<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FULL TIPS for VOIP Passing Through Check Point in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FULL-TIPS-for-VOIP-Passing-Through-Check-Point/m-p/223392#M42832</link>
    <description>&lt;P&gt;Thanks for sharing!&lt;/P&gt;</description>
    <pubDate>Mon, 12 Aug 2024 21:09:24 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-08-12T21:09:24Z</dc:date>
    <item>
      <title>FULL TIPS for VOIP Passing Through Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FULL-TIPS-for-VOIP-Passing-Through-Check-Point/m-p/223250#M42806</link>
      <description>&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;VOIP can cause a lot of issues when passing through firewalls, including Check Point devices that use SecureXL and Deep Inspections. During my three years working with Check Point, I decided to share some of the tips I've noted in my personal notes.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;NOTE: I ATTACH FOR DOWNLOAD A PDF ON THIS POST WITH ALL THIS INFORMATIONS THAT I WILL DESCRIBE HERE. BEST REGARDS&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1 - The default Check Point objects can trigger deep inspection inspections (those marked with Protocol).&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create a new object with only the port specified, as shown in the example below, without selecting anything under General &amp;gt; Protocol.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2024-08-10 at 9.38.58 PM.jpeg" style="width: 556px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27188i0FD0575AC2951D77/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2024-08-10 at 9.38.58 PM.jpeg" alt="WhatsApp Image 2024-08-10 at 9.38.58 PM.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;2- To pass voice via RTP, a range of high ports is used. Simply create the object and include the dash between the range. Also, make sure not to select Protocol in the General field.&lt;/STRONG&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2024-08-10 at 9.45.07 PM.jpeg" style="width: 507px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27189i5948944908044F97/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2024-08-10 at 9.45.07 PM.jpeg" alt="WhatsApp Image 2024-08-10 at 9.45.07 PM.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;3 - Increase the default session timout of some udp or tcp port can be necessary some times. For example for udp 5060 can be necessary have more than 40 seconds. Do this on Advanced inside your service object.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2024-08-10 at 9.59.18 PM.jpeg" style="width: 634px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27190i37D48D6A5EC70223/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2024-08-10 at 9.59.18 PM.jpeg" alt="WhatsApp Image 2024-08-10 at 9.59.18 PM.jpeg" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;4 - It is common in VOIP to need to create bidirectional rules, especially for UDP traffic. So, if you are handling UDP voice traffic, or in large IPsec site-to-site scenarios where both sides need to send and receive traffic, create bidirectional NAT and security rules as shown in the example below:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; There are certain topologies where this may not be necessary, so evaluate your scenario using the VOIP Admin Guide for your version, and check the section "Important Information About Creating SIP Security Rules." link bellow:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_VoIP_AdminGuide/Topics-VOIPG/207846.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_VoIP_AdminGuide/Topics-VOIPG/207846.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;NAT POLICY&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2024-08-10 at 10.14.39 PM.jpeg" style="width: 920px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27193i116855C3418FB0CE/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2024-08-10 at 10.14.39 PM.jpeg" alt="WhatsApp Image 2024-08-10 at 10.14.39 PM.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;SEC POLICY&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2024-08-10 at 10.12.49 PM.jpeg" style="width: 956px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27192i7FC3EB2B49F4B7F2/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2024-08-10 at 10.12.49 PM.jpeg" alt="WhatsApp Image 2024-08-10 at 10.12.49 PM.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;NOTE: NAT rules using masquerade types can cause issues; if possible, it’s advisable to avoid them.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;5&amp;nbsp; -&amp;nbsp;Even after following all the steps, you may still encounter some cases of deep inspections. In such cases, it’s worth creating fast_accel rules for the PBX IP. I usually make them bidirectional, as shown in the examples below:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;SecureXL Fast Accelerator (fw fast_accel) for R80.20 and above&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk156672" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://support.checkpoint.com/results/sk/sk156672&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;sk156672 shows examples of fast_accel rules.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2024-08-10 at 10.24.01 PM.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27194i532807525644F0B4/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2024-08-10 at 10.24.01 PM.jpeg" alt="WhatsApp Image 2024-08-10 at 10.24.01 PM.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt; You need enable fast_accel first with&lt;STRONG&gt;&amp;nbsp;fw ctl fast_accel enable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;You can create the rule pointing to a network, in which case you need to include the subnet mask:&lt;/P&gt;&lt;P&gt;fw ctl fast_accel add 1.1.1.1 2.2.2.0/24 80 6&lt;/P&gt;&lt;P&gt;You can specify the network in either the source or destination. (to be bidirectional)&lt;/P&gt;&lt;P&gt;You can also create rules in the following ways:&lt;/P&gt;&lt;P&gt;fw ctl fast_accel add any 2.2.2.2 any any&lt;/P&gt;&lt;P&gt;fw ctl fast_accel add 2.2.2.2 any any any&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&lt;SPAN&gt; The rule name must use ONLY LETTERS and no special characters.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;6 -&amp;nbsp;&lt;SPAN&gt;In the PBX, configure &lt;/SPAN&gt;NAT=yes&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is necessary if there is NAT configuration in the VPN tunnel's phase 2 to resolve any overlap, or if you are hiding any network for any reason in phase 2. It is also applicable if you need to handle VOIP traffic outside of an IPsec site-to-site tunnel.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2024-08-10 at 10.31.57 PM.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27195i95BEF8D5960F0653/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2024-08-10 at 10.31.57 PM.jpeg" alt="WhatsApp Image 2024-08-10 at 10.31.57 PM.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;7 -&amp;nbsp;&lt;SPAN&gt;If you continue to have difficulty establishing a UDP connection for SIP, consider switching to TCP on the PBX.&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;Also, check if the client can establish communication on TCP 5060 instead of UDP 5060, especially if the client does not have DTMF (Dual-Tone Multi-Frequency) activated in VOIP.&lt;/P&gt;&lt;P&gt;Add the line transport=tcp to the configuration.&lt;BR /&gt;&lt;BR /&gt;NOTE: request for the VOIP team, bellow is just an example.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="WhatsApp Image 2024-08-10 at 10.36.10 PM (1).jpeg" style="width: 703px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27196i748DCEA0EEBCF014/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2024-08-10 at 10.36.10 PM (1).jpeg" alt="WhatsApp Image 2024-08-10 at 10.36.10 PM (1).jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;8 -&amp;nbsp;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&lt;SPAN&gt;VoIP SIP issues after upgrading Security Gateway to version R80.40 or higher with Hide NAT configured&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk176286" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk176286&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2024-08-10 at 10.38.41 PM.jpeg" style="width: 836px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27198iCA910D240C8C613A/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2024-08-10 at 10.38.41 PM.jpeg" alt="WhatsApp Image 2024-08-10 at 10.38.41 PM.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;9 - AS my last read the VOIP ATRG, and other references that Check Point have for VOIP, but my tips are here for all now.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Here are some useful resources for VOIP troubleshooting and configuration with Check Point:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;ATR VOIP&lt;/STRONG&gt;: &lt;A href="https://support.checkpoint.com/results/sk/sk95369" target="_new" rel="noreferrer"&gt;SK95369&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;SIP calls cannot be established after installing Check Point Security Gateway between SIP phones and SIP server&lt;/STRONG&gt;: &lt;A href="https://support.checkpoint.com/results/sk/sk113503" target="_new" rel="noreferrer"&gt;SK113503&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;How to disable 'fw early SIP nat' chain / SIP inspection&lt;/STRONG&gt;: &lt;A href="https://support.checkpoint.com/results/sk/sk65072" target="_new" rel="noreferrer"&gt;SK65072&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Check Point Active Streaming (CPAS) and Passive Streaming Layer (PSL)&lt;/STRONG&gt;: &lt;A href="https://support.checkpoint.com/results/sk/sk44788" target="_new" rel="noreferrer"&gt;SK44788&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Important Information About Creating SIP Security Rules&lt;/STRONG&gt;: &lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_VoIP_AdminGuide/Topics-VOIPG/207846.htm" target="_new" rel="noreferrer"&gt;VoIP Admin Guide&lt;/A&gt; (including how to create rules)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Community Link with a good example of VOIP troubleshooting&lt;/STRONG&gt;: &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/How-to-fully-accelerate-SIP-RTP-media-streams-using-SecureXL/td-p/67508" target="_new" rel="noreferrer"&gt;Community Example&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;BR /&gt;Best Regards&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Aug 2024 01:52:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FULL-TIPS-for-VOIP-Passing-Through-Check-Point/m-p/223250#M42806</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2024-08-11T01:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: FULL TIPS for VOIP Passing Through Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FULL-TIPS-for-VOIP-Passing-Through-Check-Point/m-p/223392#M42832</link>
      <description>&lt;P&gt;Thanks for sharing!&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 21:09:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FULL-TIPS-for-VOIP-Passing-Through-Check-Point/m-p/223392#M42832</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-12T21:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: FULL TIPS for VOIP Passing Through Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FULL-TIPS-for-VOIP-Passing-Through-Check-Point/m-p/273749#M104225</link>
      <description>&lt;P&gt;Great!&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 18:34:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FULL-TIPS-for-VOIP-Passing-Through-Check-Point/m-p/273749#M104225</guid>
      <dc:creator>Dibzera</dc:creator>
      <dc:date>2026-03-18T18:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: FULL TIPS for VOIP Passing Through Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FULL-TIPS-for-VOIP-Passing-Through-Check-Point/m-p/273750#M104226</link>
      <description>&lt;P&gt;Never seen this one before, great!&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 18:45:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FULL-TIPS-for-VOIP-Passing-Through-Check-Point/m-p/273750#M104226</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-03-18T18:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: FULL TIPS for VOIP Passing Through Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FULL-TIPS-for-VOIP-Passing-Through-Check-Point/m-p/273763#M104231</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;, this one's a few years old (2024-08-10), but it's still relevant today.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 23:28:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FULL-TIPS-for-VOIP-Passing-Through-Check-Point/m-p/273763#M104231</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-03-18T23:28:18Z</dc:date>
    </item>
  </channel>
</rss>

