I have problem with my external SIP phones.
When I am in the same lan with the laptop and one of the phones as example
and I make a ipsec/l2tp connection from the laptop the phone disconects from the SIP and give time out on registraton.
When some time pass after I disconnect the vpn connection the phone makes the registration successfull.
RB2011UAS-2HnD
This are my firewall settings:
Code: Select all
192.168.20.2 - IP of the SIP Server
XXX.XXX.XXX.XXX - external IP of the router
# apr/15/2014 09:09:01 by RouterOS 6.4
# software id = 9LHA-SJ05
#
/ip firewall filter
add chain=input dst-port=5060-5082,10000-20000 protocol=udp
add chain=forward dst-port=5060-5082,10000-20000 protocol=udp
/ip firewall nat
add action=masquerade chain=srcnat comment="Default NAT rule" out-interface=\
bridgeWan src-address=192.168.20.0/24
add action=dst-nat chain=dstnat disabled=yes dst-port=5060-5082,10000-20000 \
protocol=udp to-addresses=192.168.20.2
add action=dst-nat chain=dstnat disabled=yes dst-port=5060-5061 protocol=tcp \
to-addresses=192.168.20.2
add action=netmap chain=dstnat comment="SIP TCP 5060 IN" dst-address=\
XXX.XXX.XXX.XXX dst-port=5060 in-interface=bridgeWan protocol=tcp \
src-address=0.0.0.0/0 to-addresses=192.168.20.2 to-ports=5060
add action=netmap chain=dstnat comment="SIP UDP 5060-5082 IN" dst-address=\
XXX.XXX.XXX.XXX dst-port=5060-5082 in-interface=bridgeWan protocol=udp \
src-address=0.0.0.0/0 to-addresses=192.168.20.2 to-ports=5060-5082
add action=netmap chain=dstnat comment="RTP 10000-20000 IN" dst-address=\
XXX.XXX.XXX.XXX dst-port=10000-20000 in-interface=bridgeWan protocol=udp \
src-address=0.0.0.0/0 to-addresses=192.168.20.2 to-ports=10000-20000
add action=netmap chain=srcnat comment="SIP TCP 5060 OUT" protocol=tcp \
src-address=192.168.20.2 src-port=5060 to-ports=5060
add action=netmap chain=srcnat comment="SIP UDP 5060-5082 OUT" protocol=udp \
src-address=192.168.20.2 src-port=5060-5082 to-ports=5060
add action=netmap chain=srcnat comment="RTP UDP 10000-20000 OUT" protocol=udp \
src-address=192.168.20.2 src-port=10000-20000 to-ports=10000-20000
/ip firewall service-port
set ftp disabled=yes
set tftp disabled=yes
set irc disabled=yes
set h323 disabled=yes
set sip disabled=yes
set pptp disabled=yes
5060 TCP/UDP, 5061-5082UDP, 10000-20000UDP to the server.
Now I cant make external SIP calls. Nothing is changed in the server, so I think that the problem is in the firewall.
Where I am wrong?