- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
via an existing VPN tunnel, IP telephones from the manufacturer Avaya are to register in a branch office via H232 on the "IP Office 500 V2" PBX at the main location and make calls via this.
The registration of the phones works.
However, telephony is not possible via these devices.
An extremely delayed operation of the IP telephones can also be seen.
In the branch office, a CP 1530 appliance establishes a permanent VPN tunnel to the CP 6400 security cluster. There is a router in front of the CP 1530 appliance and implements the Internet dial-in. There is a switch behind the CP 1530. The interfaces of the CP 1530 and the switch are assigned Vlans.
No blocked packets can be seen in the log via Smart Console.
Can someone help me to solve the problem. Thank you in advance.
Did you already contact CP TAC ?
No
Why not ? That is the way to get your issue resolved asap !
Then you will have to follow this guide: sk95369: ATRG: VoIP
What version is the 1530 operating with and how are your rules for SIP/H232 traffic defined?
What if any advanced settings are set on the 1530 with regards to VoIP?
The version of the 1530 is R80.20.50 (992002773).
There are currently no explicit rules for SIP/H232.
In the current test phase, the value "Any" is set under "Services&Applications".
There are no explicit settings on the 1530 related to VoIP.
What should be set?
Many Thanks
The 1530 is not managed locally. We use the central management.
Where can you set the appropriate settings here? Many Thanks.
Check you scenario and configure the rules based on the info available at
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
attention to "... Do not use this service in the same rule with the 'XXXX' service (because they contradict each other). ... "
Hi,
I see two important things to check here. First as every one here already told you, make sure you have a correct configuration according to your specific scenario and sk95369. Second thing, can you provide more details about your ISP connections? are they static IP addresses? dynamic? if dynamic, does DHCP provide a public IP or private IP address that is nated later by the ISP?
did you check drops on CLI with "fw ctl zdebug + drop | grep X.X.X.X" while you replicate the issue? if you did not, try filtering the PBX ip address first and then the IP phone address.
Regards
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
13 | |
3 | |
3 | |
2 | |
1 | |
1 |
Tue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureTue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFTue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY