Hi,
I wanted to reach out to the community and find out what others are doing when it comes to VoIP traffic and the Application/URL filtering layer. I want to know if others are using the built in Application Objects (i.e RTCP, SIP Object, SDP over SIP, etc) or does your rule base have a rule with just the port objects (i.e udp_5060, 5061, etc).
The reason being is that in our environment we basically have our rule duplicated from the firewall layer onto the application layer with the port objects defined. I can't remember where I saw this, but the reason being is we had some strange issues with our VoIP system in the beginning and I found an SK somewhere that stated I needed to create a separate port object instead of using the builtin system objects for firewall and application control.
So far we haven't encountered any issues doing it this way. While I'm looking over our rulebase and looking at doing some optimization for reorganization of our rulebase, I noticed our VoIP traffic on the Application Control hits the UDP port with the UDP port range object, but the logs indicate the RTCP Protocol along with it.
I'm just wanting to know specifically for the Application/URL layer what's the better way, what works better, what others are doing in their rulebase for VoIP traffic. Are you using custom UDP port objects similar to the firewall layer? Or are you using the system built in application objects?
Jonathan