Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFSense support SIP Traffic Through NAT?

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 4 Posters 3.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      alestan3
      last edited by

      First question: see subject header

      Second question:  In regards to SIP and NAT does PFSense rewrite packets to have the external IP on it?

      Thank you!

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        |'ve not had cause to try it myself but I think this is what you're looking for:
        http://doc.pfsense.org/index.php/Siproxd_package

        Steve

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by

          first question: of course.

          second question:  by default, no, and generally that's bad (lots of the devices that do so break SIP in various ways), but if you're in a scenario where that's a must, siproxd does so.

          1 Reply Last reply Reply Quote 0
          • D
            dhatz
            last edited by

            PFSense support SIP Traffic Through NAT?

            pfsense does not do any special handling of SIP traffic, i.e. by default it doesn't enable any "proxy" (aka ALG Application Level Gateway). SIP traffic is handled just like all other traffic. This is generally a good thing, because many SIP ALGs implemented in routers break things.

            However, since the pf (packet filter used by pfsense) implements the so-called "symmetric NAT" (more) i.e. the most restrictive (and secure) type of NAT, on average it leads to more headaches with non-NAT-aware protocols (like SIP) than if you were using a NAT firewall implementing a more permissive NAT algo.

            Developments of NAT traversal technologies (STUN, ICE etc) in recent years have made things much easier with SIP, so it boils down to the capabilities and configuration of both your SIP device and your VoIP provider, which is why there isn't really a single configuration that one could post here for every pfsense user to use.

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              @dhatz:

              "symmetric NAT" (more) i.e. the most restrictive (and secure) type of NAT.

              Wow, 100% pure information on that page. I just discovered I knew nothing.
              Thanks Dhatz.  :)

              Steve

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.