Solved

Mikrotik routerboard 1100 x2h need to open ports - voip

Posted on 2013-06-13
14
2,324 Views
Last Modified: 2013-07-15
I have a Mikrotik routerboard 1100 x2h router and I need to open udp ports both incoming and out going for voip service. the ports are 5199, 3479, 5060 and range 2222 - 2269. I have tried from the web gui and winbox and cant figure the correct settings. Could someone please help with this?
0
Comment
Question by:premiumts
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 6
14 Comments
 
LVL 22

Expert Comment

by:eeRoot
ID: 39249332
Can you post a screenshot from the web gui showing what is not working?
0
 

Author Comment

by:premiumts
ID: 39250093
Hi  eeRoot

There are a few different screens. I will take screenshots today and attach them.

Thanks
0
 
LVL 4

Expert Comment

by:MarcusSjogren
ID: 39253080
Hi,

Please see my attached image.

1. Specify chain, usualy "input", could also be "forward" if the packets are passing from one mikrotik interface to another.

2. Specify destination address (if you want to)

3. Specify protocol as "UDP"

4. Specify destination port.
Destination port formats are either <P>, <P1-Pn> or <P1,P2,P3 ... Pn> where P is port number.

Good luck!

Edit: Depending on your config you might need to make an identical rule with the chain "output" and to also specify which interface the traffic is going to/from.
To enable outbound on ether1 you would set chain="output" and "out-interface=ether1" and vice versa for input.

Also note that Mikrotik reads the access-list from top to bottom and catches first match.
Winbox-Firewall.png
0
Now Available: Firebox Cloud for AWS and FireboxV

Firebox Cloud brings the protection of WatchGuard’s leading Firebox UTM appliances to public cloud environments. It enables organizations to extend their security perimeter to protect business-critical assets in Amazon Web Services (AWS).

 

Author Comment

by:premiumts
ID: 39253586
I have uploaded screen shots of the firewall rules and nat rules. I added the UPD rules as stated and still no luck. We can make outbound calls but incoming calls phones dont ring
router.rtf
0
 
LVL 4

Expert Comment

by:MarcusSjogren
ID: 39253623
Hi,

On which ether-interface is the telephone traffic originated?

Marcus
0
 

Author Comment

by:premiumts
ID: 39253633
we have the switch which the phone is plugged into on eth 11
0
 

Author Comment

by:premiumts
ID: 39253636
so eth 1 is internet and eth 11 is switch on router
0
 
LVL 4

Expert Comment

by:MarcusSjogren
ID: 39253694
The Mikrotik is using IP tables (more or less) for the firewall, which makes it a little bit different than Cisco and other common firewalls.

Here is a quite good description of how it works. I think that you need to put a new rule above rule #3 which is "forward", "UDP", "<ports>", "in-interface=Ether11".

After that I believe you should be able to remove the rule added for "output"-chain.

http://www.mikrotik.com/testdocs/ros/2.9/ip/flow.php
0
 

Author Comment

by:premiumts
ID: 39253738
I got lost reading the art but did add a rule at number 2 of "forward", "UDP", "<ports>", "in-interface=Ether11 - still same thing.
0
 
LVL 4

Expert Comment

by:MarcusSjogren
ID: 39254580
How is this setup? Is ether11 its own subnet?
If so, can you ping the mikrotik ether11 and ether1 from behind it if you put an "allow everything, in-interface=Ether11"? E.g you connect a laptop to the switch.

Just to start of with the knowledge that you have the proper connectivity.
0
 

Author Comment

by:premiumts
ID: 39254600
The way it is setup is there are 2 vlans on the router. Lets say ports 1,2,3,4,11,12 are vlan 1 which is 10.0.0.x subnet. then ports 5,6,7,8 are vlan 2 which is a 192.168.10.x network just for wireless routers throughout the building.

10.0.0.x is the internal network and voip phones.

From the server I can ping the phones IP address and also pull up the web gui of the phone. I can pint the internal and external address of the router.

From the router I can also ping the phone address.

The odd thing is if I call the phone 50 times maybe 1 or 2 times out of the 50 the phone will ring. The rest of the times I will hear the ringing on my cell phone but the physical phone will never ring.

EDIT: Ps. this was setup by an outside consultant for the company and when we asked him he had no clue as to how to get this working
0
 
LVL 4

Expert Comment

by:MarcusSjogren
ID: 39255415
If you look at interfaces in the router and compare the rx and tx utilization vs what you have purchased from you provider, are you almost reaching the maximum?

Sound like a QoS-issue to be honest. There is no way the access-rules work 2 times out of 50.

Does it work if you only have the telephones connected (no PCs etc)?
0
 

Author Comment

by:premiumts
ID: 39256159
I know its not a qos issue as we are no where near the limit. I already tried shuting off all computers and it is the same result.

If I plug a phone directly into the isp modem there are no issues. It is as soon as it is put back behind the Mikrotik that the issues happen
0
 
LVL 4

Accepted Solution

by:
MarcusSjogren earned 500 total points
ID: 39257478
Hi,

By the way... You have an outgoing NAT for ether1 and 2 so There must be some incoming NAT on Ether1 or it won't work. I suppose the PBX tries to contact the IP of Ether1 when calls are coming in, right?

So, you have to make a dst-NAT for in-interface=ether1, protocol=UDP and the ports that you stated in the access-list.

Please send IP of Ether1, Ether11, IP-phone and what IP the PBX tries to contact on incoming calls.

Marcus
0

Featured Post

Surfing Is Meant To Be Done Outdoors

Featuring its rugged IP67 compliant exterior and delivering broad, fast, and reliable Wi-Fi coverage, the AP322 is the ideal solution for the outdoors. Manage this AP with either a Firebox as a gateway controller, or with the Wi-Fi Cloud for an expanded set of management features

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Price for Fiber 13 61
Network setup between buildings 4 57
Port to open for RDP connection to VM in DMZ ? 5 64
Unidentified Network 12 54
In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question