Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to separate sip traffic

I have a question regarding sip traffic.

In our main office we have a firewall rule for outgoing calls. We have recently setup a remote office connected by a red 60. It has its own phone system but we are setting it up so you can dial extensions across the red tunnel. When we dial an extension it rings in the other end but you can hear anything once they pick up. I have noticed that once the call is answered it is trying to send that call out the firewall rule that I created for outgoing calls. What do I need to do in order to separate the 2 and make this work correctly?



This thread was automatically locked due to age.
Parents
  • Hi,

    please post a screenshot of your firewall rules. I assume you have different rules for the SIP traffic from the other traffic?

    Ian

  • Yes for outgoing calls this is the firewall rule…source zone: lan

    source device: sip server

    destination zone: wan

    i tried added the red network also to the destination zone but still no audio.

    the rules between the 2 offices are..

    source zone: lan

    source device: local network

    destination zone: red

    destination device: office 2 network.

    I also have one for reverse traffic.

  • Hi,

    you shouldn't need a reverse firewall rule. I assume you have the SIP service in your firewall rule?

    Please try changing your destination zone to ANY in your SIP rule because the phones setup the connection to the SIP server so the XG knows where to send the traffic because a connection between the phones and the server is maintained even when there are no calls.

    Ian

  • So here are my unchanged rules

    This is for outgoing sip traffic

    the last 2 are for going to and coming back. I have it going both ways because we have data that both locations share. 

    now you are saying that I need to change the destination zone in my sip rule to Any?

    is there anything else I should change?

  • I should also note that the 2 location have separate phone systems. They are 2 different units and our phone provider programmed the 2 to communicate. My issue I believe is when the call gets answered it’s trying to send the audio out the wan port and not down the tunnel.

  • Hi,

    your RED rule with RED as source and destination is a bit strange. For a both way rule you would normally go something like this RED and LAN (or ANY) in Source zone and RED and LAN (or ANY for destination zone. with source a dn destination network being RED and the actual network in the office.

    Ian

Reply
  • Hi,

    your RED rule with RED as source and destination is a bit strange. For a both way rule you would normally go something like this RED and LAN (or ANY) in Source zone and RED and LAN (or ANY for destination zone. with source a dn destination network being RED and the actual network in the office.

    Ian

Children