Issue description:
Many of our customers have reported the following issue in recent weeks. Telephone VoIP connections are terminated and can no longer be established.
Issue debug:
On the firewall you see a typical issue with the following message if you start: # fw ctl zdebug drop
Issue message: fwconn_key_init_links (INBOUND) failed
Solution:
There are two different Servers on the SIP/RTP provider's side that take part in the process of establishing the SIP/RTP call:
- Server for SIP (Management and control)
- Server for RTP (Media and Voice Data)
Make sure that the UDP high ports from the internal RTP VoIP telephone system to the provider RTP server on the RTP provider's side are dropped by the rule base on 600 / 1100 / 1200 / 1400 appliance:
RTP rules:
- Create a service for the UDP high ports and use it in an incoming Accept rule, which also has to allow the RTP ports.
- Create a drop rule to block outgoing connections from the Internal RTP server (VoIP telephone system) to the provider's RTP server on high UDP ports
SIP rule:
- Create an allow rule for incoming and outgoing SIP traffic on UDP port 5060
Example:
A similar description can be found in SK104082.
Regards,
Heiko
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips