Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT drops SIP registration over time

    NAT
    2
    5
    2.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mastermindpro
      last edited by

      I've got a Cisco SIP phone that sits behind a pfSense RELENG_1 box.  It connects to my Asterisk server, and works just fine.  The problem I'm seeing is that, over time, Asterisk loses connection with my SIP phone.

      When I was running Linux/iptables on the same firewall box as I have now, I never had this problem.  Is there something I have to tweak in pfSense to get it to not drop NAT mappings?

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        Try to monitor the state of the voipphone via the shell menu (pftop). Does the state not renew it's expiration time? If not the phone doesn't contact the asterisk or viceversa when idle. In that case you might want to use a firewallrule with some advanced options to set a higher statetimeout or set the whole firewall to conservative optimization (at system>advanced).

        1 Reply Last reply Reply Quote 0
        • M
          mastermindpro
          last edited by

          In monitoring with pftop, I get multiple connections betwixt the phone and Asterisk…all listed in state MULTIPLE:MULTIPLE.  I don't know how to determine anything beyond that, but I have set optimization to conservative.  Reading the description for that makes it sound like it will fix the problem.

          Time will tell.

          1 Reply Last reply Reply Quote 0
          • M
            mastermindpro
            last edited by

            Wow…that didn't take long to tell if it worked or not.

            It didn't work.  ;D

            The NAT mapping was completely gone from the pftop output.  Do I need to modify the outbound NAT rules or the firewall rules (or both) to increase the state time as you suggest?

            1 Reply Last reply Reply Quote 0
            • H
              hoba
              last edited by

              Only firewallrules.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.