<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[1:1 NAT issues with asterisk box and phones.]]></title><description><![CDATA[<p dir="auto">Ok here is a brief rundown of my setup.</p>
<p dir="auto">Cable connection with 5 available IPs xxx.xxx.xxx.114 - xxx.xxx.xxx.118</p>
<p dir="auto">Only going to use two of the 5 at the moment<br />
xxx.xxx.xxx.114 for the WAN and xxx.xxx.xxx.117 for the Asterisk server.</p>
<p dir="auto">I have setup pfSense 1.2-RELEASE built on Sun Feb 24 17:13:15 EST 2008 updated from 1.01 with 2 nics enabled, simple WAN and LAN.  I have an OPT1 on the MB, but am not using it at the moment, it is disabled.</p>
<p dir="auto">WAN (xxx.xxx.xxx.114)<br />
LAN DHCP 192.168.13.0/24 range 192.168.13.120 - 200<br />
VIP Asterisk (xxx.xxx.xxx.117) internal IP 192.168.13.117</p>
<p dir="auto">Cable &gt; pfSense &gt; switch &gt; Asterisk and DHCP</p>
<p dir="auto">This sounds doable so far, right?</p>
<p dir="auto">I have the NAT reflection working (unchecked) and I can connect to the pfSense admin pages, but the phones still don't work.</p>
<p dir="auto">I have opened ports 5060 for setup and the port range 10000 - 10500 for the voice.</p>
<p dir="auto">I have read about making the port range for Static, but when I try to do this it changes the IP I assign it dropping it one number in the last octet.</p>
<p dir="auto">firewall:nat:outbound, checked the AON and entered:</p>
<p dir="auto">WAN * * 192.168.13.117/31 * * * YES</p>
<p dir="auto">It goes from 192.168.13.177 (Asterisk VIP) to 192.168.13.116 (unused static IP, no VIP assigned) as the Destination???  Strange behavior.</p>
<p dir="auto">Anyone have any ideas, I have read soo many different threads and tried them all, but nothing.</p>
<p dir="auto">I think I might scrub it and start fresh following a couple of the <strong>SOLVED</strong> threads I have read.</p>
]]></description><link>https://forum.netgate.com/topic/8707/1-1-nat-issues-with-asterisk-box-and-phones</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Jul 2026 08:30:08 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/8707.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 02 May 2008 18:33:59 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to 1:1 NAT issues with asterisk box and phones. on Sat, 03 May 2008 18:37:42 GMT]]></title><description><![CDATA[<p dir="auto">Have you made the adjustments to your sip.conf file that are detailed in the following link?<br />
http://forum.pfsense.org/index.php/topic,8682.msg50287.html#msg50287</p>
<p dir="auto">These changes help tell asterisk what its local network address is so that it is less likely to give the wrong internal address in the SIP packets.</p>
]]></description><link>https://forum.netgate.com/post/172879</link><guid isPermaLink="true">https://forum.netgate.com/post/172879</guid><dc:creator><![CDATA[cybrsrfr]]></dc:creator><pubDate>Sat, 03 May 2008 18:37:42 GMT</pubDate></item><item><title><![CDATA[Reply to 1:1 NAT issues with asterisk box and phones. on Sat, 03 May 2008 00:16:10 GMT]]></title><description><![CDATA[<p dir="auto">Thank you for your response hoba.</p>
<p dir="auto">I have seen others post that they have resolved these annoying issues without resorting to a STUN server or proxy… at least that is what I made of it when I read all the threads.</p>
<p dir="auto">With or without the AON it still does not work.  I am using AON because that is what I have found as solutions when I did a search of the forums.</p>
<p dir="auto">The only notable difference prior to trying pfSense is that they were on different subnets.  We put them on the same subnet this time.</p>
<p dir="auto">PfSense offers traffic shaping, something the prior FW did not have, it has become a priority and an annoyance all at once.</p>
<p dir="auto">I am getting this response from the show states.</p>
<p dir="auto">Proto    Source -&gt; Router -&gt; Destination    State   <br />
udp 192.168.13.200:5060 -&gt; xxx.xxx.xxx.117:5060 SINGLE:NO_TRAFFIC<br />
udp xxx.xxx.xxx.117:5060 &lt;- 192.168.13.200:5060 NO_TRAFFIC:SINGLE</p>
<p dir="auto">That does not look good. :(</p>
]]></description><link>https://forum.netgate.com/post/172850</link><guid isPermaLink="true">https://forum.netgate.com/post/172850</guid><dc:creator><![CDATA[Munkee]]></dc:creator><pubDate>Sat, 03 May 2008 00:16:10 GMT</pubDate></item><item><title><![CDATA[Reply to 1:1 NAT issues with asterisk box and phones. on Fri, 02 May 2008 22:11:13 GMT]]></title><description><![CDATA[<p dir="auto">1:1 nat always uses static ports so you don't need that additional advanced outbound nat. Are the phones at WAN? You might need to use a stun server or a proxy. Inside the SIP protocols the clients (asterisk and ipphones) send their IP and ports to each other when registering. As the systems only see there local IP and don't know about their public IP this might cause several issues. Using an external STUN server or a proxa that rewrites these IPs on the fly might solve the problem.</p>
]]></description><link>https://forum.netgate.com/post/172840</link><guid isPermaLink="true">https://forum.netgate.com/post/172840</guid><dc:creator><![CDATA[hoba]]></dc:creator><pubDate>Fri, 02 May 2008 22:11:13 GMT</pubDate></item></channel></rss>