Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
FrankXie
Participant

TCP SIP traffic over IPSec VPN get dropped with log first packet not syn

Hello expert

 

Recently we noticed some SIP invite timeout to SIP client through IPsec vpn at our sip agent server logs.

While checking firewall logs we noticed there are a few drops with information first packet not syn dropped by firewall with same source as previous accept vpn encrypt log hours later(looks like always more than 1 and half hour).

That specific traffic passing through internal firewall (no drop log) and reach perimeter firewall which hosting vpn connections. It suppose get encrypted and passing through vpn tunnel. 

IPsec looks fine because other traffic passing through without problem at the same time. Just wondering if there's any session timeout mismatch.

 

Firewall running R81.10

Regards

Frank

0 Kudos
2 Replies
Chris_Atkinson
Employee Employee
Employee

Are both sets of Firewalls referencing the same service objects in their respective security policy for SIP?

CCSM R77/R80/ELITE
0 Kudos
FrankXie
Participant

Hello Chris

Looks like there's some inconsistency about session timeout setting. Perimeter is default 3600 seconds but internal is 7500 seconds.  Working on sync them and will update later.

 

Thanks

Frank

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events