Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    At times WiFi calling and sending SMS doesn't work?

    Scheduled Pinned Locked Moved Firewalling
    55 Posts 8 Posters 13.2k Views 10 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      JohnnyBeGood
      last edited by johnpoz

      @JKnott said in At times WiFi calling and sending SMS doesn't work?:

      It would be nice if they added MAC addresses to firewall rules. With IPv6, it's pretty much needed with privacy addresses.

      Ok, so I tried to compare when I can dial and when I can't but could not see any difference and what is interesting when its working I do not see ESP protocol.
      Other screenshot of pfTop is when I i'm on the call it creates connection to .233
      When I can't make call over the Wi-Fi I turn it off place the call and it goes through after that when I turrn Wi-Fi on call goes through.

      Can someone please compare packet_capture.zip logs?
      packet_capture.zip

      pfTop.JPG

      I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

      1 Reply Last reply Reply Quote 0
      • johnpozJ Online
        johnpoz LAYER 8 Global Moderator
        last edited by

        compare what zips?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07 | Lab VMs 2.8, 25.07

        1 Reply Last reply Reply Quote 0
        • J Offline
          JohnnyBeGood
          last edited by

          Attached file to the post. Forum software makes it not that visible.

          d58cf831-af9d-474d-a468-fef5c925b2af-image.png

          I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

          1 Reply Last reply Reply Quote 0
          • johnpozJ Online
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            I fixed that for you ;)

            zipslocaTion.png

            In the one you say doesn't work see ESP out to
            OrgName: Cellco Partnership DBA Verizon Wireless

            No responses.

            But in the one you say works, don't see any ESP.. I would guess you missed capturing the actual data.

            I see some talk to samsung something, and google - nothing other in that so called working sniff. Like your call actually went out over cell vs wifi.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07 | Lab VMs 2.8, 25.07

            1 Reply Last reply Reply Quote 0
            • DerelictD Offline
              Derelict LAYER 8 Netgate
              last edited by

              UDP/4500 is performing the same functionality as ESP. It is known as NAT Traversal, or NAT-T.

              I would totally expect that for an IPsec client like wifi calling behind a NAT router. It's the same as those micro-cells. They IPsec to home base and all comms are over that too.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • johnpozJ Online
                johnpoz LAYER 8 Global Moderator
                last edited by

                Pretty sure your talking to the OP there Derelict.. I am quite aware of what ESP and Port 4500 are ;)

                My point was there is only 443 traffic in his so called working pcap, and non of it was to what could be a wifi calling system either.. So either his sniff missed when the call was placed, or it didn't go over wifi like he thinks it did.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07 | Lab VMs 2.8, 25.07

                1 Reply Last reply Reply Quote 0
                • DerelictD Offline
                  Derelict LAYER 8 Netgate
                  last edited by

                  @JohnnyBeGood said in At times WiFi calling and sending SMS doesn't work?:

                  when its working I do not see ESP protocol.

                  Yeah, just commenting on that ^

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Online
                    johnpoz LAYER 8 Global Moderator
                    last edited by johnpoz

                    Yeah there was no ESP or NAT-T anything, NO anything really when he says it works - a https session to google and one to like *.push.samsungsomething.. Only thing I could make out in the cert - the hello didn't contain actual sni.

                    Where sure isn't he making a wifi call

                    So he either missed the traffic with his sniff, or his phone used cell to make the call.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07 | Lab VMs 2.8, 25.07

                    1 Reply Last reply Reply Quote 0
                    • JKnottJ Offline
                      JKnott
                      last edited by

                      I have attached a capture of a WiFi call, so the OP can see what he should be looking for. It contains both the NAT keepalive and actual IPSec traffic, which is identified by ESP, but is in fact a UDP packet encapsulating ESP.

                      WiFicall.pcapng

                      PfSense running on Qotom mini PC
                      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                      UniFi AC-Lite access point

                      I haven't lost my mind. It's around here...somewhere...

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Online
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        ^ exactly there is 2 way communication there ;) Kind of a given for any sort of call to be going on...

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07 | Lab VMs 2.8, 25.07

                        1 Reply Last reply Reply Quote 0
                        • J Offline
                          JohnnyBeGood
                          last edited by

                          @johnpoz said in At times WiFi calling and sending SMS doesn't work?:

                          Where sure isn't he making a wifi call

                          Here's the video I made showing what I was doing https://youtu.be/q-iVQqJ_wA0
                          Am I doing something wrong?

                          I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

                          JKnottJ 1 Reply Last reply Reply Quote 0
                          • johnpozJ Online
                            johnpoz LAYER 8 Global Moderator
                            last edited by johnpoz

                            Not going to watch a video... If you can not post a sniff showing traffic then no traffic is happening..

                            Your sniff showing when a call worked had ZERO traffic in that could be a call.

                            Your call showing when didn't work showed some traffic hitting the lan, so sniff on the wan did it go out? If goes out and no answer - that has zero to do with pfsense.

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 25.07 | Lab VMs 2.8, 25.07

                            J 1 Reply Last reply Reply Quote 0
                            • J Offline
                              JohnnyBeGood @johnpoz
                              last edited by

                              packetcapture (4).zip @johnpoz said in At times WiFi calling and sending SMS doesn't work?:

                              Not going to watch a video... If you can not post a sniff showing traffic then no traffic is happening..
                              Your sniff showing when a call worked had ZERO traffic in that could be a call.
                              Your call showing when didn't work showed some traffic hitting the lan, so sniff on the wan did it go out? If goes out and no answer - that has zero to do with pfsense.

                              Attached is the packet capture as shown in the video.
                              Call was never answered. "Calling" on the phone screen and silence as it was trying to place the call.

                              I'm willing to post whatever is needed in order to get to the bottom of this.

                              packetcapture (4).zip

                              I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

                              1 Reply Last reply Reply Quote 0
                              • JKnottJ Offline
                                JKnott @JohnnyBeGood
                                last edited by

                                @JohnnyBeGood said in At times WiFi calling and sending SMS doesn't work?:

                                Am I doing something wrong?

                                Yeah, trying to show what you're doing with a video. I just watched it and it's of absolutely no use.

                                Do as I did, that is run Wireshark capturing only the WiFi calling. You should have the IP address of where the call is going. Filter on that, while placing a call. Also, allow enough time to capture some of the keep alive packets. When that's done, post the capture here.

                                PfSense running on Qotom mini PC
                                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                UniFi AC-Lite access point

                                I haven't lost my mind. It's around here...somewhere...

                                J 1 Reply Last reply Reply Quote 0
                                • J Offline
                                  JohnnyBeGood @JKnott
                                  last edited by JohnnyBeGood

                                  Here's another capture of when it works and of course ESP are shown.
                                  packetcapture (6).zip

                                  .

                                  @JKnott said in At times WiFi calling and sending SMS doesn't work?:

                                  Do as I did, that is run Wireshark capturing only the WiFi calling. You should have the IP address of where the call is going. Filter on that, while placing a call. Also, allow enough time to capture some of the keep alive packets. When that's done, post the capture here.

                                  Ok, when you did your capture you used your phone's private IP on the LAN, correct?

                                  add6a6c4-88fb-4b92-bd29-898e856c71c0-image.png

                                  I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

                                  1 Reply Last reply Reply Quote 0
                                  • JKnottJ Offline
                                    JKnott
                                    last edited by

                                    Any reason why you zipped it? By zipping it, I have to download it, unzip it, then run Wireshark with the extracted file. If you just attach the capture file, it opens Wireshark directly.

                                    PfSense running on Qotom mini PC
                                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                    UniFi AC-Lite access point

                                    I haven't lost my mind. It's around here...somewhere...

                                    J 1 Reply Last reply Reply Quote 0
                                    • J Offline
                                      JohnnyBeGood @JKnott
                                      last edited by

                                      @JKnott said in At times WiFi calling and sending SMS doesn't work?:

                                      Any reason why you zipped it? By zipping it, I have to download it, unzip it, then run Wireshark with the extracted file. If you just attach the capture file, it opens Wireshark directly.

                                      Sorry but the forum does not allow me to upload it without zipping it first.

                                      f0c3db4b-2e8d-4276-bb83-05452b6c6080-image.png

                                      I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

                                      1 Reply Last reply Reply Quote 0
                                      • JKnottJ Offline
                                        JKnott
                                        last edited by

                                        @JohnnyBeGood said in At times WiFi calling and sending SMS doesn't work?:

                                        Sorry but the forum does not allow me to upload it without zipping it first.

                                        I had no problem doing that. Take a look at my post.

                                        PfSense running on Qotom mini PC
                                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                        UniFi AC-Lite access point

                                        I haven't lost my mind. It's around here...somewhere...

                                        1 Reply Last reply Reply Quote 0
                                        • DerelictD Offline
                                          Derelict LAYER 8 Netgate
                                          last edited by Derelict

                                          I'll see about getting .cap added to the allowed list of prefixes.

                                          Actually, looking at it, it is probably easier to rename the file to .pcap than to zip it.

                                          Chattanooga, Tennessee, USA
                                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                          JKnottJ 1 Reply Last reply Reply Quote 0
                                          • JKnottJ Offline
                                            JKnott @Derelict
                                            last edited by

                                            @Derelict said in At times WiFi calling and sending SMS doesn't work?:

                                            I'll see about getting .cap added to the allowed list of prefixes.

                                            Yeah, it's a bit strange the pfSense forum won't accept files created by pfSense packet capture.

                                            PfSense running on Qotom mini PC
                                            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                            UniFi AC-Lite access point

                                            I haven't lost my mind. It's around here...somewhere...

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.