<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Incoming VOIP calls disconnect after 30/31 seconds in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233105#M45081</link>
    <description>&lt;P&gt;Maybe involve TAC. There are a lot of&amp;nbsp;unknown.&lt;/P&gt;
&lt;P&gt;As I remember we had early NAT isssues in tha past. Sometimes some calls disconnected randomly. It was really tricky&lt;/P&gt;
&lt;P&gt;The TAC helped us in the investigation, and they solved our problem.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
    <pubDate>Tue, 19 Nov 2024 12:33:38 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2024-11-19T12:33:38Z</dc:date>
    <item>
      <title>Incoming VOIP calls disconnect after 30/31 seconds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233082#M45073</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;All of a sudden a customer is having issues with incoming VOIP calls (outgoing no issues).&lt;/P&gt;&lt;P&gt;Previously no issues and no changes on the firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You communicate for 30/31 seconds then the call are dropped.&lt;/P&gt;&lt;P&gt;Customer has an internal PABX with communicates with the VOIP provider's PABX.&lt;/P&gt;&lt;P&gt;If I change the SIP port on the rule that allows the external PABX to talk to the gateways external IP&amp;nbsp; (NAT to internal PABX) to use the pre-defined SIP port (with inspection) from a custom UDP 5060 port then the incoming calls are all good and don't disconnect.&lt;/P&gt;&lt;P&gt;However this breaks the audio on outgoing calls (both ways).&lt;/P&gt;&lt;P&gt;I have configured the rules/NATs as per the VOIP sk but that just makes it worse.&lt;/P&gt;&lt;P&gt;Current rules are like this:&lt;/P&gt;&lt;P&gt;Source&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Destination&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Service&lt;/P&gt;&lt;P&gt;Voip_provider_PABX --&amp;gt; Gateways_external_IP&amp;nbsp; udp_5060&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;--&amp;gt; Internal_PABX_IP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; udp_5060&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internal_PABX_IP&amp;nbsp; --&amp;gt;&amp;nbsp;&amp;nbsp;Voip_provider_PABX&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SIP_port&lt;/P&gt;&lt;P&gt;Internal_PABX_IP&amp;nbsp; --&amp;gt;&amp;nbsp;&amp;nbsp;Voip_provider_RTP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; udp range&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NATs&lt;/P&gt;&lt;P&gt;Voip_provider_PABX --&amp;gt; Gateways_external_IP&amp;nbsp; &amp;nbsp; &amp;nbsp;udp_5060&amp;nbsp; &amp;nbsp;translated destination = internal_PABX_IP&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internal_PABX_IP&amp;nbsp; --&amp;gt;&amp;nbsp;&amp;nbsp;Voip_provider_PABX&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;any port&amp;nbsp; &amp;nbsp; &amp;nbsp;translated source =&amp;nbsp;&amp;nbsp;Gateways_external_IP&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internal_PABX_IP&amp;nbsp; --&amp;gt; &amp;nbsp;Voip_provider_RTP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;any port&amp;nbsp; &amp;nbsp; &amp;nbsp;translated source =&amp;nbsp;&amp;nbsp;Gateways_external_IP&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas as seems to be a mis-configuration on the CP.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 08:00:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233082#M45073</guid>
      <dc:creator>Mark_Edwards</dc:creator>
      <dc:date>2024-11-19T08:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming VOIP calls disconnect after 30/31 seconds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233090#M45076</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/14865"&gt;@Mark_Edwards&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The VOIP is always&amp;nbsp;naughty thing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;First the general steps according to the&amp;nbsp; VOIP ARTG guide:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Disable all special/advanced features and Software Blades and re-test:&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL type="circle"&gt;
&lt;LI&gt;&lt;EM&gt;NAT&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;SecureXL&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;ClusterXL&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;VPN&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;etc.&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;"Previously no issues and no changes on the firewall. "&lt;/P&gt;
&lt;P&gt;If not only the Firewall Blade is enabled, a good troubleshooting step can be to make a exception for this traffic on the Application Contron, URL Filtering blade, or in IPS etc.&lt;/P&gt;
&lt;P&gt;I think there is no drop on SmartLog&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 12:08:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233090#M45076</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-11-19T12:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming VOIP calls disconnect after 30/31 seconds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233099#M45078</link>
      <description>&lt;P&gt;In addition to the AKOS's suggestion, you can test with creating new service for SIP &amp;amp; UDP_5060 and select "match for any" option in those services. Create a rule with these custom services.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 11:52:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233099#M45078</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2024-11-19T11:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming VOIP calls disconnect after 30/31 seconds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233101#M45079</link>
      <description>&lt;P&gt;Hi, I did try that.&lt;/P&gt;&lt;P&gt;It fixes the incoming calls but breaks the outgoing - no audio.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have tried various SIP ports, etc to no avail.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 12:24:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233101#M45079</guid>
      <dc:creator>Mark_Edwards</dc:creator>
      <dc:date>2024-11-19T12:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming VOIP calls disconnect after 30/31 seconds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233105#M45081</link>
      <description>&lt;P&gt;Maybe involve TAC. There are a lot of&amp;nbsp;unknown.&lt;/P&gt;
&lt;P&gt;As I remember we had early NAT isssues in tha past. Sometimes some calls disconnected randomly. It was really tricky&lt;/P&gt;
&lt;P&gt;The TAC helped us in the investigation, and they solved our problem.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 12:33:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233105#M45081</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-11-19T12:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming VOIP calls disconnect after 30/31 seconds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233107#M45082</link>
      <description>&lt;P&gt;I can tell you every time I ever worked with customer that had voip issues, TAC gave us below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk95369" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk95369&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Now, I dont expect you to go through the whole article (I dont think anyone ever has lol), BUT, here is one important thing I will say. In the old days of CP, most people would end up changing involved services to protocol none, rather than default one. So, say what you can do is clone sip, make sure poirt is 5060 and do below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28488i4B1A7BB6BE3FF7D0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 12:45:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233107#M45082</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-19T12:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming VOIP calls disconnect after 30/31 seconds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233113#M45084</link>
      <description>&lt;P&gt;Sounds like possibly some kind of delayed notification or timeout issue between the SecureXL connections table (&lt;STRONG&gt;fwaccel conns&lt;/STRONG&gt;) and the INSPECT connections table (&lt;STRONG&gt;fw tab -t connections&lt;/STRONG&gt;).&amp;nbsp; I'd suggest selectively disabling SecureXL for UDP/5060 (and any other related ports) to force all that traffic F2F and see what happens, see&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk104468" target="_blank" rel="noopener"&gt;sk104468: How to exclude traffic from&amp;nbsp;SecureXL&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 13:43:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233113#M45084</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-11-19T13:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming VOIP calls disconnect after 30/31 seconds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233206#M45098</link>
      <description>&lt;P&gt;Hi Timothy,&lt;/P&gt;&lt;P&gt;I see that this is already configured as they had VOIP issues when the gateways were first implemented (few years ago).&lt;/P&gt;&lt;P&gt;I do have a TAC logged, maybe they will resolve it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 08:23:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233206#M45098</guid>
      <dc:creator>Mark_Edwards</dc:creator>
      <dc:date>2024-11-20T08:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming VOIP calls disconnect after 30/31 seconds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233233#M45102</link>
      <description>&lt;P&gt;Did you try what I mentioned yesterday, with protocol none?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 11:44:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233233#M45102</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-20T11:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming VOIP calls disconnect after 30/31 seconds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233762#M45255</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Tried both but did not make a difference.&lt;/P&gt;&lt;P&gt;Resolved it by moving the VOIP rule higher up although couldn't see drop logs and the rule was been hit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks everyone&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 07:08:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233762#M45255</guid>
      <dc:creator>Mark_Edwards</dc:creator>
      <dc:date>2024-11-26T07:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming VOIP calls disconnect after 30/31 seconds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233775#M45258</link>
      <description>&lt;P&gt;From what I remember it was always recommend to move voip rules as high in the rulebase as possible to avoid performance issues and delay with voice. In recent versions i don’t think this should be needed anymore due performance optimization features.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 08:13:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233775#M45258</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-11-26T08:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming VOIP calls disconnect after 30/31 seconds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233798#M45264</link>
      <description>&lt;P&gt;Great job!&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 11:48:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Incoming-VOIP-calls-disconnect-after-30-31-seconds/m-p/233798#M45264</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-26T11:48:43Z</dc:date>
    </item>
  </channel>
</rss>

