Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    SIP problems

    NAT
    7
    13
    3385
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      madas last edited by

      Hello all,

      I am having problems with my SIP connections through pfSense 2.0.  I have connections from two devices (a Sipura and an asterisk box) on the LAN going out to 4 different locations on the internet.

      All of them work fine (in and out), then after a day or two my asterisk box complains that it cannot connect to any of the destinations.  If I reboot the asterisk box the problem remains.  I have to go to the states window and clear out all of the connections on 5060, then magically everything works again for a few days.

      I attach a screenshot showing my states.

      Black = External IP Destination
      Red = My external IP
      10.2.1.20 = Asterisk
      10.2.1.199 = Sipura device

      Any ideas what I can do to stop this happening? I tried siproxd and that only seemed to make matters worse.

      1 Reply Last reply Reply Quote 0
      • D
        dhatz last edited by

        If it happens on WAN IP change, new versions 2.0.2 or 2.1-BETA deal better with it.

        1 Reply Last reply Reply Quote 0
        • M
          madas last edited by

          Thanks.  Maybe i'll give Beta 2.1 a try.  In this case my ip hasn't changed in months so I know that isn't the problem this time.

          1 Reply Last reply Reply Quote 0
          • D
            dhatz last edited by

            Are you using manual NAT (AON) with static-port for port 5060 ?

            1 Reply Last reply Reply Quote 0
            • M
              madas last edited by

              No, I am using automatic outbound NAT

              I used to use static ports but that also seemed to cause a lot of problems

              1 Reply Last reply Reply Quote 0
              • D
                dhatz last edited by

                Hmm … in that case further debugging is needed.

                To recap, both IPs (your WAN IP and presumably your VoIP provider SIP server's IP) remain unchanged, yet your asterisk pbx has trouble connecting every 1-2 days.

                You'll need to compare the states (pfctl -ss|fgrep x.y.z.w where x.y.z.w is your asterisk's ip) when it works and when it doesn't.

                You might also want to upgrade to pfsense 2.0.2 (or 2.1)

                1 Reply Last reply Reply Quote 0
                • J
                  joako last edited by

                  Create static port just for NAT from LAN to Asterisk IP and make sure it's at the top.

                  In the case the connection gets stuck and requires a reset to the states, I never found a good solution. All I know is now whenever I leave some SSH session open in my office overnight, it's dropped in the morning :(

                  1 Reply Last reply Reply Quote 0
                  • M
                    madas last edited by

                    I just upgraded to 2.1 Beta…i'll give it a day or two and see what happens.  If it occurs again i'll try the static nat for the asterisk server

                    1 Reply Last reply Reply Quote 0
                    • M
                      madas last edited by

                      Just to report back.  After upgrading to the 2.1 Beta this problem (and a bunch of others) have gone away.

                      1 Reply Last reply Reply Quote 0
                      • N
                        numer last edited by

                        Strange, I'm seeing exact this problem with 2.1 Beta

                        1 Reply Last reply Reply Quote 0
                        • C
                          c.radi last edited by

                          Hi,

                          I have the same Problem with 2.1
                          Is there a solution.

                          Regards
                          Christian

                          1 Reply Last reply Reply Quote 0
                          • K
                            kejianshi last edited by

                            Maybe if your WAN IP changes as often as the mood of a fickle GF, you should create a script to reboot the pfsense box every time the WAN IP changes.

                            1 Reply Last reply Reply Quote 0
                            • B
                              bullet92 last edited by

                              Hi, i have pfsense 2.0.3 and i have the same issue:
                              after 1 or 2 days SIP connection won't go and i must do a reset states to permit sip to connect as well.
                              I have a manual nat (i've tried also a autoamtic nat, but same issue) with this configuration :

                              Interface Source Source Port Destination Destination Port NAT Address NAT Port Static Port Description
                              WAN  172.16.30.0/24 * * 500 * * YES Auto created rule for ISAKMP - DMZ to WAN 
                              WAN  172.16.30.0/24 * * * * * NO Auto created rule for DMZ to WAN 
                              WAN  127.0.0.0/8 * * * * 1024:65535 NO Auto created rule for localhost to WAN 
                              WAN  192.168.132.0/24 * * 500 * * YES Auto created rule for ISAKMP - LAN to WAN 
                              WAN  192.168.132.0/24 * * * * * NO Auto created rule for LAN to WAN

                              My WAN IP's cannot change because i'm using a line with a fixed IP.

                              Waiting for your reply, Regards.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post

                              Products

                              • Platform Overview
                              • TNSR
                              • pfSense Plus
                              • Appliances

                              Services

                              • Training
                              • Professional Services

                              Support

                              • Subscription Plans
                              • Contact Support
                              • Product Lifecycle
                              • Documentation

                              News

                              • Media Coverage
                              • Press
                              • Events

                              Resources

                              • Blog
                              • FAQ
                              • Find a Partner
                              • Resource Library
                              • Security Information

                              Company

                              • About Us
                              • Careers
                              • Partners
                              • Contact Us
                              • Legal
                              Our Mission

                              We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

                              Subscribe to our Newsletter

                              Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

                              © 2021 Rubicon Communications, LLC | Privacy Policy