Community discussions

MikroTik App
 
Hussam
just joined
Topic Author
Posts: 10
Joined: Fri Dec 13, 2013 8:41 am

[Solved] SIP Over VPN Problem

Mon Dec 16, 2013 11:48 am

I have Two Office (A and B ) In each Office there is RB-750GL Router , both Office connected with L2TP VPN , in Each Office I have IP PBX connected to each other with SIP protocol.

Everything is working great , but at the end of the day office ( A ) disconnect the power from all the equipment and devices , next day morning they power up all the devices again , VPN is working fine ( file share , RDP …etc. ) except the SIP connection , if I change the PBX IP address in Office A the SIP connection will work again , then I can change it back after an hour.

I think the Router in the Office( B ) block the SIP traffic generated from The PBX because no replay from the target.
I delete all the firewall rules , and disable the NAT helper for SIP ( it have no work in VPN but I did it as try ) but the problem still the same I have to change the PBX IP address every day morning.
Any help Please.
see the attached image please
PBX.PNG
You do not have the required permissions to view the files attached to this post.
Last edited by Hussam on Sun Jan 26, 2014 7:35 pm, edited 2 times in total.
 
name29
newbie
Posts: 30
Joined: Sun Jun 20, 2010 10:25 pm

Re: SIP Over VPN Problem

Mon Dec 16, 2013 12:52 pm

Hi,

Before change IP address, please verify connection in connection tracking and check src/dst/reply src/reply dst and check connection state.


Are you natting che SIP traffic between two office or che subnet are routed ?
 
User avatar
THG
Member
Member
Posts: 472
Joined: Thu Oct 15, 2009 1:05 am

Re: SIP Over VPN Problem

Mon Dec 16, 2013 7:03 pm

Maybe you need a NAT bypass rule for your remote sites LAN IP addresses.
 
Hussam
just joined
Topic Author
Posts: 10
Joined: Fri Dec 13, 2013 8:41 am

Re: SIP Over VPN Problem

Tue Dec 17, 2013 8:32 pm

I didnt nat it because i use VPN , do i need to nat ???
all traffice working fine except SIP
any way i will try to nat and see what will happen
 
name29
newbie
Posts: 30
Joined: Sun Jun 20, 2010 10:25 pm

Re: SIP Over VPN Problem

Tue Dec 17, 2013 9:05 pm

I didnt nat it because i use VPN , do i need to nat ???
all traffice working fine except SIP
any way i will try to nat and see what will happen
Hi,

If possible not use NAT with VoIP ( Sip ).

Please verify that really your traffic between two PBX is not natted.

Can you post your routing table of the two router and ip/firewall (filter/nat) configuration?

When SIP not work, can you check if an entry exist into connection tracking and src/dst/dst reply/src reply is correct?
 
User avatar
THG
Member
Member
Posts: 472
Joined: Thu Oct 15, 2009 1:05 am

Re: SIP Over VPN Problem

Wed Dec 18, 2013 12:58 am

I didnt nat it because i use VPN , do i need to nat ???
No, you do not need NAT for your VPN connection. Depending on the configuration, you might need a NAT bypass rule placed at the top of all other NAT rules.

http://wiki.mikrotik.com/wiki/Manual:IP ... NAT_Bypass
 
Hussam
just joined
Topic Author
Posts: 10
Joined: Fri Dec 13, 2013 8:41 am

Re: SIP Over VPN Problem

Wed Dec 18, 2013 6:16 am

this is the routers configrations
Site A.png
Site B.png
this is the configration befor
then i add this NAT Bypass rule

site A
/ip firewall nat
add chain=srcnat action=accept place-before=0 \
src-address=192.168.50.0/24 dst-address=192.168.40.0/24

site B
/ip firewall nat
add chain=srcnat action=accept place-before=0 \
src-address=192.168.40.0/24 dst-address=192.168.50.0/24

but still the sme result every things is working fine through VPN except SIP , and please dont forget Sip is working if i just change the sip device IP address tell the next power disconnect then i have to change it again
You do not have the required permissions to view the files attached to this post.
 
name29
newbie
Posts: 30
Joined: Sun Jun 20, 2010 10:25 pm

Re: SIP Over VPN Problem

Wed Dec 18, 2013 10:01 am

Can you ping from pbx1 pbx2 and from pbx2 pbx1 ?

Please attach also connection tracking of SIP UDP connection when not working
 
djdrastic
Member
Member
Posts: 367
Joined: Wed Aug 01, 2012 2:14 pm

Re: SIP Over VPN Problem

Wed Dec 18, 2013 10:50 am

Can you run a Wireshark trace behind the firewalls when the connetions works as well as when it doesn't work ?
 
User avatar
THG
Member
Member
Posts: 472
Joined: Thu Oct 15, 2009 1:05 am

Re: SIP Over VPN Problem

Wed Dec 18, 2013 6:33 pm

but still the sme result every things is working fine through VPN except SIP , and please dont forget Sip is working if i just change the sip device IP address tell the next power disconnect then i have to change it again
It sounds that the session timed out and something in the router pretend the keep alive probe. Do you have any filter rules in input and forward chain?
 
Hussam
just joined
Topic Author
Posts: 10
Joined: Fri Dec 13, 2013 8:41 am

Re: SIP Over VPN Problem

Thu Dec 19, 2013 5:17 pm

I didnt nat it because i use VPN , do i need to nat ???
No, you do not need NAT for your VPN connection. Depending on the configuration, you might need a NAT bypass rule placed at the top of all other NAT rules.

http://wiki.mikrotik.com/wiki/Manual:IP ... NAT_Bypass
thank you Mr THG you are genius , it was VPN Nat bypass rule , but the strange thing it didnt work first time even after i restart the router , it work after i change the PBX IP again ( may be because it was already blocked by the firewall ) then i change it back after one hour , next day every thing still fine , thanks alot ( THG )
 
User avatar
Kreacher
Member
Member
Posts: 359
Joined: Wed Sep 25, 2013 3:58 pm
Location: Hogwarts

Re: SIP Over VPN Problem

Fri Dec 20, 2013 7:46 pm

thank you Mr THG you are genius , it was VPN Nat bypass rule ,
@Hussam
if he was helping you out please fell free to give him a Karma point, this must not paid by yours!
 
Hussam
just joined
Topic Author
Posts: 10
Joined: Fri Dec 13, 2013 8:41 am

Re: SIP Over VPN Problem

Sat Dec 21, 2013 11:16 am

Sorry dear i am new i wasnt know whats karma , sure i will do , thank you

Who is online

Users browsing this forum: jvanhambelgium and 23 guests