<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After upgrade R82 - RTP (VOIP) not working, with secureXL enabled in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/265281#M52265</link>
    <description>&lt;P&gt;Will do!&lt;/P&gt;&lt;P&gt;Kr,&lt;BR /&gt;Bert&lt;/P&gt;</description>
    <pubDate>Mon, 15 Dec 2025 09:58:50 GMT</pubDate>
    <dc:creator>BertEtienne</dc:creator>
    <dc:date>2025-12-15T09:58:50Z</dc:date>
    <item>
      <title>After upgrade R82 - RTP (VOIP) not working, with secureXL enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/264837#M52077</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've never really in depth troubleshooted secureXL, so I wanted to get some additional insight from the community. I'll be creating a TAC case for it as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We recently upgraded our customer from R81.20 to R82 JHF 44.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We did however encounter a major issue with VOIP traffic, specifically the RTP part.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Internally people could call each other, but couldn't hear one another. After some troubleshooting it seems an issue with RTP not being processed correctly on the firewall. Disabling secureXL resolves the issue.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Setup&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;=============&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;6200 cluster running R82 JHF 44&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;fwaccel is currently disabled and running in kppak mode.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;firewall itself is in user mode&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Kernel: 4.18.0-372.9.1cpx86_64&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Voice vlan: 10.0.40.0/22&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Voice border gateway: 172.16.51.20 (public IP 176.62.X.X)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Troubleshooting&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;==============&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;A VOIP telephone connects to the bordergateway public IP 176.62.X.X, which is natted to the internal IP 172.16.51.20. It establishes a SIP connection (TCP 5060/5061) and determines which UDP high port will be used for the data transfer (RTP) between the two users.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We use custom TCP protocols, to disable inspection/ALG issues. Nothing has changed to this setup prior to the upgrade.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This flow above worked in the R81.20 setup and also works in R82, if the voice user is not connected on an internal network.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Example: User working from home.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Flow: Public IP user &amp;lt;&amp;gt; 176.62.X.X &amp;lt;&amp;gt; 172.16.51.20 &amp;lt;&amp;gt; internal ip user 10.0.40.x/22&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Capture of RTP traffic&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[vs_0][&lt;STRONG&gt;ppak_0&lt;/STRONG&gt;] &lt;STRONG&gt;eth4:i&lt;/STRONG&gt;[44]: 172.16.51.20 -&amp;gt; 10.0.40.38 (UDP) len=200 id=&lt;STRONG&gt;40609&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;UDP: 25076 -&amp;gt; 55114&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[vs_0][ppak_0] &lt;STRONG&gt;eth4:I&lt;/STRONG&gt;[44]: 172.16.51.20 -&amp;gt; 10.0.40.38 (UDP) len=200 id=&lt;STRONG&gt;40609&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;UDP: 25076 -&amp;gt; 55114&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[vs_0][ppak_0] &lt;STRONG&gt;bond1.40:o&lt;/STRONG&gt;[44]: 172.16.51.20 -&amp;gt; 10.0.40.38 (UDP) len=200 id=&lt;STRONG&gt;40609&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;UDP: 25076 -&amp;gt; 55114&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[vs_0][ppak_0] &lt;STRONG&gt;bond1.40:O&lt;/STRONG&gt;[44]: 176.62.X.X -&amp;gt; 10.0.40.38 (UDP) len=200 id=&lt;STRONG&gt;40609&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;UDP: 25076 -&amp;gt; 55114&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This flow doesn't work in R82 when a user is working locally in the office.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Example: Both users have an IP in 10.0.40.0/22&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Flow: 10.0.40.x/22 &amp;lt;&amp;gt; 176.62.X.X &amp;lt;&amp;gt; 172.16.51.20 &amp;lt;&amp;gt;10.0.40.x/22&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Capture of RTP trafic&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;---------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[vs_0][&lt;STRONG&gt;ppak_0&lt;/STRONG&gt;] &lt;STRONG&gt;eth4&lt;/STRONG&gt;:&lt;STRONG&gt;i&lt;/STRONG&gt;[44]: 172.16.51.20 -&amp;gt; 10.0.40.133 (UDP) len=200 id=&lt;STRONG&gt;42532&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;UDP: 26640 -&amp;gt; 55080&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[vs_0][&lt;STRONG&gt;fw_2&lt;/STRONG&gt;] &lt;STRONG&gt;eth4&lt;/STRONG&gt;:&lt;STRONG&gt;i&lt;/STRONG&gt;[44]: 172.16.51.20 -&amp;gt; 10.0.40.133 (UDP) len=200 id=&lt;STRONG&gt;42532&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;UDP: 26640 -&amp;gt; 55080&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[vs_0][ppak_0] eth4:i[44]: 172.16.51.20 -&amp;gt; 10.0.40.133 (UDP) len=200 id=42548&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;UDP: 26640 -&amp;gt; 55080&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[vs_0][fw_2] eth4:i[44]: 172.16.51.20 -&amp;gt; 10.0.40.133 (UDP) len=200 id=42548&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;UDP: 26640 -&amp;gt; 55080&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Doesn't get processed after small "i", and gets dropped? by "fw_2".&lt;BR /&gt;fw ctl zdebug + drop, doesn't show any&amp;nbsp; drops for these connections.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Disabling secureXL makes this flow work again.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I've tried setting up a fast_accel rule, but this doesn't seem to help. It's also more a quick fix, then an actual solution.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;------------------------------------ FIREWALL FAST ACCEL TABLE ------------------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# Source IP Destination IP D-Port Protocol Hit count&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;---- ------------------ ------------------ ------ -------- -----------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;1) 10.0.40.0/22 172.16.51.20/32 any 17 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2) 172.16.51.20/32 10.0.40.0/22 any 17 11&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm not too knowledgeable on how the voice traffic actually works in depth.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I would assume if two users in the same subnet are calling each other, that the actual UDP traffic would be sent directly to one another (not passing the firewall), but it seems this isn't the case here and it's all relayed via the border gateway.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It might be related to NAT within secureXL someway, but unsure how to tackle this furhter.&lt;BR /&gt;&lt;BR /&gt;Kr,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Bert&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 11:31:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/264837#M52077</guid>
      <dc:creator>BertEtienne</dc:creator>
      <dc:date>2025-12-09T11:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade R82 - RTP (VOIP) not working, with secureXL enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/265153#M52218</link>
      <description>&lt;P&gt;If disabling SecureXL resolves an issue (really, it just prevents new templates from being formed), TAC definitely needs to be involved.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 21:44:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/265153#M52218</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-12-11T21:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade R82 - RTP (VOIP) not working, with secureXL enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/265158#M52221</link>
      <description>&lt;P&gt;You could give below a go and see if it works.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk104468" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk104468&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 22:05:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/265158#M52221</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-11T22:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade R82 - RTP (VOIP) not working, with secureXL enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/265172#M52227</link>
      <description>&lt;P&gt;Yeah a troubleshoot session is already planned.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 08:19:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/265172#M52227</guid>
      <dc:creator>BertEtienne</dc:creator>
      <dc:date>2025-12-12T08:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade R82 - RTP (VOIP) not working, with secureXL enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/265247#M52244</link>
      <description>&lt;P&gt;Let us know how it gets solved, it would definitely help if someone else encounters the same issue.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Dec 2025 14:06:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/265247#M52244</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-13T14:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade R82 - RTP (VOIP) not working, with secureXL enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/265281#M52265</link>
      <description>&lt;P&gt;Will do!&lt;/P&gt;&lt;P&gt;Kr,&lt;BR /&gt;Bert&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 09:58:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/265281#M52265</guid>
      <dc:creator>BertEtienne</dc:creator>
      <dc:date>2025-12-15T09:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade R82 - RTP (VOIP) not working, with secureXL enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/265285#M52268</link>
      <description>&lt;P&gt;Hey Bert,&lt;/P&gt;
&lt;P&gt;Check out the sk I mentioned, might be relevant.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 11:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-R82-RTP-VOIP-not-working-with-secureXL-enabled/m-p/265285#M52268</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-15T11:56:50Z</dc:date>
    </item>
  </channel>
</rss>

