<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SIP_DYNAMIC_PORTS in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SIP-DYNAMIC-PORTS/m-p/92551#M3933</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sip_dynamic_ports service was never supported in SMB.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The phones have to be configured to use permanent&amp;nbsp;source-port and destination-port (by default: 5060. If using non-default port, the SIP_UDP service port has to be changed accordingly).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;For more info about the SIP configuration which is supported in SMB, please refer to&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113573" target="_blank" rel="noopener"&gt;sk113573&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jul 2020 19:04:03 GMT</pubDate>
    <dc:creator>ronk</dc:creator>
    <dc:date>2020-07-27T19:04:03Z</dc:date>
    <item>
      <title>SIP_DYNAMIC_PORTS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SIP-DYNAMIC-PORTS/m-p/92548#M3932</link>
      <description>&lt;P&gt;GW CP730&lt;/P&gt;&lt;P&gt;Firmware: R77.20.87 (990173004)&lt;/P&gt;&lt;P&gt;Good day.&amp;nbsp; I have a scenario where two remote sites have multiple SIP devices (phones and softphones) behind a Verizon FiOS modem.&amp;nbsp; The issue is that for some reason the modem takes the device_LAN_IP1:5060 becomes device_WAN_IP:random (i.e. 173.X.X.X:35011 and 173.X.X.X:1026 and&amp;nbsp;173.X.X.X:1034).&amp;nbsp; The devices SIP register but RTP does not work because to odd port cannot be reached.&lt;/P&gt;&lt;P&gt;After reading the manual I understand that a sip_dynamic_ports service can be made to fix this issue. With the odd port numbers does one has to make an outgoing and incoming rule for each device.&amp;nbsp; For example&lt;/P&gt;&lt;P&gt;SIP SERVER is PBX with external IP Address and NAT to internal (LAN) PBX IP (This rule already exists)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Source&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Destination&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Action&lt;/P&gt;&lt;P&gt;(inbound rule) Phone IP address&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SIP Server Address&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;udp_sip&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Accept&amp;nbsp;&lt;/P&gt;&lt;P&gt;(outbound rule)&amp;nbsp; SIP Server address&amp;nbsp; &amp;nbsp; SIP Phone Address&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;sip_dynamic_port1&amp;nbsp; &amp;nbsp; &amp;nbsp; Accept&amp;nbsp;&lt;/P&gt;&lt;P&gt;Get the impression that a rule has to be made for each odd Port number,&amp;nbsp;&lt;/P&gt;&lt;P&gt;So for three devices I would have to add&amp;nbsp;sip_dynamic_port1 (35011),&amp;nbsp;sip_dynamic_port2 (port1026),&amp;nbsp;sip_dynamic_port3 (1034), etc&lt;/P&gt;&lt;P&gt;Am I on the right trail or going down the rabbit hole?&amp;nbsp; Is there another way that one can fix this quirky port numbering problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The GW setup for VOIP interface has been setup IAW the CheckPoint SK113573. Other remote phones connected over VPN tunnel function as expected.&amp;nbsp; Just the remote FiOS phones are the prime headache.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 18:27:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SIP-DYNAMIC-PORTS/m-p/92548#M3932</guid>
      <dc:creator>Thomas_Dunlap</dc:creator>
      <dc:date>2020-07-27T18:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: SIP_DYNAMIC_PORTS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SIP-DYNAMIC-PORTS/m-p/92551#M3933</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sip_dynamic_ports service was never supported in SMB.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The phones have to be configured to use permanent&amp;nbsp;source-port and destination-port (by default: 5060. If using non-default port, the SIP_UDP service port has to be changed accordingly).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;For more info about the SIP configuration which is supported in SMB, please refer to&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113573" target="_blank" rel="noopener"&gt;sk113573&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 19:04:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SIP-DYNAMIC-PORTS/m-p/92551#M3933</guid>
      <dc:creator>ronk</dc:creator>
      <dc:date>2020-07-27T19:04:03Z</dc:date>
    </item>
  </channel>
</rss>

