enables organizations to extend their security perimeter to protect business-critical assets in Amazon Web Services (AWS).

 
LVL 18

Expert Comment

by:Sanga Collins
ID: 38756801
Since this appears to be at least screenOS 6.x or newer the following statement in your config should be sufficient

set interface ethernet 0/0 gateway 63.x.x.x

But since you said you are sending the device to a client, just to be safe you can (from the webui) add the default route under Network > Routing > Destination, or from the command line using the following command

set route 0.0.0.0/0 interface ethernet0/0 gateway 63.x.x.x
save
0
 

Author Comment

by:dhuff2012
ID: 38756984
Thanks.  The phone server is outside of the customer network at a place called Next Level.  Does this help?
0
 
LVL 18

Expert Comment

by:Sanga Collins
ID: 38757055
Yes that is very important. With the VoIP server residing off site, what you want to do is:

A) disable sip ALG
B) enable 'source based NAT' in the advanced properties of the trust to untrust policy. You can get to properties for a policy by clicking on the edit link for the policy in question.

I will look up the correct CLI commands to enter and post them if you only have console access.
0
 

Author Comment

by:dhuff2012
ID: 38757095
That would be terrific.  Please provide the cli commands.  Thank you.
0
 
LVL 18

Accepted Solution

by:
Sanga Collins earned 500 total points
ID: 38757539
unset alg sip enable
set policy id 1 from "Trust" to "Untrust"  "Any" "Any" "ANY" nat src permit log
save

The above commands will accomplish the required setting
0
 

Author Closing Comment

by:dhuff2012
ID: 38778961
Thanks.  The FW is going in today and I will try your suggestions.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to limit traffic to Netscaler 10.5 VIP 3 130
Setup another VLAN on Fortigate 3 38
VLAN Question 13 60
Rensome / malware protection 9 71
It’s 2016. Password authentication should be dead — or at least close to dying. But, unfortunately, it has not traversed Quagga stage yet. Using password authentication is like laundering hotel guest linens with a washboard — it’s Passé.
Transferring data across the virtual world became simpler but protecting it is becoming a real security challenge.  How to approach cyber security  in today's business world!
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question