<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[GrandStream HT502 BEHIND router]]></title><description><![CDATA[<p dir="auto">hello,</p>
<p dir="auto">I have a HARD time getting a Granstream HT502 to work in conjunction with pfsense and since I no longer have a cellphone and VOIP will be my only phone, I am in a rush to get this working.</p>
<p dir="auto">Anyone who can coach me, please share!</p>
<p dir="auto">Basically, I have tried 2 different configurations:</p>
<p dir="auto"><strong>Before the pfsense router (i.e. between my cable modem and the opfsense box)</strong><br />
Phone works (with LOTS of noise and static), and sound is chioppy.  I believe this is because there's no QoS being done since the pfsense box doesnt see the ATA device.</p>
<p dir="auto">My 30Mbps/10Mbps connection is throttled to around 15Mbps/5Mbps.  This is not going to happen ;)</p>
<p dir="auto"><strong>After the pfsense machine (as a LAN device like my computers, printers, etc)</strong><br />
I have configured the ATA as much as possible (given the crappy firmware in it) for it to get an IP from pfsense, and that works flawlessly.  I can reach the webinetrface and see its status.</p>
<p dir="auto">The problem is that the ATA never registers with my service provider.  Im not sure why.</p>
<p dir="auto">According to them, my router is causing the problems.  I tried opening ports, doing port forwarding as per my service provider's instructions, to no avail.  The ATA just doesnt reach the outside world.</p>
<p dir="auto">I tried setting up WAN rules to direct the outside traffic to the ports 5060, 5061, 10538, etc (as my service provide suggested) but its not working.</p>
<p dir="auto">Can someone guide me through setting up pfsense to support a simple ATA )VOIP) device??</p>
<p dir="auto">Pfsense is still cryptic for me since Im just a normal home user and not a network expert..</p>
<p dir="auto">Thanks!!!!</p>
]]></description><link>https://forum.netgate.com/topic/59594/grandstream-ht502-behind-router</link><generator>RSS for Node</generator><lastBuildDate>Tue, 08 Sep 2026 13:26:56 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/59594.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 22 Aug 2013 19:36:28 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Thu, 29 Aug 2013 14:50:21 GMT]]></title><description><![CDATA[<p dir="auto">As suggested above - these are NOT pfsense-specific issues for the most part. You need to work with <strong>upstream</strong> to get those sorted out, improved, polished, more usable, less sucky, more shiny, more out-of-the box experience stuff. Those <strong>downstream</strong> pfSense guys just package the stuff together and ship it (in addition, providing some added value, such at the GUIs.) Unless the issue is one related to the packaging/customized configuration stuff… this won't get solved here.</p>
]]></description><link>https://forum.netgate.com/post/414280</link><guid isPermaLink="true">https://forum.netgate.com/post/414280</guid><dc:creator><![CDATA[doktornotor]]></dc:creator><pubDate>Thu, 29 Aug 2013 14:50:21 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Thu, 29 Aug 2013 14:34:30 GMT]]></title><description><![CDATA[<p dir="auto">All right, I get the point.  This is really eye opening and changed the way I see the pfsense project forever.</p>
<p dir="auto">I still dream that some day, there are some REALLY SOLID packages for pfsense.</p>
<p dir="auto">I kept tinkering with this because for a long while, I had success with the pfsense - havp - squid - snort - squidguard combination…  Real success.</p>
<p dir="auto">I still think all of this can be somewhow improved or fixed.</p>
]]></description><link>https://forum.netgate.com/post/414271</link><guid isPermaLink="true">https://forum.netgate.com/post/414271</guid><dc:creator><![CDATA[pftdm007]]></dc:creator><pubDate>Thu, 29 Aug 2013 14:34:30 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Thu, 29 Aug 2013 13:50:08 GMT]]></title><description><![CDATA[<p dir="auto">I understand your frustrations.  Me, being a relative newbie here get your point.<br />
However, the reason the devs and others are not jumping through whoops to reply is because your issues have actually already been talked to death on the forums and they are really busy people.  (I'd guess that anyway)</p>
<p dir="auto">If I were you, I'd run pfsense as vanilla as I could and only add what is needed.<br />
I'd say the same for all distros.</p>
]]></description><link>https://forum.netgate.com/post/414249</link><guid isPermaLink="true">https://forum.netgate.com/post/414249</guid><dc:creator><![CDATA[kejianshi]]></dc:creator><pubDate>Thu, 29 Aug 2013 13:50:08 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Thu, 29 Aug 2013 12:40:43 GMT]]></title><description><![CDATA[<p dir="auto">This is just funny. You need a rather flaky and sensitive VOIP stuff working behind firewall, and instead of setting things up so that it works and calling it a day, you go, overload your box with extremely intrusive, extremely resource intensive and rather horrible to maintain bloat and come back to vent your frustrations about how broken it is. Seriously. Just do <strong>not</strong> do that! You are causing this whole trouble to yourself!</p>
<p dir="auto">Now - yeah, snort does NOT work out of the box, never has, never will. And quite frankly my point of view is that it is just pure evil for any home/SOHO environment, not to mention the effort constant babysitting required. (This thing has been dropped from multiple firewall distros for a damn good reason, your rants being a prime example. The mailing lists and forums basically flooded with complaints from people thinking that IDS/IPS/UTM is a musthave, point-and-click, plug and play stuff.) Getting similar intrusive and complicated setups working does not take hours nor days… Do not have time and patience for that? Well, see above, just don't install such things. And regardless, take as a fact that it may just as well <em>never</em> work properly with things like some buggy flaky VOIP device, depending on the device itself, the SIP provider, the ISP, etc. etc. etc.</p>
<p dir="auto">Finally, these issues are nothing pfsense specific. Snort is exact same intrusive and disruptive everywhere else, HAVP (and the ClamAV thing behind it) does not magically become any better, nor does squid/squidguard when run on say Debian or Fedora instead of FreeBSD/pfSense.</p>
]]></description><link>https://forum.netgate.com/post/414221</link><guid isPermaLink="true">https://forum.netgate.com/post/414221</guid><dc:creator><![CDATA[doktornotor]]></dc:creator><pubDate>Thu, 29 Aug 2013 12:40:43 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Thu, 29 Aug 2013 12:22:42 GMT]]></title><description><![CDATA[<p dir="auto">Geez!  doktornotor calm down !!! ;)</p>
<p dir="auto">While I have shown signs of frustrations, my frustrations really were about the packages not the base platform.  If any of you took 2 seconds to look at my other thread where I <strong>EXPLICITELY</strong> mentioned that on the base platform I had ZERO problems, but with HAVP, Squid and its crappy guardian, I had issues, you would have understood my POV.</p>
<p dir="auto">I have repeatedly said that I was more than willing to give my time for <strong>FREE</strong> to help troubleshoot and analyze what the hell is going on with these packages because they're not working well.  Is this not what Opensource projects needs in the end?  Contributors and people helping for <strong>FREE</strong>?</p>
<p dir="auto">It is not pfsense that frustrates me, it is <strong>NOT</strong> even the packages so much , its people <strong>attitude</strong>.</p>
<p dir="auto">You post severe problems you have, you spend the necessary time to document it and write a meaningful thread about it, you explicitly ask developers and other "experts" to at least say a few words, and all you get is:</p>
<blockquote>
<p dir="auto">13 Replies<br />
1139 Views</p>
</blockquote>
<p dir="auto">Which on the 13 replies, 11 are <strong>MINE</strong>.</p>
<p dir="auto">Thats fine.  I get the point.  pfsense is meant to be alone to work properly, no packages added.  Then I suggest pfsense devs add a big fat warning in the package manager:</p>
<blockquote>
<p dir="auto">Warning!  Adding packages may (will) break your pfsense install</p>
</blockquote>
]]></description><link>https://forum.netgate.com/post/414216</link><guid isPermaLink="true">https://forum.netgate.com/post/414216</guid><dc:creator><![CDATA[pftdm007]]></dc:creator><pubDate>Thu, 29 Aug 2013 12:22:42 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Thu, 29 Aug 2013 09:38:21 GMT]]></title><description><![CDATA[<p dir="auto">Well - There is routing, which pfsense does very well.</p>
<p dir="auto">Then there is firewalling, which pfsense also does well.</p>
<p dir="auto">Then there are add on packages, which do various other things like clamav and caching squid proxy and those things are neither routing nor are they anthing to do with firewall..</p>
<p dir="auto">And then there are the UTM features of pfsense.  Not know what you are doing WILL break your install.</p>
<p dir="auto">While I don't share the dislike of clamav, I do have a dislike for all AV in general.  They are resource hogs.<br />
Better to use OSes that don't require you to run it and just load AV on your play/gaming machines.<br />
Probably nobody who doesn't NEED the last 2 sets of features at the router should touch those.</p>
<p dir="auto">Almost no one needs the UTM stuff at home, but if you go there, don't say pfsense is broken.  Some really patient fairly expert people get those features to work just fine.  The key being expert + patient.  Like you really keep an eye on it.</p>
<p dir="auto">These systems are not automatically better the more you add to them.</p>
]]></description><link>https://forum.netgate.com/post/414154</link><guid isPermaLink="true">https://forum.netgate.com/post/414154</guid><dc:creator><![CDATA[kejianshi]]></dc:creator><pubDate>Thu, 29 Aug 2013 09:38:21 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Thu, 29 Aug 2013 04:50:56 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">my tinkering is causing me too many issues and headaches</p>
</blockquote>
<p dir="auto">There- fixed that for you!</p>
<p dir="auto">A plain Jane router is just that. No firewall.  SIP doesn't like NAT. It can be made to work if your patient. Try Vonage. It will work fine. That tells me that there are other underlying factors going on with some SIP providers.</p>
<blockquote>
<p dir="auto">DO I really need 3 NIC's???</p>
</blockquote>
<p dir="auto">No. You don't.</p>
]]></description><link>https://forum.netgate.com/post/414123</link><guid isPermaLink="true">https://forum.netgate.com/post/414123</guid><dc:creator><![CDATA[chpalmer]]></dc:creator><pubDate>Thu, 29 Aug 2013 04:50:56 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Thu, 29 Aug 2013 04:26:39 GMT]]></title><description><![CDATA[<p dir="auto">@lpallard:</p>
<blockquote>
<p dir="auto">pfsense is causing me too many issues and headaches.  I think Im gonna find another firewall project or go back to a simple plain Jane router…</p>
</blockquote>
<p dir="auto">Sorry, but installing junk and blaming the OS just makes no sense. HAVP sucks, is broken, is not worth it, is not protecting you in any meaningful way. It uses ClamAV with absolutely pathetic detection rate, yet plagued with loads of false positives, which eats tons of resources, makes downloads suck. Any free AV on a workstation makes couple orders of magnitudes better job here. Installing HAVP, squidguard, snort on the same box? Are you mad?</p>
<p dir="auto">You are causing all this grief to yourself. " simple plain Jane router…" - yeah, that's what you get with vanilla pfS install - before you go on a resource killing spree with all those things mentioned above. They are NOT required. They are NOT needed. They are harmful in most cases. They make you babysit the firewall 24/7.</p>
<p dir="auto">Doctor, it hurts when I do this... Yeah, so don't do that.</p>
]]></description><link>https://forum.netgate.com/post/414121</link><guid isPermaLink="true">https://forum.netgate.com/post/414121</guid><dc:creator><![CDATA[doktornotor]]></dc:creator><pubDate>Thu, 29 Aug 2013 04:26:39 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Thu, 29 Aug 2013 02:43:57 GMT]]></title><description><![CDATA[<p dir="auto">THings were too good to be true… Until I added a domain in squidguard target categoriues and suddenly the whole router crawled to a stop.. I knew what it was 1000000%</p>
<p dir="auto">See http://forum.pfsense.org/index.php/topic,63025.msg357852.html#msg357852</p>
<p dir="auto">Clearly nobody thinks this is a problem.  IMO something is <strong>severely</strong> broken in pfsense's packages.</p>
<p dir="auto">See the result of ps -A:</p>
<p dir="auto">20 million havp and squidguard processes running anybody think its normal?!</p>
<pre><code>$ ps -A
  PID  TT  STAT      TIME COMMAND
    0  ??  DLs  177:38.54 [kernel]
    1  ??  SLs    0:00.05 /sbin/init --
    2  ??  DL     1:50.16 [g_event]
    3  ??  RL     4:25.76 [g_up]
    4  ??  DL     2:53.40 [g_down]
    5  ??  DL     0:00.00 [crypto]
    6  ??  DL     0:00.00 [crypto returns]
    7  ??  DL     0:00.00 [sctp_iterator]
    8  ??  DL     1:03.50 [pfpurge]
    9  ??  DL     0:00.00 [xpt_thrd]
   10  ??  DL     0:00.00 [audit]
   11  ??  RL   23533:39.71 [idle]
   12  ??  WL   483:41.74 [intr]
   13  ??  DL     0:00.00 [ng_queue]
   14  ??  DL     7:57.60 [yarrow]
   15  ??  DL     0:42.49 [usb]
   16  ??  DL     1:39.58 [acpi_thermal]
   17  ??  DL     0:16.16 [pagedaemon]
   18  ??  DL     0:00.36 [vmdaemon]
   19  ??  DL     0:00.04 [pagezero]
   20  ??  DL     0:03.54 [idlepoll]
   21  ??  DL     0:17.68 [bufdaemon]
   22  ??  DL    15:17.22 [syncer]
   23  ??  DL     0:14.00 [vnlru]
   24  ??  DL     0:21.51 [softdepflush]
   40  ??  DL     0:19.84 [md0]
  245  ??  INs    3:21.70 /usr/local/sbin/check_reload_status
  247  ??  IWN    0:00.00 check_reload_status: Monitoring daemon of check_reloa
  257  ??  Is     0:00.02 /sbin/devd
 2396  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
 2715  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
 2738  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
 2845  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
 4907  ??  D      0:09.28 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
 5011  ??  D      0:08.78 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
 5319  ??  D      0:09.04 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
 5396  ??  D      0:09.29 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
 5529  ??  Is     0:00.13 /usr/local/sbin/sshlockout_pf 15
 5736  ??  D      0:08.72 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
 6035  ??  Is     0:00.00 /usr/sbin/sshd
 6365  ??  D      0:22.03 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
 6468  ??  D      0:23.23 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
 6515  ??  D      0:21.55 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
 6801  ??  Is     0:00.07 dhclient: re0 [priv] (dhclient)
 6848  ??  D      0:21.44 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
 7114  ??  D      0:21.84 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
 8100  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
 8230  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
 8480  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
 8808  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
 9023  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
 9289  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
 9496  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
 9753  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
10724  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
10778  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
10913  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
12344  ??  Ss     0:20.32 dhclient: re0 (dhclient)
13208  ??  Ss     0:15.62 /usr/sbin/cron -s
16871  ??  Ss     4:33.25 /usr/sbin/syslogd -s -c -c -l /var/dhcpd/var/run/log 
17328  ??  D      0:17.47 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
17662  ??  D      0:17.63 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
17685  ??  D      0:17.99 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
17777  ??  D      0:17.64 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
17814  ??  D      0:17.42 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
17934  ??  D      0:33.44 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
18190  ??  D      0:33.49 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
18243  ??  D      0:34.27 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
18529  ??  D      0:32.95 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
18705  ??  D      0:33.19 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
20216  ??  S      0:00.67 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
20557  ??  S      0:00.47 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
20578  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
20768  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
20884  ??  Is     0:00.04 /usr/local/sbin/squid -D
20949  ??  S      0:00.17 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
21239  ??  S      0:00.27 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
21403  ??  S      0:00.02 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
21675  ??  S      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
21798  ??  I      0:00.30 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
21881  ??  S      0:00.09 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
22095  ??  Ds   307:46.96 /usr/local/bin/ntop -i re0,re1 -u root -d -4 -M -x 81
22142  ??  Is     2:19.13 /usr/local/sbin/filterdns -p /tmp/filterdns.pid -i 30
22209  ??  I      0:00.02 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
22304  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
23045  ??  Ds    71:53.62 /usr/local/sbin/clamd -c /usr/local/etc/clamd.conf
23741  ??  DL     0:06.21 [md10]
24125  ??  Ss     7:37.85 /usr/local/sbin/apinger -c /var/etc/apinger.conf
25631  ??  SN     0:00.00 sleep 60
25762  ??  R      0:00.01 ps -A
28072  ??  S      0:59.81 /usr/local/sbin/lighttpd -f /var/etc/lighty-webConfig
28602  ??  IWs    0:00.00 /usr/local/bin/php
30096  ??  IWs    0:00.00 /usr/local/bin/php
30530  ??  Ss     0:25.95 /usr/local/sbin/dhcpd -user dhcpd -group _dhcp -chroo
32419  ??  S      0:06.04 /usr/local/bin/php
32731  ??  D      0:50.29 /usr/local/bin/php
38698  ??  S      0:01.39 (squid) -D (squid)
38859  ??  I      0:00.00 (unlinkd) (unlinkd)
39204  ??  I      0:00.09 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
39339  ??  I      0:00.07 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
39437  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
39503  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
39559  ??  Ss     2:04.82 /usr/local/bin/ntpd -g -c /var/etc/ntpd.conf
39682  ??  S      0:00.07 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
39825  ??  S      0:00.09 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
39965  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
40116  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
40538  ??  S      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
40849  ??  I      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
40980  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
41205  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
42829  ??  I      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
42997  ??  D      0:09.75 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
43100  ??  IWs    0:00.00 /usr/local/bin/minicron 240 /var/run/ping_hosts.pid /
43129  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
43158  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
43186  ??  D      0:09.26 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
43229  ??  R      0:11.26 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
43281  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
43530  ??  I      0:01.81 minicron: helper /usr/local/bin/ping_hosts.sh  (minic
43541  ??  D      0:09.40 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
43674  ??  S      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
43677  ??  I      0:09.61 /usr/local/bin/rrdtool -
43730  ??  D      0:31.64 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
43739  ??  D      0:09.46 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
43767  ??  IWs    0:00.00 /usr/local/bin/minicron 3600 /var/run/expire_accounts
43771  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
43823  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
44076  ??  R      0:30.82 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
44086  ??  S      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
44098  ??  I      0:00.10 minicron: helper /etc/rc.expireaccounts  (minicron)
44167  ??  IWs    0:00.00 /usr/local/bin/minicron 86400 /var/run/update_alias_u
44226  ??  S      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
44348  ??  D      0:30.33 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
44389  ??  S      3:08.20 /usr/local/sbin/dnsmasq --local-ttl 1 --all-servers -
44473  ??  D      0:31.46 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
44562  ??  I      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
44594  ??  I      0:00.01 minicron: helper /etc/rc.update_alias_url_data  (mini
44657  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
44676  ??  INs    0:00.02 /usr/sbin/inetd -wW -R 0 -a 127.0.0.1 /var/etc/inetd.
44736  ??  R      0:32.10 (squidGuard) -c /usr/local/etc/squidGuard/squidGuard.
44811  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
44910  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
45068  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
45118  ??  S      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
45263  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
45599  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
45796  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
46069  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
46356  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
46702  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
46944  ??  S      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
47136  ??  S      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
47311  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
47382  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
47469  ??  S      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
47705  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
47919  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
48205  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
48545  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
48681  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
48716  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
48874  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
49163  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
49502  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
49515  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
49847  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
50167  ??  S      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
50227  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
50540  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
50757  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
51098  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
51166  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
51192  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
51209  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
51454  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
51585  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
51676  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
51734  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
51769  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
52037  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
53482  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
53518  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
54795  ??  Ss    17:23.59 /usr/sbin/powerd -b adp -a adp
56210  ??  I      0:00.00 sleep 55
59021  ??  Ss     0:00.09 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
59708  ??  S      0:00.95 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
59959  ??  S      0:00.60 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
59965  ??  S      0:00.82 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
60073  ??  S      0:00.01 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
60360  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
60528  ??  S      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
61680  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
61798  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
61995  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
62170  ??  I      0:00.00 /usr/local/sbin/havp -c /usr/local/etc/havp/havp.conf
16277  v0- S      1:16.15 /usr/sbin/tcpdump -s 256 -v -S -l -n -e -ttt -i pflog
16308  v0- S      1:51.49 logger -t pf -p local0.info
32161  v0- I      0:49.28 /bin/sh /usr/local/pkg/sqpmon.sh
52753  v0- SN     4:51.06 /bin/sh /var/db/rrd/updaterrd.sh
52813  v0  Is+    0:00.01 /usr/libexec/getty Pc ttyv0
53228  v1  Is+    0:00.01 /usr/libexec/getty Pc ttyv1
</code></pre>
<p dir="auto">pfsense is causing me too many issues and headaches.  I think Im gonna find another firewall project or go back to a simple plain Jane router…</p>
]]></description><link>https://forum.netgate.com/post/414109</link><guid isPermaLink="true">https://forum.netgate.com/post/414109</guid><dc:creator><![CDATA[pftdm007]]></dc:creator><pubDate>Thu, 29 Aug 2013 02:43:57 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Tue, 27 Aug 2013 12:33:44 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">To bypass some filtering issues here I set up a second subnet to run my voip ata's on. Its all great if you have the room to install a third NIC into your box. Otherwise its VLANs and a managed switch…  :P</p>
</blockquote>
<p dir="auto">Unfortunately, I do not have a second PCI clot on that machine so adding another NIC is impossible.</p>
<p dir="auto">I also intend to virtualize pfsense at some point on a shiny new dual socket server with LOTS of RAM….  Im not sure how will this work but I know for sure it wont have 3 NIC's (I will be able to install several NICs as the server's mobo will have 6 PCI-E slots but will I need to??)</p>
<p dir="auto">Right now, Snort is down.  Unless I know how to make sure it wont block the ATA again, it will remain down.</p>
<p dir="auto">You see this is what Ive done:</p>
<p dir="auto">Create an alias including all my internal IP's and some outside servers I want to keep free access to,<br />
Under Snort's config, I went to white-list, added a white-list, and then used the alias I had created</p>
<p dir="auto">I really thought this way snort wouldn't interfere with the hosts listed under this alias..</p>
<p dir="auto">Apparently not.<br />
<strong>Anybody knows why?</strong></p>
<p dir="auto">I did not have to try Siproxd yet because the ATA works flawlessly with my port forwarding setup and snort down.  If I can clear snort's interference out of the equation, and I have problems again, I will try Siproxd.  I just prefer not to mix too many variables together until I really knows whats going on.</p>
<p dir="auto">That has been my recipe with pfsense…</p>
]]></description><link>https://forum.netgate.com/post/413707</link><guid isPermaLink="true">https://forum.netgate.com/post/413707</guid><dc:creator><![CDATA[pftdm007]]></dc:creator><pubDate>Tue, 27 Aug 2013 12:33:44 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Sun, 25 Aug 2013 20:36:18 GMT]]></title><description><![CDATA[<p dir="auto">Registration time is in the locked advanced pages so not an option without help from his voip providers tech support.</p>
<p dir="auto">To bypass some filtering issues here I set up a second subnet to run my voip ata's on. Its all great if you have the room to install a third NIC into your box. Otherwise its VLANs and a managed switch…  :P</p>
<p dir="auto">Im not sure if Siproxd will bypass snort or not. I only use it to run multiple ata's to multiple external servers. My provider has a production server and a byod server. Plus they are beta testing a cloud based pbx server which I am playing with.</p>
]]></description><link>https://forum.netgate.com/post/413378</link><guid isPermaLink="true">https://forum.netgate.com/post/413378</guid><dc:creator><![CDATA[chpalmer]]></dc:creator><pubDate>Sun, 25 Aug 2013 20:36:18 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Sun, 25 Aug 2013 17:57:48 GMT]]></title><description><![CDATA[<p dir="auto">Yep, snort WAS the problem.. I think anyways.  I stopped it, cleared the blocked hosts, rebooted the ATA and bingo! got the phone again!</p>
<p dir="auto">I'm not sure of the right way to prevent snort from doing that again…</p>
]]></description><link>https://forum.netgate.com/post/413355</link><guid isPermaLink="true">https://forum.netgate.com/post/413355</guid><dc:creator><![CDATA[pftdm007]]></dc:creator><pubDate>Sun, 25 Aug 2013 17:57:48 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Sun, 25 Aug 2013 17:59:18 GMT]]></title><description><![CDATA[<p dir="auto">Your device should probably have the "NAT" box checked in its settings and also, I had to change my device to time out every 15 seconds instead of 3600.  Same for UDP time-out.  After that, it stayed registered.  If I set my settings same as yours, I'd be offline also.</p>
<p dir="auto">Unless their service will boot you for checking in too often, its better to make those numbers smaller.</p>
<p dir="auto">And snort…  Geeze.  Don't get me started on SNORT.</p>
]]></description><link>https://forum.netgate.com/post/413354</link><guid isPermaLink="true">https://forum.netgate.com/post/413354</guid><dc:creator><![CDATA[kejianshi]]></dc:creator><pubDate>Sun, 25 Aug 2013 17:59:18 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Sun, 25 Aug 2013 17:51:03 GMT]]></title><description><![CDATA[<p dir="auto">As I expected, this was too good to be true…</p>
<p dir="auto">I was talking on the phone and suddenly, everything died.  Now when I pickup the phone I hear "Device not registered".</p>
<p dir="auto">The ATA lost connectivity to the outside.  See screenshot:  Not Registered.</p>
<p dir="auto">Looking in pfsense logs:</p>
<pre><code>Aug 25 13:44:11 	snort[12247]: [122:21:1] (portscan) UDP Filtered Portscan [Classification: Attempted Information Leak] [Priority: 2] {PROTO:255} 206.248.144.132 -&gt; 192.0.227.200
Aug 25 13:44:11 	snort[12247]: [122:21:1] (portscan) UDP Filtered Portscan [Classification: Attempted Information Leak] [Priority: 2] {PROTO:255} 206.248.144.132 -&gt; 192.0.227.200
Aug 25 13:43:55 	snort[35706]: [140:20:1] (spp_sip) Invite replay attack [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} 192.168.0.109:5060 -&gt; 206.248.144.132:5060
Aug 25 13:43:55 	snort[35706]: [140:20:1] (spp_sip) Invite replay attack [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} 192.168.0.109:5060 -&gt; 206.248.144.132:5060
Aug 25 13:43:38 	snort[35706]: [140:20:1] (spp_sip) Invite replay attack [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} 192.168.0.109:5060 -&gt; 206.248.144.132:5060
Aug 25 13:43:38 	snort[35706]: [140:20:1] (spp_sip) Invite replay attack [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} 192.168.0.109:5060 -&gt; 206.248.144.132:5060
</code></pre>
<p dir="auto">Could snort cause issues??  I stopped it and rebooted the ATA.  Will post back ASAP if this helped or not.</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/ISS11.jpg" alt="ISS11.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS11.jpg_thumb" alt="ISS11.jpg_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/413353</link><guid isPermaLink="true">https://forum.netgate.com/post/413353</guid><dc:creator><![CDATA[pftdm007]]></dc:creator><pubDate>Sun, 25 Aug 2013 17:51:03 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Sun, 25 Aug 2013 15:13:42 GMT]]></title><description><![CDATA[<p dir="auto">Other screenshots</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/ISS8.jpg" alt="ISS8.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS8.jpg_thumb" alt="ISS8.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS9.jpg" alt="ISS9.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS9.jpg_thumb" alt="ISS9.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS10.jpg" alt="ISS10.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS10.jpg_thumb" alt="ISS10.jpg_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/413329</link><guid isPermaLink="true">https://forum.netgate.com/post/413329</guid><dc:creator><![CDATA[pftdm007]]></dc:creator><pubDate>Sun, 25 Aug 2013 15:13:42 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Sun, 25 Aug 2013 15:13:09 GMT]]></title><description><![CDATA[<p dir="auto">OK !  Out of nowhere, after I had set my port forwarding and NAT on the pfsense machine, I plugged the ATA in my LAN, it got an IP from pfsense's DHCP server and then after a few minutes, the phone worked..  Not sure why it didnt work the 100 times I tried last week…</p>
<p dir="auto">Anyways,</p>
<p dir="auto">kejianshi, look at my screenshots to see my config.  DO you spot anything dangerous, out of the ordinary or wrong??</p>
<p dir="auto">chpalmer,  my modem is Thomson DCM475.  Apparently, this modem is what they call a plain-Jane modem, no routing functions whatsoever done my the modem.  Its more or less just a device that converts cable signals to Network signals..  Anyways this is what I understand..</p>
<p dir="auto">I do have access to the HT502 settings.  They're in the screenshots as well.</p>
<p dir="auto">THe HT502 is factory set to get an IP thru DHCO on its WAN port (normally from the service supplier if connected BEFORE the router) but since in my case its connected AFTER the router, its getting an IP from pfsense.  It works perfectly.  As for the LAN port on the HT502, Im not using it (if after router) since I dont need to bridge or NAT throu it to "feed" another device.  That'd be required if the HT502 was placed between my modem &amp; router which is not right now.</p>
<p dir="auto">The LAN on pfsense is set to 192.168.0.100 to 110</p>
<p dir="auto">Other than that, please ask I will try to find the info or post additional screnshots.</p>
<p dir="auto">:)</p>
<p dir="auto">NB: I do NOT have access to the HT502's advanced settings page and the FXS Port 1 &amp; 2 since at the moment the ATA is provisioned by the service provider, they block access to these pages...</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/ISS1.jpg" alt="ISS1.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS1.jpg_thumb" alt="ISS1.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS2.jpg" alt="ISS2.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS2.jpg_thumb" alt="ISS2.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS3.jpg" alt="ISS3.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS3.jpg_thumb" alt="ISS3.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS4.jpg" alt="ISS4.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS4.jpg_thumb" alt="ISS4.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS5.jpg_thumb" alt="ISS5.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/ISS5.jpg" alt="ISS5.jpg" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/413328</link><guid isPermaLink="true">https://forum.netgate.com/post/413328</guid><dc:creator><![CDATA[pftdm007]]></dc:creator><pubDate>Sun, 25 Aug 2013 15:13:09 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Sat, 24 Aug 2013 19:49:12 GMT]]></title><description><![CDATA[<p dir="auto">lpallard-</p>
<p dir="auto">What model cable modem do you have?</p>
<p dir="auto">Do you have access to the voip settings on the grandstream?</p>
<p dir="auto">also-  did you change the LAN address from default on either pfsense or the grandstream?</p>
]]></description><link>https://forum.netgate.com/post/413259</link><guid isPermaLink="true">https://forum.netgate.com/post/413259</guid><dc:creator><![CDATA[chpalmer]]></dc:creator><pubDate>Sat, 24 Aug 2013 19:49:12 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Sat, 24 Aug 2013 17:07:32 GMT]]></title><description><![CDATA[<p dir="auto">Well - In my case I have several subnets here in the 10.x.x.0 / 24 range.<br />
So, what I did rather than make a dozen entries in my outbound NAT is to just make one.</p>
<p dir="auto">So, first off you would have to be running Manual outbound NAT.</p>
<p dir="auto">So, firewall &gt; NAT &gt; Outbound</p>
<p dir="auto">click "Manual Outbound NAT rule generation" Then save.</p>
<p dir="auto">(Don't worry - You can always re-click the auto setting later if you like)</p>
<p dir="auto">Now, you should get a bunch of rules that automatically appear.</p>
<p dir="auto">At the very top, I created a rule with interface as WAN and source as 10.50.0.0/16 (to cover all my /24 subnets) with destination port 5060 and static port checked.  That fixed my SIP issues.</p>
<p dir="auto">THE RULE HAS TO BE AT TOP OF LIST OR IT WILL NEVER GET PROCESSED.</p>
<p dir="auto">Mileage varies per user…</p>
]]></description><link>https://forum.netgate.com/post/413243</link><guid isPermaLink="true">https://forum.netgate.com/post/413243</guid><dc:creator><![CDATA[kejianshi]]></dc:creator><pubDate>Sat, 24 Aug 2013 17:07:32 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Sat, 24 Aug 2013 16:40:39 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">Can you try the siproxd package? Im not a big fan of Grandstream product due to various issues  but Im sure the double natting that your doing isn't helping the situation.</p>
</blockquote>
<p dir="auto">Of Course I will try the siproxd package with pleasure!  I will report back on that.  I agree 100% with you, GS products seems to be crappy at best.  Double natting?  Like I said, Im a total idiot when it comes to networking.  I can setyp a basic LAN but other than that, no clue!</p>
<p dir="auto">One thing I observed.  The ATA in bridge mode (supposedly just acting like a switch), if I connect it to the modem and the router is NOT connected to the ata (in other words modem -&gt; ATA -&gt; Nothing) and I wait for the ATA to sync and initialize, it will register on the supplier's network and the phone will work.  If I connect the ATA to the modem and connect the pfsense router to the ATA, and initialize the ATA, the pfsense router will get an IP but the ATA wont register to the service provider.</p>
<p dir="auto">TO me, it looks like the ATA was getting an IP from the supplier but NOT forwarding the IP to the LAN (the router in my case) which I thought should..</p>
<p dir="auto">In NAT mode, the ATA gets an IP from the supplier, and gives an IP to the router no problems..</p>
<blockquote>
<p dir="auto">Grandstream will give you problems being the first in line.</p>
</blockquote>
<p dir="auto">Agreed.  My network has worked FLAWLESSLY for several months.  At the moment I introduced this Grandstream P-O-S (sorry I tend to lose it) before my pfsense box, it was game over immediately.</p>
<blockquote>
<p dir="auto">Where you have been using more NAT rules and stuff, you probably really should use less.  NAT rules only make sense if the server is behind your firewall and its not.</p>
<p dir="auto">I am using manual outbound NAT and I do have a outbound NAT rule that tells anything on port 5060 or 5061 to use STATIC port.</p>
</blockquote>
<p dir="auto">Would you care to guide me thru this??? I know nothing about port forwarding and NAT so I know myself, I will end up screwing stuff up instead of fixing it.</p>
<blockquote>
<p dir="auto">You said you used your phone connected directly to the modem before pfsense and it worked?  Thats really bizarre UNLESS your modem is also a router and your pfsense is double NATed, in which case I'd expect alot of broken functionality.</p>
</blockquote>
<p dir="auto">Well…. AFAIK the modem is only a cable modem but it is factory set.  I will try to get into the modem config and see that is there.  But yes , the ATA directly after the modem, the phone in the ATA, all is fine (phone wise) but the ATA has to be in NAT mode for the internet access to work.</p>
<p dir="auto">Heres a summary to clear things up:</p>
<p dir="auto">Config 1</p>
<p dir="auto">--&gt; Cable modem --&gt; ATA in NAT mode --&gt; pfSense --&gt; LAN</p>
<p dir="auto">Internet works, phone works (ATA registers with supplier), bandwidth is capped to 15Mbps</p>
<p dir="auto">Config 2</p>
<p dir="auto">--&gt; Cable modem --&gt; ATA in BRIDGE mode --&gt; pfSense --&gt; LAN</p>
<p dir="auto">ATA will sync with supplier, phone will work but pfsense wont get a valid public IP.</p>
]]></description><link>https://forum.netgate.com/post/413234</link><guid isPermaLink="true">https://forum.netgate.com/post/413234</guid><dc:creator><![CDATA[pftdm007]]></dc:creator><pubDate>Sat, 24 Aug 2013 16:40:39 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Sat, 24 Aug 2013 00:26:15 GMT]]></title><description><![CDATA[<p dir="auto">The only thing I've ever had to do to get my device to register well with a distant SIP server is make my system recheck registration every few seconds vs 3600 seconds.  I have several SIP devices behind pfsense and all work.  Where you have been using more NAT rules and stuff, you probably really should use less.  NAT rules only make sense if the server is behind your firewall and its not.</p>
<p dir="auto">I am using manual outbound NAT and I do have a outbound NAT rule that tells anything on port 5060 or 5061 to use STATIC port.</p>
<p dir="auto">If you have multiple IPs that can also cause a problem. I've heard that using "sticky connections" fixes that.</p>
<p dir="auto">Now - You said something earlier that made little sense to me.  You said you used your phone connected directly to the modem before pfsense and it worked?  Thats really bizarre UNLESS your modem is also a router and your pfsense is double NATed, in which case I'd expect alot of broken functionality.</p>
]]></description><link>https://forum.netgate.com/post/413170</link><guid isPermaLink="true">https://forum.netgate.com/post/413170</guid><dc:creator><![CDATA[kejianshi]]></dc:creator><pubDate>Sat, 24 Aug 2013 00:26:15 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Sat, 24 Aug 2013 00:03:29 GMT]]></title><description><![CDATA[<p dir="auto">Its important to note that differnent voip companies do things different. The standard that should be was scared off by the big lawsuit that Vonage lost.</p>
<p dir="auto">Can you try the siproxd package? Im not a big fan of Grandstream product due to various issues  but Im sure the double natting that your doing isn't helping the situation.</p>
<p dir="auto">My only Grandsteam product is actually behind a pfsense install sharing a network with a Vonage device (linksys) and doing quite well without siproxd. At my home however I have 4 numbers across 2 Linksys devices with the same company as the Grandstream that need Siproxd to work.</p>
<p dir="auto">Grandstream will give you problems being the first in line.</p>
]]></description><link>https://forum.netgate.com/post/413169</link><guid isPermaLink="true">https://forum.netgate.com/post/413169</guid><dc:creator><![CDATA[chpalmer]]></dc:creator><pubDate>Sat, 24 Aug 2013 00:03:29 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Fri, 23 Aug 2013 21:22:29 GMT]]></title><description><![CDATA[<p dir="auto">Another reply….</p>
<p dir="auto">I am trying to set a DMZ for the ATA.  All tutorials or documentation I find, you need 3 network cards in the machine running PFS.  DO I really need 3 NIC's???</p>
<p dir="auto">Thats pathetic.  My $35 old linksys router could do DMZ in a second.</p>
<p dir="auto">Other than DMZ, how could I make this thing work?</p>
]]></description><link>https://forum.netgate.com/post/413162</link><guid isPermaLink="true">https://forum.netgate.com/post/413162</guid><dc:creator><![CDATA[pftdm007]]></dc:creator><pubDate>Fri, 23 Aug 2013 21:22:29 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Fri, 23 Aug 2013 01:28:13 GMT]]></title><description><![CDATA[<p dir="auto">Additionally, I tried once again to setup the ATA on the LAN side and setup port forwarding on pfsense</p>
<p dir="auto">using http://forum.pfsense.org/index.php?topic=55676.0</p>
<p dir="auto">No go.  The ATA doesnt register at all..</p>
<p dir="auto">In both configuration, pfsense is the root cause of the issues..</p>
<p dir="auto">What kind of configuration do pfsense needs for a simple voip device to work?</p>
]]></description><link>https://forum.netgate.com/post/413017</link><guid isPermaLink="true">https://forum.netgate.com/post/413017</guid><dc:creator><![CDATA[pftdm007]]></dc:creator><pubDate>Fri, 23 Aug 2013 01:28:13 GMT</pubDate></item><item><title><![CDATA[Reply to GrandStream HT502 BEHIND router on Fri, 23 Aug 2013 01:38:58 GMT]]></title><description><![CDATA[<p dir="auto">Turns out, I think pfsense is the issue.  I did a thorough troubleshooting along with the service provider and step by step I've isolated the bottleneck.</p>
<p dir="auto">Important to mention, between each speed tests, I have unplugged EVERYTHING (modem, ATA, pfsense box, computer) so no residual data (subnet, IP, etc..) from a previous test would stay and cause troubles or screw up the test.</p>
<p dir="auto">Here's the results of the speedtests for each network config: <strong>(All in Mbps)</strong></p>
<p dir="auto"><strong>This is a 30Mbps/10Mbps connection</strong></p>
<p dir="auto"><strong>Test 1: Cable modem -&gt; Computer</strong></p>
<p dir="auto">1.  U 23.18 / D 9.44<br />
2.  U 22.77 / D 9.46<br />
3.  U 22.16 / D 9.51<br />
4.  U 24.44 / D 9.53</p>
<p dir="auto"><strong>Test 2: Cable modem -&gt; ATA device -&gt; Computer</strong></p>
<p dir="auto">1.  U 22.82 / D 10.34<br />
2.  U 20.87 / D 10.30<br />
3.  U 22.87 / D 10.34<br />
4.  U 22.60 / D 10.18</p>
<p dir="auto"><strong>Test 3: Cable modem -&gt; ATA device -&gt; pfSense box -&gt; Computer</strong></p>
<p dir="auto">1.  U 16.70 / D 10.06<br />
2.  U 15.85 / D 1.30<br />
3.  U 16.93 / D 10.22<br />
4.  U 17.98 / D 10.25</p>
<p dir="auto"><strong>Test 4: Cable modem -&gt; pfSense box -&gt; Computer</strong></p>
<p dir="auto">1.  U 30.16 / D 10.22<br />
2.  U 15.57 / D 1.47<br />
3.  U 31.62 / D 9.94<br />
4.  U 30.03 / D 10.20</p>
<p dir="auto">My thoughts:</p>
<ul>
<li>
<p dir="auto">Results from test 1 and 2 clearly show that the ATA device does not cause bottleneck issues as I previously thought.  The difference between the average speed of approx. 22Mbps versus my nominal speed of 30Mbps IMO are related to cable congestion or other ISP issues (I am close to a large city).</p>
<p dir="auto">Result from test 4 also shows that the pfsense box directly connected to the cable modem is not causing bandwidth issues.</p>
</li>
</ul>
<p dir="auto">SO I conclude that for whatever reason that I would like to determine, pfsense has a hard time playing with the ATA device. The only configuration that caused severe bandwidth throttle was the config where pfsense was after the ATA device.</p>
<p dir="auto">I hope this will be useful to someone to help me pin point the cause..</p>
<p dir="auto">EDIT:  Speedtest done using a python CLI utility available at https://github.com/sivel/speedtest-cli<br />
Thanks for the original devs for this useful tool!</p>
]]></description><link>https://forum.netgate.com/post/413013</link><guid isPermaLink="true">https://forum.netgate.com/post/413013</guid><dc:creator><![CDATA[pftdm007]]></dc:creator><pubDate>Fri, 23 Aug 2013 01:38:58 GMT</pubDate></item></channel></rss>