- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I am in a sticky situation with a customer of mine.
We are displacing SonicWALL. The migration has been no problem minus the telephony system.
Due to this, the cutover has had to be rolled back multiple times.
Ill try keep this brief to aid assistance 🙂
TAC case has been raised, but any technical advice would be wonderful. This is a particular unique setup with a Teams front end as a softphone client, with a SBC on site with the SIP trunks being on a different network delivered in by a 3rd party.
SIP ALG has been disabled and enabled many times. Interestingly, outbound calls only work with the proper defined SIP object.
NAT Rules are all static, and not hide.
SIP Inspection settings have been changed not to change hide NAT source port regardless.
The topology is as follows
Microsoft Teams Public ->NAT-> SBC on Premise ->NAT-> Telephony Provider Network
Facts:
Thanks all!
Did you contact TAC yet ?
TAC contacted. No response yet.
I have narrowed the issue to where I think it is.
SIP Session is OK - so lets ignore 5060 etc.
RTP is the issue. Between SBC and Microsoft Teams I can see the outbound RTP. Fixed source port, high UDP destination port
Nothing is coming back from Microsoft Teams as far as I can see on SmartConsole.
Due to having to roll back, no kernel debugs or packet captures to 100% verify the above.
Any advice on if you have seen inbound RTP streams being received but being chewed in the kernel (hence no SC logs) would be welcome 🙂
You could check if they are dropped and received on the external internal with a. kernel debug.
cppcap -i <external interface>
fw ctl debug 0
fw ctl debug -buf 32768
fw ctl debug -m fw + drop conn
fw ctl kdebug -T -f > debugfile.txt
<Make Teams call>
fw ctl debug 0
Well, I know in the old days of CP, one thing people would do is set protocol handler to none, but not sure if that made any difference for you.
Andy
This is the odd thing..
Outbound calls only work with the protocol handler set! Role reversal.
Got it. I would follow voip ARTG sk (cant get it now, as support center is super slow), but if that does not help, TAC case I suppose...
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY