Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Issue in voice traffic

Dear sir,

I hope you are doing well,

Kindly sir i am facing issue in voice traffic send through IP Sec VPN tunnel.

I have XG 210 in the head office and 116 XGS in the branch the

IPsec VPN is active and i can ping all server and devices

but the issue is in the IP phone its Ring (from both sites) but there is no voice



This thread was automatically locked due to age.
Parents
  • Hello ,

    Thank you for reaching out to the community, check & perform the following:

    Step1current UDP time-out value Under the Advance shell [ssh menu > press 5 for the device management > press 3 for the advance shell) 
    type the following command:
    #show advanced-firewall

    Step2: Then increases the UDP time-out to 150 or 300 seconds, with the following command: 
    #set advanced-firewall udp-timeout-stream 300
    #set advanced-firewall udp-timeout 300

    Step3: turns off the preloaded IPS patterns for SIP
    #set ips sip_preproc disable

    Step4:
    check the SIP module status:
    #system system_modules show

    Step5: 
    if you think the protocol is required, you can load/unload with the following command:
    To load: #system system_modules sip load
    To unload: #system system_modules sip unload

    *Note
    The commands are persistent even if the Sophos Firewall is restarted.

    > If you are using any custom Port for the SIP other than the traditional 5060 then you may use it with the following command below:
    #system system_modules sip load ports <custom_port>

    > And lastly ensure you've configured a firewall rule for SIP.
    Path: Go to Rules and policies > Firewall rules.
    Ensure you select the recipient's network in Destination networks. If you want to call any phone, set the recipient's network to Any.

    > Also ensure if there is no UDP flood settings enabled.
    Path: 
    Go to Intrusion prevention > DoS & spoof protection.
    Under DoS settings, clear the Apply flag checkboxes for UDP flood.
    Test the VoIP connection.
    If this setting resolves the VoIP issue, lower the UDP flood protection values before applying the flag again.
    A single value doesn't work for all environments. Adjust the values until you find those that work best for your VoIP setup.

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • I think Step 3 is a typo and should be:

    set ips sip_preproc disable

Reply Children