VoIP over VPN problem

Aristide Akaffou
Aristide Akaffou used Ask the Experts™
on
Hi,

I have a problem to establish call session between two sites over gre tunnel ipsec. The tunnel is up but I am Unable to set a call. I think the problem is Nat but I don't know how to fix it.  It's seems like the traffic were blocked in the beginning of the tunnel.

You can see the configuration files in attached.

 

Best Regards,

 

Aristide
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
David FavorFractional CTO
Distinguished Expert 2018

Commented:
Or somewhere along the line of your VPN is blocking either ports or IPs.

Turn off your VPN first + retry.

If this works, turn on your VPN. If you can look at Websites + not make calls, likely this means someone is blocking your VOIP call port from the outdrop (IP) your VPN is using.

You can always connect through another region to get another IP.

Switching regions or just doing a VPN reconnect will likely give you a new IP. If this helps at all, likely this will only help for a while + the block will occur again in the future.

If you're doing this to attempt creating a secure VOIP setup, likely best to switch to a secure VOIP client, where security is handled at the VOIP layer. If you use a secure VOIP client, then you can drop the VPN setup for better call quality, because your connection speed will be higher.
nociSoftware Engineer
Distinguished Expert 2018

Commented:
There can be filters on the tunnel blocking some traffic. Check this by doing a tshark/tcpdump/wireshark dump on both side and see what gets accross.
It may very well be routing on the other side has trouble finding the way back...

Lots of if's...
Can you provide  more info on the setup.
( left & right side address ranges, and all possible routing in view.).
The config files seem to be missing from the post.
SouljaSr.Net.Eng
Top Expert 2011

Commented:
If you are using GRE, it sounds like you are using a routed vpn with VTI's. Insure that the routing for your voice traffic is pointed to the tunnel interface or far end of the vpn's tunnel interface.
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

SouljaSr.Net.Eng
Top Expert 2011

Commented:
Please post the configuration file. I don't see one attached.

Author

Commented:
Hi Soulja,
You can see the files in attached.
The network address you have to consider:

For CI:

192.168.30.0/24 : data vlan
10.2.2.0/24: Voice vlan
160.120.120.216: public IP address

For Lebanon:

131.107.0.0/16: data vlan
192.168.150.0/24: voice vlan
77.42.156.122 ; 212.40.132.22: Public IP address


Best Regards,

Aristide
architecture-voip.PNG
Sh-run-CI.txt
sh-run-lebanon.txt
SouljaSr.Net.Eng
Top Expert 2011

Commented:
For your vpn, what is the status of your ipsec sa's.


sh crypto ipsec sa

Also what is your eigrp routing looking like

sh ip eigrp neighbors
sh ip route eigrp or sh ip route 192.168.150.0 from the CI router. sh ip route 10.2.2.0 from the  Lebanon router.

Author

Commented:
Hi Soulja,
The status of sh crypto ipsec sa is idle

EIGRP Adjacency is established I can ping each the two sites.


Best Regards,

Aristide
SouljaSr.Net.Eng
Top Expert 2011

Commented:
I see the ASA in the diag. Is it allowing your VOIP traffic through. You have a lot of pieces in play in order to troubleshoot this in this forum. Please provide as much detail as possible. You provided the router configs, but there are many more points of failure for connectivity in this scenario.

Author

Commented:
OK I can provide ASA configuration. I have permitted the traffic in ASA.
asa310818.txt

Author

Commented:
Hi Guys,
Any update.

Best Regards,

Aristide

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial