SIP Traffic Without Firewall Rules using Flowroute

Status
Not open for further replies.

techguy1

SOHO User
Joined
Nov 22, 2020
Messages
4
Reaction score
0
So I'm hoping someone can help me make some sense of what is going on in my situation. This might be an unusual request, since my setup is currently working, but I don't understand how it is working, and I am wondering the best way to have this configured. Also I thought this post might be helpful for someone who is having one-way audio issues.

I have on-prem Windows 3CX 16.0.6.614 and am running a Fortinet Fortigate Firewall. I'm in the process of switching to Flowroute for SIP from Spectrum VOIP delivered via analog. I'll try to outline my initial configuration, what didn't work, what I changed to get it to work, and why I'm now confused.

Initial Configuration:
  • Site has a single IP address (dynamic)
  • Flowroute setup to use "SIP Registration" for inbound rule. Also using IP address authentication.
  • Fortigate SIP ALG and helpers, etc - all disabled
  • Fortigate Virtual IP setup to 3CX server for both SIP and RTP ports (5060, 9000-10999) (port forwarding)
  • Fortigate Inbound Rules
    • Allow UDP/TCP 5060 from Flowroute IPs to 3CX Server with SIP service
    • Allow UDP 9000-10999 from any to 3CX Server with RTP service
    • Settings use NAT, set to preserve source port
  • 3CX Flowroute Trunk settings options
    • public IP address listed in the 2 spots to publish public IP
    • Support Re-Invite
    • PBX Delivers Audio
    • Codec G711ulaw
  • 3CX Network Settings - Firewall
    • "Send Media to IP and port of REGISTER" was already checked - I think this is default
  • 3CX Firewall Checker passes with flying colors related to SIP (temporarily changed inbound rule from flowroute only IPs source to any, just for the test)
^ The above results in one-way audio. The party from the outside is unable to hear the party on the 3CX side of things. I thought maybe something on the outbound wasn't right, so I wrote a lan->wan rule for RTP ports to NAT, preserving source port, but that didn't do anything.

I found a forum somewhere, now I forget where, that someone said NAT was causing one-way audio. There weren't any specifics on it, but I thought I would play around with the firewall rules. I ended up turning NAT off on the Fortigate rule for RTP, and it worked fine after that. Only unchecking the box to preserve source port but leaving NAT on does not work.

According to my firewall logs, it was hitting the correct rules. Now where things get interesting, is I disabled the RTP inbound rule entirely, and it still worked after that. I was seeing traffic getting categorized as application RTP using the main outbound firewall rules, where previously it was hitting the service I created RTP as well as the created rule.

Then I tried disabling the SIP signalling inbound rule, and it still worked fine after that. I see traffic getting thrown into application SIP.VIA.NAT on one of the main outbound rules. I then took it a step further and unchecked that box in network settings to send media to IP and port of Register, and the SIP traffic still works... So basically I have no inbound rules configured at all now, but flowroute registration is valid, and everything seems to work fine. And Firewall Checker fails miserably

So my question is.. how on earth is this working? Is it because I have an outbound connection with Flowroute established? and it's all smart enough to route everything appropriately through Flowroute? I'm wondering if I'm best off turning back on the firewall rules, but leave the NAT portion off since that's what I had to do to get it to work.

Does anyone have any thoughts? Appreciate the insight.
 
Status
Not open for further replies.

Forum statistics

Threads
111,972
Messages
590,065
Members
164,886
Latest member
784