-
Website
http://dmiessler.com/ -
Original page
http://dmiessler.com/blog/problems-with-check-point-nat-and-sip -
Subscribe
All Comments -
Community
-
Top Commenters
-
ax0n
5 comments · 1 points
-
Maxo
12 comments · 2 points
-
Michael Blume
5 comments · 1 points
-
cooperati
179 comments · 2 points
-
dapxin
39 comments · 1 points
-
-
Popular Threads
maybe this will help
http://blog.sekiur.com/2008/12/checkpoint-firew...
So you mean you can't create an inbound port forwarding rule? (which on most devices implies that the outbound source ports will be preserved)
Also are you sure the device doesn't have any SIP Application Layer Gateway functionality enabled?
I have tested it. And although CheckPoint does change the source port, it does properly handle messages coming back. It properly changes the ports.
You mentioned that it is during the initial phase. If it not be during initial phase than I would guest that the problem might be that the UDP session times out. But it should be alive for at least 40 seconds (which is default). Could you provide me with pcap dumps? I do not want to install the whole asterisk thing :)
Besides it seems that VOIP is broken in the first place ;)
For some stuff like this one, Check Point should have more granular controls, like UDP virtual session timeouts per protocol and/or rule.
Any additional ideas?
Why should a NAT-device user the same source port? What if a second connection uses the same?