Solved

Mikrotik routerboard 1100 x2h need to open ports - voip

Posted on 2013-06-13
14
2,266 Views
Last Modified: 2013-07-15
I have a Mikrotik routerboard 1100 x2h router and I need to open udp ports both incoming and out going for voip service. the ports are 5199, 3479, 5060 and range 2222 - 2269. I have tried from the web gui and winbox and cant figure the correct settings. Could someone please help with this?
0
Comment
Question by:premiumts
  • 7
  • 6
14 Comments
 
LVL 22

Expert Comment

by:eeRoot
ID: 39249332
Can you post a screenshot from the web gui showing what is not working?
0
 

Author Comment

by:premiumts
ID: 39250093
Hi  eeRoot

There are a few different screens. I will take screenshots today and attach them.

Thanks
0
 
LVL 4

Expert Comment

by:MarcusSjogren
ID: 39253080
Hi,

Please see my attached image.

1. Specify chain, usualy "input", could also be "forward" if the packets are passing from one mikrotik interface to another.

2. Specify destination address (if you want to)

3. Specify protocol as "UDP"

4. Specify destination port.
Destination port formats are either <P>, <P1-Pn> or <P1,P2,P3 ... Pn> where P is port number.

Good luck!

Edit: Depending on your config you might need to make an identical rule with the chain "output" and to also specify which interface the traffic is going to/from.
To enable outbound on ether1 you would set chain="output" and "out-interface=ether1" and vice versa for input.

Also note that Mikrotik reads the access-list from top to bottom and catches first match.
Winbox-Firewall.png
0
 

Author Comment

by:premiumts
ID: 39253586
I have uploaded screen shots of the firewall rules and nat rules. I added the UPD rules as stated and still no luck. We can make outbound calls but incoming calls phones dont ring
router.rtf
0
 
LVL 4

Expert Comment

by:MarcusSjogren
ID: 39253623
Hi,

On which ether-interface is the telephone traffic originated?

Marcus
0
 

Author Comment

by:premiumts
ID: 39253633
we have the switch which the phone is plugged into on eth 11
0
 

Author Comment

by:premiumts
ID: 39253636
so eth 1 is internet and eth 11 is switch on router
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 4

Expert Comment

by:MarcusSjogren
ID: 39253694
The Mikrotik is using IP tables (more or less) for the firewall, which makes it a little bit different than Cisco and other common firewalls.

Here is a quite good description of how it works. I think that you need to put a new rule above rule #3 which is "forward", "UDP", "<ports>", "in-interface=Ether11".

After that I believe you should be able to remove the rule added for "output"-chain.

http://www.mikrotik.com/testdocs/ros/2.9/ip/flow.php
0
 

Author Comment

by:premiumts
ID: 39253738
I got lost reading the art but did add a rule at number 2 of "forward", "UDP", "<ports>", "in-interface=Ether11 - still same thing.
0
 
LVL 4

Expert Comment

by:MarcusSjogren
ID: 39254580
How is this setup? Is ether11 its own subnet?
If so, can you ping the mikrotik ether11 and ether1 from behind it if you put an "allow everything, in-interface=Ether11"? E.g you connect a laptop to the switch.

Just to start of with the knowledge that you have the proper connectivity.
0
 

Author Comment

by:premiumts
ID: 39254600
The way it is setup is there are 2 vlans on the router. Lets say ports 1,2,3,4,11,12 are vlan 1 which is 10.0.0.x subnet. then ports 5,6,7,8 are vlan 2 which is a 192.168.10.x network just for wireless routers throughout the building.

10.0.0.x is the internal network and voip phones.

From the server I can ping the phones IP address and also pull up the web gui of the phone. I can pint the internal and external address of the router.

From the router I can also ping the phone address.

The odd thing is if I call the phone 50 times maybe 1 or 2 times out of the 50 the phone will ring. The rest of the times I will hear the ringing on my cell phone but the physical phone will never ring.

EDIT: Ps. this was setup by an outside consultant for the company and when we asked him he had no clue as to how to get this working
0
 
LVL 4

Expert Comment

by:MarcusSjogren
ID: 39255415
If you look at interfaces in the router and compare the rx and tx utilization vs what you have purchased from you provider, are you almost reaching the maximum?

Sound like a QoS-issue to be honest. There is no way the access-rules work 2 times out of 50.

Does it work if you only have the telephones connected (no PCs etc)?
0
 

Author Comment

by:premiumts
ID: 39256159
I know its not a qos issue as we are no where near the limit. I already tried shuting off all computers and it is the same result.

If I plug a phone directly into the isp modem there are no issues. It is as soon as it is put back behind the Mikrotik that the issues happen
0
 
LVL 4

Accepted Solution

by:
MarcusSjogren earned 500 total points
ID: 39257478
Hi,

By the way... You have an outgoing NAT for ether1 and 2 so There must be some incoming NAT on Ether1 or it won't work. I suppose the PBX tries to contact the IP of Ether1 when calls are coming in, right?

So, you have to make a dst-NAT for in-interface=ether1, protocol=UDP and the ports that you stated in the access-list.

Please send IP of Ether1, Ether11, IP-phone and what IP the PBX tries to contact on incoming calls.

Marcus
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now