cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
nsoares
Ivory

VOIP by VPN

Hi Everyone,


I have a VPN conection to my ClusterXL Checkpoints (4200 appliances). Everything works fine, except VOIP calls.

I can sucessfully make a conection to my voip server, make voice calls from the internal network to the external network, but when I make calls from the external network to the internal network, get this error:

"

Firewall - Protocol violation detected with protocol:(RTP), matched protocol sig_id:(1), violation sig_id:(9). (500)


"

What can I do? Without compromise my security?

 

 

0 Kudos
5 Replies
Admin
Admin

Re: VOIP by VPN

Where are the SIP clients and server in relation to the VPN endpoints? A network diagram would help as well as what version of code is involved and the rule(s) matching the traffic.

Note that VoIP protections are considered basic firewall protections, not IPS.

0 Kudos
nsoares
Ivory

Re: VOIP by VPN

Hi

Thank you for your reply. I solved the problem after posting my question.

Thank you for your help.

 

0 Kudos

Re: VOIP by VPN

I have this same issue. How did you solve it @nsoares?
0 Kudos
nsoares
Ivory

Re: VOIP by VPN

Hi Cris_Allen,

In my case, the problem was asymmetrical routing and the topology wasn't configured correctly.

Assuming that your problem is the same as mine, the solution is:

1- It's essencial to ensure that all traffic is received and sended in the same VLAN/network (check routes);
2- Create a network group and add all the networks that will pass by that VLAN/network to communicate with the server;
3- In the checkpoint cluster gateway definitions, go to network management, open the interface that you want to configure and in topology setting select modify, Internal (leads to local network), specific and put the group previously created.

4- Check the firewall rules, allowing networks to communicate with the server and vice-versa.

After that,  everything should work just fine!

0 Kudos

Re: VOIP by VPN

Maybe you can find help here: sk95369: ATRG: VoIP

0 Kudos