Juniper SSG20 Not Routing SIP Traffic To Failover Interface
Posted on 2014-09-10
We have an SSG20 with 2 ADSL connections on separate interfaces in the untrusted zone on physical ports 0/0 and 0/1. We have set up interface failover using the track ip monitor on the primary interface so that if the primary line / interface goes down it switches to backup. We have a default route setup for each WAN connection, the primary has a lower preference value so that when it is active all the traffic is routed via this interface.
The failover works perfectly for web traffic and our VPNs but does not switch the SIP traffic and subsequently the VOIP phones go offline. The only way we can get the phones up and running on the backup connection is to reboot the SSG.
We have disabled SIP ALG on the Juniper and have 2 outbound policies to allow SIP (ports 5060 - 5069) and RTP (ports 10000 - 20000)
Any ideas on how to get the VOIP phones to successfully failover to the backup line without having to reboot the Juniper?
Thanks in advance