This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Configure Routing for VoIP and DATA over 2 WAN IP's

 I am hoping for some assistance in configuring XG125 for use with 2WAN IP's, one for Data one for VoIP.

 

Currently, traffic is flowing correctly for the DATA network, through WAN 1 (port 2 on XG)

 

I have another WAN interface (WAN 2 - Port4) for VoIP traffic, using a separate ISP from the DATA network, which I have taken from the initial br0 bridge pair

My Phones system comes from a device on the LAN with the IP 172.20.164.190, and I need all traffic from that IP to be routed through WAN2.

I then need the incoming traffic from WAN2 port to be accepted, and forwarded to that device on my LAN using a set of TCP and UDP ports.

 

Do I need to create a new LAN zone for the device in question?

Which firewall rules are needed to route the correct traffic through the correct gateway. / User/Network rule or Full NAT?

Do I need to create Policy Routes?

 

VoIP currently working through Draytek but need to move it over to the XG.



This thread was automatically locked due to age.
Parents
  • Hello Alex,

    If you have 2 WAN links configured on your firewall. You could create a network/user rule to allow the traffic to your VOIP server. I believe your VOIP server has an IP address or URL it connects to. You may create a destination based rule using an IP address or FQDN rule using a URL. Apply NAT MASQ and configure your primary gateway on that firewall rule as the link on WAN2 and backup as WAN1. 

  • Thanks Aditya

     So, if I enable rule 8 in the above screenshot, this should take care of the incoming connection (WAN2 ->LAN) using the required ports. The rule is configured as below:

    Summary

    VoIP Incoming

    Allow

    Rule

    Accept "VoIP Services" service going to "LAN" zone, when in "WAN" zone, and coming from "#Port4" network

    Source & schedule

    WAN

    Source networks and devices : #Port4
    During scheduled time : All the time

    Destination & services

    LAN

    Destination networks : VoIP Server
    Services : VoIP Services

    Advanced

    Synchronized security

    Source : Minimum heartbeat is No restriction, Clients with no heartbeat allowed
    Destination : Minimum heartbeat is No restriction, Request to destination with no heartbeat allowed

    Masquerading is ON

     

    For the outgoing, do I then configure an IPv4 Policy route?

  • Hi,

    outgoing is a straight firewall rule with MASQ and the second WAN port selected primary gateway.

    For incoming traffic that would be going to an internal PABX, the PABX would have to setup connections to the source of your VoIP traffic, so in reality you do not need an incoming rule.

    Ian

  • Thanks Ian

     

    I will need to schedule some testing to check the suggestions. This will only be in around two weeks time unfortunately.

Reply Children
No Data