<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: inspection SIP - unidirectional traffic in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/inspection-SIP-unidirectional-traffic/m-p/87879#M17699</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Hello thank you for your reply,&lt;/P&gt;&lt;P&gt;We use the Big-IP EDGE client in VPN alwaysON mode , I don't have any problem of routing. The server SIP can reach a vpn device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I did a fw monitor on the checkpoint gateway "&lt;SPAN&gt;fw monitor -e "host(X.X.X.X), accept;" but I have a lot of malformed packet and Packet size limited during capture. On the capture the gateway receive the SIP packet frome the SIP server (tcp sip dynamic port 54640) but the client VPN sent an RST packet ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;the log on the checkpoint gateway&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-06-10_10h05_17.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6445i079E1B21DABACD43/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-06-10_10h05_17.png" alt="2020-06-10_10h05_17.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The capture on the SIP server&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="cucm.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6446i8CABEF0A66B2B093/image-size/large?v=v2&amp;amp;px=999" role="button" title="cucm.png" alt="cucm.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Miguel&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jun 2020 08:17:01 GMT</pubDate>
    <dc:creator>chico</dc:creator>
    <dc:date>2020-06-10T08:17:01Z</dc:date>
    <item>
      <title>inspection SIP - unidirectional traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/inspection-SIP-unidirectional-traffic/m-p/87760#M17679</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have softphones CISCO Jabber on our vpn devices and it's doesn't work well. We have some different scenarios and different behaviour for each scenarios.&lt;/P&gt;&lt;P&gt;&amp;nbsp;The network topology is simple -&amp;gt; F5 client EDGE VPN -&amp;gt; GW Checkpoint 4800-&amp;gt; LAN&lt;/P&gt;&lt;P&gt;As below my checkpoint rule&lt;/P&gt;&lt;P&gt;SRC: SIP server; client VPN -&amp;gt; DST: Client VPN; SIP Server -&amp;gt; service: sip_dynamic_ports; sip-tcp&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="chkp_rule.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6408i579E34E6437B84C2/image-size/large?v=v2&amp;amp;px=999" role="button" title="chkp_rule.png" alt="chkp_rule.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 - I can etablish a call from my client jabber on the VPN device to my client jabber on my laptop (LAN) it's work fine&lt;/P&gt;&lt;P&gt;2 - But I can't etablish a call from my client jabber on my laptop to my client jabber on the vpn device it's doesn't work&lt;/P&gt;&lt;P&gt;I did a TCPDUMP on the SIP server and I can see that the SIP server send a "request: INVITE" but the client jabber never respond to the INVITE as shown on the capture below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="TCPDUMP.png" style="width: 870px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6403i7208B9BB57AF0FDA/image-dimensions/870x236?v=v2" width="870" height="236" role="button" title="TCPDUMP.png" alt="TCPDUMP.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe because de SIP packets are inspected and modified by the checkpoint ?? How can I verify if the SIP packet are inspected by checkpoint ? how can I completly desactivate the inspection SIP to be sure if the problem come frome to SIP inspection ?&lt;/P&gt;&lt;P&gt;In the checkpoint log on the dashboard I can see the REQUEST INVITE frome the SIP server but with a error message as below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="chkp_log.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6406i5D1F2436C3DB8EE2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chkp_log.png" alt="chkp_log.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="chkp_log2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6407i254C5C84EEFD982C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chkp_log2.png" alt="chkp_log2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tied to do the manipulation as mentionned by "&lt;SPAN&gt;Hugo_vd_Kooij"&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Access-Control-Products/How-to-disable-SIP-ALG-inspection-in-a-specific-rule-in/td-p/25249" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Access-Control-Products/How-to-disab&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Access-Control-Products/How-to-disable-SIP-ALG-inspection-in-a-specific-rule-in/td-p/25249" target="_blank" rel="noopener"&gt;le-SIP-ALG-inspection-in-a-specific-rule-in/td-p/25249&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-I created a clone of sip-tcp service with "protocol" set to none and in the advanced "Ma&lt;/SPAN&gt;&lt;SPAN&gt;tch fo Any"&amp;nbsp; but for the "sip_dynamic_ports" I can't change the advanced parameter "Match fo Any" ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="sip-tcp-clone_advanced.png" style="width: 321px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6399i8887757872B27670/image-dimensions/321x361?v=v2" width="321" height="361" role="button" title="sip-tcp-clone_advanced.png" alt="sip-tcp-clone_advanced.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="sip-tcp-clone_general.png" style="width: 363px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6400i090F2A8EA515312E/image-dimensions/363x312?v=v2" width="363" height="312" role="button" title="sip-tcp-clone_general.png" alt="sip-tcp-clone_general.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="sip-dynamic_advanced.png" style="width: 352px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6404i2FD2A4DA6C1A888D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sip-dynamic_advanced.png" alt="sip-dynamic_advanced.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If someone as an idea about this problem ?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 14:28:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/inspection-SIP-unidirectional-traffic/m-p/87760#M17679</guid>
      <dc:creator>chico</dc:creator>
      <dc:date>2020-06-09T14:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: inspection SIP - unidirectional traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/inspection-SIP-unidirectional-traffic/m-p/87769#M17683</link>
      <description>&lt;P&gt;Two questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Do you use office mode? If yes, do your office mode IPs are routed to VPN GW from SIP server?&lt;/P&gt;
&lt;P&gt;2. Did you run drop debug and/or traces on GW side to see if GW is even receiving SIP packets sent to VPN client from SIP server?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 15:24:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/inspection-SIP-unidirectional-traffic/m-p/87769#M17683</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-06-09T15:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: inspection SIP - unidirectional traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/inspection-SIP-unidirectional-traffic/m-p/87879#M17699</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Hello thank you for your reply,&lt;/P&gt;&lt;P&gt;We use the Big-IP EDGE client in VPN alwaysON mode , I don't have any problem of routing. The server SIP can reach a vpn device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I did a fw monitor on the checkpoint gateway "&lt;SPAN&gt;fw monitor -e "host(X.X.X.X), accept;" but I have a lot of malformed packet and Packet size limited during capture. On the capture the gateway receive the SIP packet frome the SIP server (tcp sip dynamic port 54640) but the client VPN sent an RST packet ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;the log on the checkpoint gateway&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-06-10_10h05_17.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6445i079E1B21DABACD43/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-06-10_10h05_17.png" alt="2020-06-10_10h05_17.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The capture on the SIP server&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="cucm.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6446i8CABEF0A66B2B093/image-size/large?v=v2&amp;amp;px=999" role="button" title="cucm.png" alt="cucm.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Miguel&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 08:17:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/inspection-SIP-unidirectional-traffic/m-p/87879#M17699</guid>
      <dc:creator>chico</dc:creator>
      <dc:date>2020-06-10T08:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: inspection SIP - unidirectional traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/inspection-SIP-unidirectional-traffic/m-p/88245#M17730</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I remarqued that the signalisation SIP doesn't pass when the SIP server intiate a Request INVITATION with a dynamic tcp port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 - the client jabber on the local network initatie a SIP session on the port 5060 to the SIP proxy and I don't have any problem, accepted by checkpoint.&lt;/P&gt;&lt;P&gt;2- the SIP proxy initiate a connexion SIP with dynamique port destination to my vpn client jabber, at this time the signalisation packet doesn't arrive to the client. &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sip_.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6661iC1E1CBB31A5AD124/image-size/large?v=v2&amp;amp;px=999" role="button" title="sip_.png" alt="sip_.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see that the packets are accepted by the checkpoint but I don't see any informations about SIP packet in the checkpoint log.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="__.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6662iD81A1A66C3B96959/image-size/large?v=v2&amp;amp;px=999" role="button" title="__.png" alt="__.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 12:41:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/inspection-SIP-unidirectional-traffic/m-p/88245#M17730</guid>
      <dc:creator>chico</dc:creator>
      <dc:date>2020-06-11T12:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: inspection SIP - unidirectional traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/inspection-SIP-unidirectional-traffic/m-p/91553#M18264</link>
      <description>&lt;P&gt;Hi Chico,&lt;BR /&gt;I am having same issues with below setup&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco Jabber/Webex teams running on VPN with office mode ---- Checkpoint 5600 -----LAN.&lt;/P&gt;&lt;P&gt;The issue when CUCM originates the signalling with dynamic TCP ports, the signalling fails.&lt;/P&gt;&lt;P&gt;Did you manage to resolve the issue ?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 23:22:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/inspection-SIP-unidirectional-traffic/m-p/91553#M18264</guid>
      <dc:creator>Karan0587</dc:creator>
      <dc:date>2020-07-14T23:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: inspection SIP - unidirectional traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/inspection-SIP-unidirectional-traffic/m-p/92215#M18366</link>
      <description>&lt;P&gt;Hi Karan0587,&lt;/P&gt;&lt;P&gt;Yes I resolved the issue but the root cause came from our F5 proxy, we use a BIG-IP edge client and we had to Enable the settings "preserve Source Port Strict" otherwise the source port is changed by BIG-IP for optimisation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 06:22:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/inspection-SIP-unidirectional-traffic/m-p/92215#M18366</guid>
      <dc:creator>chico</dc:creator>
      <dc:date>2020-07-23T06:22:14Z</dc:date>
    </item>
  </channel>
</rss>

