Community discussions

MikroTik App
 
samirkal
just joined
Topic Author
Posts: 3
Joined: Thu Oct 03, 2013 10:48 am

sip problem with nat masquerade

Thu Oct 03, 2013 11:08 am

I created a pptp vpn server in mikrotik and its working with android smart phones sip, when I enable nat rule with masquerade to allow clients to connect through vpn to internet, sip voice no longer works, I can dial sip number but when in call no voice is heard.
When disabling nat rule there is no problem.
How can I fix this ?

Thanks
 
User avatar
cbrown
Trainer
Trainer
Posts: 1839
Joined: Thu Oct 14, 2010 8:57 pm
Contact:

Re: sip problem with nat masquerade

Thu Oct 03, 2013 2:27 pm

It would help if we could see that NAT rule. Post /export compact
 
samirkal
just joined
Topic Author
Posts: 3
Joined: Thu Oct 03, 2013 10:48 am

Re: sip problem with nat masquerade

Thu Oct 03, 2013 2:33 pm

I created nat rule with
chain=srcnat
src .address 192.168.14.0/24
and action=masquerade

thats it
 
samirkal
just joined
Topic Author
Posts: 3
Joined: Thu Oct 03, 2013 10:48 am

Re: sip problem with nat masquerade

Thu Oct 03, 2013 2:35 pm

It would help if we could see that NAT rule. Post /export compact

its a rule with chain=srcnat and src. address=192.168.14.0/24 and action = masquerade
 
User avatar
pcunite
Forum Guru
Forum Guru
Posts: 1345
Joined: Sat May 25, 2013 5:13 am
Location: USA

Re: sip problem with nat masquerade

Thu Oct 03, 2013 3:34 pm

The audio portion of a VoIP call, the RTP session, is handled on a separate port and UDP session. To make this work with typical equipment and firewalls you have two options.

1.
Enable NAT Keepalive interval on your VoIP equipment. This keeps a UPD session alive by sending out a UPD packet every 120 seconds or so. Thus firewall rules see a related or established connection all the time. When the SIP handshake creates the RTP session, the firewall lets it work.

2.
Narrow down the port ranges RTP uses so you can easily mark them and do what you wish. We do that here so we can apply Qos rules. You could also allow IP ranges from your VoIP provider, etc.

Note that MikroTik enables by default so called NAT helpers under /ip firewall service-port. I have those turned off.

Who is online

Users browsing this forum: Amazon [Bot], Google [Bot] and 124 guests