- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hello,
via an existing VPN tunnel, IP telephones from the manufacturer Avaya are to register in a branch office via H232 on the "IP Office 500 V2" PBX at the main location and make calls via this.
The registration of the phones works.
However, telephony is not possible via these devices.
An extremely delayed operation of the IP telephones can also be seen.
In the branch office, a CP 1530 appliance establishes a permanent VPN tunnel to the CP 6400 security cluster. There is a router in front of the CP 1530 appliance and implements the Internet dial-in. There is a switch behind the CP 1530. The interfaces of the CP 1530 and the switch are assigned Vlans.
No blocked packets can be seen in the log via Smart Console.
Can someone help me to solve the problem. Thank you in advance.
Did you already contact CP TAC ?
No
Why not ? That is the way to get your issue resolved asap !
Then you will have to follow this guide: sk95369: ATRG: VoIP
What version is the 1530 operating with and how are your rules for SIP/H232 traffic defined?
What if any advanced settings are set on the 1530 with regards to VoIP?
The version of the 1530 is R80.20.50 (992002773).
There are currently no explicit rules for SIP/H232.
In the current test phase, the value "Any" is set under "Services&Applications".
There are no explicit settings on the 1530 related to VoIP.
What should be set?
Many Thanks
The 1530 is not managed locally. We use the central management.
Where can you set the appropriate settings here? Many Thanks.
Check you scenario and configure the rules based on the info available at
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
attention to "... Do not use this service in the same rule with the 'XXXX' service (because they contradict each other). ... "
Hi,
I see two important things to check here. First as every one here already told you, make sure you have a correct configuration according to your specific scenario and sk95369. Second thing, can you provide more details about your ISP connections? are they static IP addresses? dynamic? if dynamic, does DHCP provide a public IP or private IP address that is nated later by the ISP?
did you check drops on CLI with "fw ctl zdebug + drop | grep X.X.X.X" while you replicate the issue? if you did not, try filtering the PBX ip address first and then the IP phone address.
Regards
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY