Fortinet Fortigate Firewalls

Status
Not open for further replies.

KonradSC

Active Member
Mar 10, 2017
166
99
28
Hello. Does anyone have any tips or tricks for getting SIP traffic to pass correctly through a Fortigate firewall? We are running SIP over UDP and have disabled SIP ALG & SIP session helper as stated in this KB article.
https://kb.fortinet.com/kb/documentLink.do?externalID=FD36405

All phones can register and can make outgoing calls, however inbound calls do not work.

I am aware that you can beat these issues with TLS or possibly TCP. In this case I'm looking specifically for a UDP solution.

Thanks!
 

Low

New Member
Apr 15, 2021
2
1
3
On the Fortigate can you do a debug from the CLI and see what it sees when an inbound cal tries to establish? If you know the ip address that is the source I would probably use that for the debugs. If the source ip is heavily used it may be hard to capture the correct debugs.

dia deb reset
dia deb flow filter addr x.x.x.x
dia deb flow trac start 200
dia deb flow en
 
  • Like
Reactions: KonradSC

bcmike

Active Member
Jun 7, 2018
337
58
28
54
I'm not familiar with FortiGate specifically but usually this is a case of the NAT mapping timing out. I'd look to see if you can change any of the timeout values on UDP mappings, failing that decrease the time on your keep alive messages in the phone config, assuming you've enabled keep alive.
 
  • Like
Reactions: KonradSC
Status
Not open for further replies.