Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issue with ClearSIP

    NAT
    3
    9
    865
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      John_Carter
      last edited by

      Hello all. We have a pfsense 2.4.1 device installed and internet access is functional. We have 3 Panasonic SIP phones behind the firewall using ClearSIP as the provider. We have followed the steps in the support site, setting ports to static, changing connections to conservative, installing siproxy. But we are unable to get the phones to connect.

      If anyone could make some suggestions or perhaps may have used ClearSIP, any help would be greatly appreciated.

      Thank you.

      1 Reply Last reply Reply Quote 0
      • chpalmerC
        chpalmer
        last edited by

        I generally tell people to put everything back to default (no port forwards/ no static ports..)

        Instead make inbound firewall rules from the SIP server to the phones behind the firewall.  You will also want firewall rules that allow the RTP streams from whichever server(s) provide those streams inbound..

        Also- if your phones are going out for a provisioning files then make sure you have /system_advanced_firewall.php  TFTP proxy set for your phone interface.
        I can provide some screenshots of some of my sites here if you need..

        Triggering snowflakes one by one..
        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

        1 Reply Last reply Reply Quote 0
        • J
          John_Carter
          last edited by

          Screenshots would be GREAT! I really appreciate it.

          1 Reply Last reply Reply Quote 0
          • J
            John_Carter
            last edited by

            Does anyone else have any input on this issue? I appreciate it.

            1 Reply Last reply Reply Quote 0
            • A
              AndrewZ
              last edited by

              But we are unable to get the phones to connect

              No single word about possible pfSense misbehavior.

              1 Reply Last reply Reply Quote 0
              • J
                John_Carter
                last edited by

                @chpalmer:

                I generally tell people to put everything back to default (no port forwards/ no static ports..)

                Instead make inbound firewall rules from the SIP server to the phones behind the firewall.  You will also want firewall rules that allow the RTP streams from whichever server(s) provide those streams inbound..

                Also- if your phones are going out for a provisioning files then make sure you have /system_advanced_firewall.php  TFTP proxy set for your phone interface.
                I can provide some screenshots of some of my sites here if you need..

                Would you happen to have those screenshots available? I appreciate it.

                1 Reply Last reply Reply Quote 0
                • J
                  John_Carter
                  last edited by

                  So, generally speaking, if a VoIP provider follows standards, then pfsense should just work out of the box without a lot of configurations?

                  I found several sites online that suggest lots of different configs but it seems most shouldn't be necessary now?

                  I appreciate all the suggestions and help on this.

                  1 Reply Last reply Reply Quote 0
                  • A
                    AndrewZ
                    last edited by

                    Remove all the rules you added specifically for your phone(s), remove Siproxd then speak to your SIP provider.
                    pfSense is out of discussion yet.

                    1 Reply Last reply Reply Quote 0
                    • J
                      John_Carter
                      last edited by

                      @chpalmer:

                      I generally tell people to put everything back to default (no port forwards/ no static ports..)

                      Instead make inbound firewall rules from the SIP server to the phones behind the firewall.  You will also want firewall rules that allow the RTP streams from whichever server(s) provide those streams inbound..

                      Also- if your phones are going out for a provisioning files then make sure you have /system_advanced_firewall.php  TFTP proxy set for your phone interface.
                      I can provide some screenshots of some of my sites here if you need..

                      I doun't understand how I can have inbound rules to more than one phone. For example if the port is 5060, I can only forward that to one IP address right? I know I'm missing what you're saying here. Can you explain a bit further. I appreciate it.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.