Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    problems unblocking my sip provider

    Scheduled Pinned Locked Moved General pfSense Questions
    76 Posts 6 Posters 12.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • chpalmerC
      chpalmer
      last edited by

      Redirect Target Port is a numerical input and not what you have typed. If you want a 1:1 then do a 1:1. Otherwise do a port forward for each port or range of ports.

      Triggering snowflakes one by one..
      Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

      1 Reply Last reply Reply Quote 0
      • chpalmerC
        chpalmer
        last edited by

        I can't show you a port forward example because I never port forward to an ATA or phone. But the same idea can be seen from one of my spur office ATA setups..

        rules.jpg

        Triggering snowflakes one by one..
        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

        1 Reply Last reply Reply Quote 0
        • randomaustralianR
          randomaustralian
          last edited by randomaustralian

          The ports in the answer worked perfectly on my previous software firewall IPFire. pfSense is just more tightly programmed.

          a7a7964d-ae1c-4a14-b271-00752765e060-image.png

          3f1a0d09-73ab-4d34-8135-ebc3e69cda9d-image.png

          1:1 doesn't work either. the firewall still blocks it.

          even when i try this
          cfc85f99-c3a7-429e-aec9-93988e0e246f-image.png
          it still doesn't work. but nothing shows up in the firewall logs

          2 x UP board, 4GB RAM + 64 GB eMMC w/ vesa case (http://up-shop.org/)
          1x UP^2 Pentium Quad Core, 8GB RAM, 128GB eMMC w/ vesa case (pfSense)
          1x UP Core Plus E3950, 8GB RAM, 64GB EMMC+ Net Plus i210-IT
          1x Dell Power Edge R510
          2x Dell Power Edge R610

          1 Reply Last reply Reply Quote 0
          • chpalmerC
            chpalmer
            last edited by

            The states from that box

            states.jpg

            Triggering snowflakes one by one..
            Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

            1 Reply Last reply Reply Quote 0
            • chpalmerC
              chpalmer
              last edited by

              Have you tried a Static port?

              static.jpg

              Triggering snowflakes one by one..
              Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

              1 Reply Last reply Reply Quote 0
              • randomaustralianR
                randomaustralian
                last edited by randomaustralian

                there are heaps of states from that device... but it also runs other services from my provider. the IP address to the sip server shows up nothing.

                https://justpaste.it/4rnti

                2 x UP board, 4GB RAM + 64 GB eMMC w/ vesa case (http://up-shop.org/)
                1x UP^2 Pentium Quad Core, 8GB RAM, 128GB eMMC w/ vesa case (pfSense)
                1x UP Core Plus E3950, 8GB RAM, 64GB EMMC+ Net Plus i210-IT
                1x Dell Power Edge R510
                2x Dell Power Edge R610

                1 Reply Last reply Reply Quote 0
                • randomaustralianR
                  randomaustralian
                  last edited by

                  that wont work either because the information is not being sent to port 5060 at my end

                  2 x UP board, 4GB RAM + 64 GB eMMC w/ vesa case (http://up-shop.org/)
                  1x UP^2 Pentium Quad Core, 8GB RAM, 128GB eMMC w/ vesa case (pfSense)
                  1x UP Core Plus E3950, 8GB RAM, 64GB EMMC+ Net Plus i210-IT
                  1x Dell Power Edge R510
                  2x Dell Power Edge R610

                  chpalmerC 1 Reply Last reply Reply Quote 0
                  • chpalmerC
                    chpalmer
                    last edited by

                    Remember that when you make a change and it somehow registers then you have to sometimes wait for the registration to clear out of your providers server..

                    One thing I had to do at one point was to turn on TFTP proxy on so that some of my devices could get their config files.. That one stumped me for a bit.

                    But if it already has its file I wouldn't see that as an issue. If it has registered ever it should.

                    Systemm/Advanced/Firewall&NAT twards the bottom.

                    Triggering snowflakes one by one..
                    Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                    1 Reply Last reply Reply Quote 0
                    • chpalmerC
                      chpalmer @randomaustralian
                      last edited by

                      @randomaustralian said in problems unblocking my sip provider:

                      that wont work either because the information is not being sent to port 5060 at my end

                      Its coming from the firewall at that port. Thats a randomized port that the firwall does by default. Thats what the static port would stop.

                      Triggering snowflakes one by one..
                      Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                      1 Reply Last reply Reply Quote 0
                      • randomaustralianR
                        randomaustralian
                        last edited by

                        but the logs read like its coming from the source at port 5060 and arriving at my firewall on a random port

                        2 x UP board, 4GB RAM + 64 GB eMMC w/ vesa case (http://up-shop.org/)
                        1x UP^2 Pentium Quad Core, 8GB RAM, 128GB eMMC w/ vesa case (pfSense)
                        1x UP Core Plus E3950, 8GB RAM, 64GB EMMC+ Net Plus i210-IT
                        1x Dell Power Edge R510
                        2x Dell Power Edge R610

                        chpalmerC 1 Reply Last reply Reply Quote 0
                        • chpalmerC
                          chpalmer @randomaustralian
                          last edited by

                          @randomaustralian said in problems unblocking my sip provider:

                          but the logs read like its coming from the source at port 5060 and arriving at my firewall on a random port

                          Its trying to report back to where its told to go. If you do a static port that will change.

                          Triggering snowflakes one by one..
                          Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                          1 Reply Last reply Reply Quote 0
                          • chpalmerC
                            chpalmer
                            last edited by

                            Do you have any WAN rules pointed at 10.0.0.150 now?

                            Triggering snowflakes one by one..
                            Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                            1 Reply Last reply Reply Quote 0
                            • randomaustralianR
                              randomaustralian
                              last edited by randomaustralian

                              i put it in as you had it in the picture and its "being ignored" i cant activate it

                              and no id didnt auto create a new WAN rule

                              2 x UP board, 4GB RAM + 64 GB eMMC w/ vesa case (http://up-shop.org/)
                              1x UP^2 Pentium Quad Core, 8GB RAM, 128GB eMMC w/ vesa case (pfSense)
                              1x UP Core Plus E3950, 8GB RAM, 64GB EMMC+ Net Plus i210-IT
                              1x Dell Power Edge R510
                              2x Dell Power Edge R610

                              chpalmerC 1 Reply Last reply Reply Quote 0
                              • chpalmerC
                                chpalmer @randomaustralian
                                last edited by chpalmer

                                @randomaustralian

                                Create a WAN rule with source (their server) destination 10.0.0.150 any on the ports.
                                Put it on top of all your rules.

                                Log the rule..
                                wanrule.jpg

                                Then if anything is happening between the boxes then it will show up in your firewall logs.

                                Triggering snowflakes one by one..
                                Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                                1 Reply Last reply Reply Quote 0
                                • randomaustralianR
                                  randomaustralian
                                  last edited by

                                  aaaeaeba-8ac4-4011-a6a8-7c70ae16f06b-image.png
                                  86970dcb-348b-48bb-bfac-d79fe12d9828-image.png

                                  the phone is still not ringing for incoming calls

                                  2 x UP board, 4GB RAM + 64 GB eMMC w/ vesa case (http://up-shop.org/)
                                  1x UP^2 Pentium Quad Core, 8GB RAM, 128GB eMMC w/ vesa case (pfSense)
                                  1x UP Core Plus E3950, 8GB RAM, 64GB EMMC+ Net Plus i210-IT
                                  1x Dell Power Edge R510
                                  2x Dell Power Edge R610

                                  chpalmerC 1 Reply Last reply Reply Quote 0
                                  • chpalmerC
                                    chpalmer @randomaustralian
                                    last edited by chpalmer

                                    @randomaustralian

                                    Now you need to find out where your RTP comes from.

                                    Make a call and watch the states. When you call out it will probably connect to a different server.. Some do some dont. Depends on the carrier.

                                    If you look at my WAN rules above from 30 minutes ago you will see that I have rules for RTP for at least a couple of different locations.

                                    Triggering snowflakes one by one..
                                    Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                                    1 Reply Last reply Reply Quote 0
                                    • randomaustralianR
                                      randomaustralian
                                      last edited by

                                      2d94bcc4-a34c-4db0-bcbc-ceecfc6ea4a2-image.png

                                      that is with a connected outgoing call. that all i get in hte :50** range

                                      2 x UP board, 4GB RAM + 64 GB eMMC w/ vesa case (http://up-shop.org/)
                                      1x UP^2 Pentium Quad Core, 8GB RAM, 128GB eMMC w/ vesa case (pfSense)
                                      1x UP Core Plus E3950, 8GB RAM, 64GB EMMC+ Net Plus i210-IT
                                      1x Dell Power Edge R510
                                      2x Dell Power Edge R610

                                      1 Reply Last reply Reply Quote 0
                                      • chpalmerC
                                        chpalmer
                                        last edited by

                                        Looks like the inbound SIP port for you is 5065..

                                        Your RTP is most likely somewhere other than at 5004 then.

                                        Triggering snowflakes one by one..
                                        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                                        1 Reply Last reply Reply Quote 0
                                        • chpalmerC
                                          chpalmer
                                          last edited by

                                          Do a packet capture of your device from the firewall while making a call..

                                          or you can go to status/status graph and set it for remote. See what is constant while the call is in progress.

                                          Triggering snowflakes one by one..
                                          Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                                          1 Reply Last reply Reply Quote 0
                                          • stephenw10S
                                            stephenw10 Netgate Administrator
                                            last edited by

                                            Still watching. Looks like you guys are getting close.

                                            The 1:1NAT rule we tried some time back should have taken care if the static outbound NAT and allowed back any traffic as long as you had firewall rules to pass it.

                                            The fact you were seeing the reply traffic blocked at all shows the states had closed. The keep-alives my be too far apart, or not there at all.

                                            Steve

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.