SIP ALG Disabled but still getting errors

Status
Not open for further replies.

Victor Camacho

Bronze Partner
Basic Certified
Joined
Jan 7, 2019
Messages
21
Reaction score
8
Hi,
New to the 3CX community switching from other PBX but grey beard at computer systems.

I am having issues with passing the SAP ALG test and not sure why or how to find the exact issue.
My original firewall in front of the 3CX system is OpenBSD PF, everything passes but SIP ALG.
Next tried PFSense following the information on set up from 3CX. Everything passes but SIP ALG.
According to PFSense and OpenBSD, there is not any SIP ALG by default in these systems.

Next I tried a Ubiquiti Edge Router, which has a switch to turn SIP ALG on or off.
Turned it off and everything passes but SIP ALG.

Next I tried a Cisco RV042G Router, which also has a SIP ALG button in a hidden menu.
Updated firmware.
SIP ALG was off. Everything passes except SIP ALG.

Any help or clue sticks would be appreciated in finding out why the firewalls are not passing this test.
Also any recommendations on routers.
OpenBSD/PF is my choice of firewall but willing to try something else until I can figure out the issues.

Thanks,
Victor
 
Hi Victor,

I am not familiar with your router brand but also ensure that you don't have a hidden CLI based SIP ALG or SIP helper setting - these can only be turned off by command line.
 
Since you've tried 3 routers/firewalls with the same results it would seem it's something upstream. For example the Netgear modems that Comcast provides have SIP ALG enabled on them.
 
Hi Guys,
Thanks for the quick replies.
Leejor: I will do trace and see what I find.
eddv123: That is what I worry about, but the PF people are open source and very clear about their system. That would be OpenBSD and PFSense. The Ubiquity and Cisco routers had switches.
cobaltit: My firewall connects to an AT&T router that comes with our fiber connection. I will try some searches regarding this, good thought.
I will post any information I find.
Thanks!
 
@Victor Camacho

My money is on the AT&T equipment. Is it a Motorola NV type router (ABF circuit) or Cisco/Edgewater device (enterprise fiber circuit). If you are getting your SIP trunk from AT&T as well then the it will work without passing the firewall test as will remote soft phones or remote phones using the SBC. If you want remote phones via STUN (direct SIP) then you'll need to reach out to the MACD department (7-10 days) to request removal of the ACL. AT&T blocks remote SIP by default to prevent toll fraud.
 
  • Like
Reactions: Victor Camacho
Cobaltit: It is an AT&T device model 4808, which looks like an EdgeWater Edgemarc 4808.
Is there any way to prove this or should I just request the removal?
Thanks !!!
 
Hey guys any idea on a work around?
What comes to mind is to spin up servers in the cloud and then VPN back to the office?
Would the VPN hide the traffic and would it be ok for speed?
Max calls for now would be 4 to 8.
 
Cobalit: Follow up on your information:
Currently trying to set up a 3CX server on premise.
We actually do have a remote worker on our Avaya phone system. But the connection for the Avaya phone system come out of a T1 port on the 4808. I an trying to connect the 3CX phone system on the LAN port side.
Just in case any of this information matters.
 
Ok so this is a relatively new AT&T BiB install if you have the Edgewater. If you want to use direct SIP (STUN) for a remote phone you will need to request the ACL removal. But if you plan on using AT&T for the dial tone via the PRI hand-off then for your one remote user you can do the following:

- VPN from the remote user to the office
- Put a SBC like a Raspberry Pi at the remote user site and connect the phone via tunnel.

Either method would bypass the block on inbound 5060. You can put the PBX in the cloud and then VPN back for the phones. For the dial tone it's not a supported setup but it can work that way as well.
 
Cobaltit: Thanks for the reply. Sorry for any confusion about the remote phone. The current remote phone is on the Avaya system and not part of the current situation. That is all through AT&T and is working.
I am adding a new 3CX on premise server for a different group in the building. This server is connecting to VOIP provider Vitelity through the LAN interface of the Edgemarc.
Are you saying that if I setup a 3CX in the cloud and try to connect the phones in the office through a VPN, that this is not a supported configuration?
Any ideas on how to connect phones in the office to the cloud?
Again, thank you for all your assistance.
 
Ahh ok. So if you are using Vitelity for dial tone and no AT&T then yes I would put 3CX in the cloud (Lightsail works great) and then put a SBC in the office for the local phones. No need to mess with the firewall at all as the SBC initiates the outbound connection to the 3CX instance.
 
  • Like
Reactions: Victor Camacho
Cobaltit: Thanks, any suggestions for an Session Border Controller?
 
Raspberry Pi works for up to 20 phones (depending on the number of BLFs). A small PC or VM can do up to 50 (again depending on the number of BLF keys). You can also do multiple SBCs if you need more than that or want to spread the load
 
  • Like
Reactions: YiannisH_3CX
Sorry, but what SBC software to run on the PC?
 
Ohhh, maybe the 3CX SBC. Thought I had seen something about it. I found it.
Thanks !!!
 
  • Like
Reactions: YiannisH_3CX
Status
Not open for further replies.

Forum statistics

Threads
111,908
Messages
589,684
Members
164,773
Latest member
ccocala.org