• We do not provide troubleshooting help for unsupported phones. Please try with a supported phone.
  • V20 Update 10 Alpha 2 Learn more

STUN behind Fortigate OS 7.2.0

Status
Not open for further replies.

jrodcpwk

Bronze Partner
Basic Certified
Joined
Dec 2, 2019
Messages
41
Reaction score
4
Good day,

Currently running into an issue with a client who recently got their Fortigate firewall upgraded to 7.2.0 on the firmware. Because of this now their STUN Yealink T58 starts populating several times in the PBX and the user reports not being able to make calls or show indication that its on a call. Also all the prompts for the BLFs are stating everyone is offline. I checked the SIP ALG config adjustments along with deleting the session helper, created the inbound port forwards for RTP and SIP (SIP 5065 and RTP 14000-14019) but the phone still keeps having issues connecting. PBX Audio and allowed for WAN outside are in order. Thing is the device worked fine but until this firmware upgrade. Not sure if anyone else has handled the firmware here in specific or maybe im missing any other features to adjust?
 
It could be something is stuck in the session table, but definitely sounds like a firewall issue. If you are confident about the port forwards being ok, have you tried rebooting the firewall at least once?

This might be of some help: https://www.3cx.com/docs/fortigate-firewall-configuration/
 
Hi John,

Yes, rebooted a few times just to make sure after each adjustment. Just odd, still trying to dig through the fortigate 7.2.0 documentation to see if there are any other things involved. May call and get support from them to see if anything can be done with a tech their side.
 
If you can install an SBC there you can avoid this problem entirely.

If not you might have to capture traffic from the phone, and the the Fotigate WAN port, and compare what the phone sent out and from which port, VS what the firewall sent out and from which port.

In case the firewall is not modifying any traffic or rewriting the ports (confirm via captures 1st!), you might have to look further up the line at your ISP modem. They may be messing with the traffic after it leaves the Fortigate.
 
Status
Not open for further replies.

Forum statistics

Threads
112,148
Messages
590,963
Members
165,169
Latest member
Isaac415