- Joined
- Jul 10, 2019
- Messages
- 19
- Reaction score
- 3
Hello, We have a thorn in our side reoccurring issue which the ISP claims no problems but the problem persists. Looking for some direction.
3cx v18 pro in Azure, ~250 registered extensions across ~20 SBCs, mostly Fanvil X5S. Most routers are Fortigate 60D at a minimum, the problem site has a 140D POE, anything as it ages has been replaced with E or F generation fortigates. Standard SIP ALG disabled on fortigate and ISP gateway. The 140D has been stepped to 6.2.12 so I can start using some of the 6.2 packet capture features that didnt exist prior to 6.2
What is happening is this site gets sporadic 1-way audio during a call. Call setup looks good and looking at captures when these problems start occurring (when the phone is configured to go through the SBC) I see that I start getting TCP re-transmits on the encrypted tunnel between the SBC and the 3CX server. Pings never drop, web browsing is fine, there is never any issue other than seeing that these sessions come and go as they please.
I dont have any captures for what the remote side looks like when the phone is configured Direct SIP to the 3cx server bypassing the SBC but the problem is identical. 80% of the call is fine then we get all kinds of 1 way drops lasting between 1 and 30 seconds, sometimes 2 way, etc... I havent gotten any additional captures after stepping the router up from 6.0.x for direct sip calls but I plan on doing that today now that I can do some policy based packet captures. (no fortianlyzer or related so I am limited to 10000 packets per capture)
I am about ready to build my policies so I can do some more testing, does anybody have any input on this one? ISP already rescripted the gateway, disabled everything they could disable on it and assured everything is good but I havent been able to packet capture WAN side of this 140D so I cant confirm or deny the router is causing the issue or if it is outside the network.
My next step if this fails is to put a PC out there and a switch between the fortigate and ISP equip so I can port mirror in order to give me some definitive answers.
An alternate next step is for me to have this phone direct SIP to a different site's SBC as troubleshooting. Crazy but I am wondering if results may be different.
If anybody has any insight or if I am missing something fundamental I am all-ears.
3cx v18 pro in Azure, ~250 registered extensions across ~20 SBCs, mostly Fanvil X5S. Most routers are Fortigate 60D at a minimum, the problem site has a 140D POE, anything as it ages has been replaced with E or F generation fortigates. Standard SIP ALG disabled on fortigate and ISP gateway. The 140D has been stepped to 6.2.12 so I can start using some of the 6.2 packet capture features that didnt exist prior to 6.2
What is happening is this site gets sporadic 1-way audio during a call. Call setup looks good and looking at captures when these problems start occurring (when the phone is configured to go through the SBC) I see that I start getting TCP re-transmits on the encrypted tunnel between the SBC and the 3CX server. Pings never drop, web browsing is fine, there is never any issue other than seeing that these sessions come and go as they please.
I dont have any captures for what the remote side looks like when the phone is configured Direct SIP to the 3cx server bypassing the SBC but the problem is identical. 80% of the call is fine then we get all kinds of 1 way drops lasting between 1 and 30 seconds, sometimes 2 way, etc... I havent gotten any additional captures after stepping the router up from 6.0.x for direct sip calls but I plan on doing that today now that I can do some policy based packet captures. (no fortianlyzer or related so I am limited to 10000 packets per capture)
I am about ready to build my policies so I can do some more testing, does anybody have any input on this one? ISP already rescripted the gateway, disabled everything they could disable on it and assured everything is good but I havent been able to packet capture WAN side of this 140D so I cant confirm or deny the router is causing the issue or if it is outside the network.
My next step if this fails is to put a PC out there and a switch between the fortigate and ISP equip so I can port mirror in order to give me some definitive answers.
An alternate next step is for me to have this phone direct SIP to a different site's SBC as troubleshooting. Crazy but I am wondering if results may be different.
If anybody has any insight or if I am missing something fundamental I am all-ears.