• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Registering on SIP via NAT reflection

Scheduled Pinned Locked Moved NAT
6 Posts 3 Posters 849 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    salmanghiyas
    last edited by Sep 11, 2021, 9:14 PM

    Hello all,

    I’m facing an issue on my pfsense.

    I have 6 different ISPs with public IPs terminated on every pfsense interface.

    I have a SIP asterisk server hosted on LAN which is accessible through one public IP via port forwarding.

    We have different branches in the country so our users register on the SIP server from different remote sites.

    All is working fine when any user from outside hit our Public IP on 5060 and easily gets registered to the SIP server.

    But our local users which are on the same LAN can only register from private local IP which causes NAT issues.

    I want my local LAN users to get registered from the Public IP, someone told me it’s possible with NAT reflection so I tried it with both NAT + Proxy and Pure NAT but I’m only able to access the server for SSH and HTTP.

    Users can’t register on SIP server via NAT reflection.

    Am I missing something?

    Or what’s the correct way to do it?

    K 1 Reply Last reply Sep 12, 2021, 3:30 AM Reply Quote 1
    • K
      KOM @salmanghiyas
      last edited by Sep 12, 2021, 3:30 AM

      @salmanghiyas said in Registering on SIP via NAT reflection:

      But our local users which are on the same LAN can only register from private local IP which causes NAT issues.

      Can you explain this a little more? What NAT issues are you seeing?

      S 1 Reply Last reply Sep 13, 2021, 11:41 AM Reply Quote 1
      • S
        salmanghiyas @KOM
        last edited by Sep 13, 2021, 11:41 AM

        @kom said in Registering on SIP via NAT reflection:

        @salmanghiyas said in Registering on SIP via NAT reflection:

        But our local users which are on the same LAN can only register from private local IP which causes NAT issues.

        Can you explain this a little more? What NAT issues are you seeing?

        my clients cannot register to my SIP server on LAN through public IP.

        S 1 Reply Last reply Sep 13, 2021, 4:19 PM Reply Quote 0
        • S
          SteveITS Galactic Empire @salmanghiyas
          last edited by Sep 13, 2021, 4:19 PM

          @salmanghiyas Generally the advice is to use split DNS so LAN devices connect to the server's LAN address (whatever kind of server it is).

          Did you check "Enable automatic outbound NAT for Reflection"?

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          S 1 Reply Last reply Sep 14, 2021, 10:29 AM Reply Quote 0
          • S
            salmanghiyas @SteveITS
            last edited by Sep 14, 2021, 10:29 AM

            @steveits said in Registering on SIP via NAT reflection:

            @salmanghiyas Generally the advice is to use split DNS so LAN devices connect to the server's LAN address (whatever kind of server it is).

            Did you check "Enable automatic outbound NAT for Reflection"?

            I would need to study in Split DNS on how to do that, havent tried it yet, any help or guide would be much appreciated.

            And YES "Enable automatic outbound NAT for reflection" is checked.

            S 1 Reply Last reply Sep 14, 2021, 2:18 PM Reply Quote 0
            • S
              SteveITS Galactic Empire @salmanghiyas
              last edited by Sep 14, 2021, 2:18 PM

              @salmanghiyas Split DNS is basically just overriding local DNS for a hostname. So the entire Internet resolves www.example.com to a public IP, and devices on the LAN are told www.example.com is a private IP via a host override.

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              1 Reply Last reply Reply Quote 0
              2 out of 6
              • First post
                2/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received