Firewall-1

[FW-1] SIP through Firewall

Subject: [FW-1] SIP through Firewall
From: Richard Turner <rturner AT BTINTERNET DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Wed, 30 Nov 2005 16:39:32 +0000
Hi,

Wondered if anyone out there can help me with SIP?

Using R55 on windows.

I have a SIP server (asterisk) internally. I wanted to
have staff at home using their SecureClients in Office
mode able to connect to the asterisk server to make
calls etc. When ever the software clients connect to
the server to register I get SIP errors on the
firewall 

I've tried a number of combinations - with and without
Office mode, with and with out encryption and I get
errors like :
sip reason: Illegal redirection
xxx.xx.13.41->192.168.1.2

or 
sip reason: Attack Info - Malformed SIP datagram,
OPTION message is out of state
or 

message_info: Connection contains real IP of NATed
address


I have tried an number of rules but mainly along the
line of

Any VoipDomain SIP_any client_encrypt

where VoipDomain contains my internal network and the
asterisk server. 

Should I abandon this and go for unencrypted traffic? 
If I give the asterisk server a static nat address, it
it enough to use the VOIPDomain object as the
destination object? 

Any help would be appreciated

Richard

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>
  • [FW-1] SIP through Firewall, Richard Turner <=