| To: | nn@qorbit.net |
|---|---|
| Subject: | Re: [nn] NAT -> SIP Issues |
| From: | "Pavel Lunin" <plunin@gmail.com> |
| Date: | Thu, 1 Feb 2007 02:59:25 +0300 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | ns-list2@consult.net |
| Delivered-to: | nn@qorbit.net |
| Domainkey-signature: | a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:references; b=N8KvSoH1/lNhf2IkYN29xjDxwYo+6cWKjWQbuiPqpOhJrDajqnzs3W4KSnaM3kdHw5yFFZsBUgRTAKg9b5WSQXbAk5sZNPL3uxsWnDere4sofGm8ucCwwn+PMkkkIQwnUMub+PMv5ybs5R5InCIK6yZOprdOngKgKNUn9TCdhSs= |
| In-reply-to: | <45C11365.8030407@klasa.se> |
| List-archive: | <http://www.qorbit.net/nn> |
| List-help: | <mailto:nn-request@qorbit.net?subject=help> |
| List-id: | "Netscreen mailing list for netscreen admins." <nn.qorbit.net> |
| List-post: | <mailto:nn@qorbit.net> |
| List-subscribe: | <http://qorbit.net/mailman/listinfo/nn>, <mailto:nn-request@qorbit.net?subject=subscribe> |
| List-unsubscribe: | <http://qorbit.net/mailman/listinfo/nn>, <mailto:nn-request@qorbit.net?subject=unsubscribe> |
| References: | <20070131211034.GA38151@infiltrated.net> <45C11365.8030407@klasa.se> |
| Sender: | nn-bounces@qorbit.net |
|
Not only yours, John :) Actually SIP alg is only needed in a case of stupid client, which itself can't work around NAT. Todays clients almost all can do it. Trying together to cheat each other SIP alg and a client disturb the normal way of working. So usually it's normal to say unset sip alg Keep in mind, that ScreenOS 5.1 (or maybe even 5.2) and older don't give a tip for 'set sip ?' for some reason. So don't be afraid, just say 'unset alg sip' :) To get SIP-telephony working properly, you usually need to configure policies for RTP. If two sides of calls may be situated by the different sides of NetSreen. RTP uses UDP protocol, but it's quite crazy with port numbers. First, ports depend on your SIP client. Second, saying 'a port' for RTP you mean source port, not destination. So for example if you use X-lite, you sould say something like set service "RTP_XLITE" protocol udp src-port 8000-8001 dst-port 1-65535 and than use RTP_XLITE in a policy: set pol from trust to untrust sip-clients sip-pbx RTP_XLITE permit I hope that's it. -- Regards, Pavel 2007/2/1, John Klasa <john@klasa.se>:
-----BEGIN PGP SIGNED MESSAGE----- _______________________________________________ nn mailing list nn@qorbit.net http://qorbit.net/mailman/listinfo/nn |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [nn] NAT -> SIP Issues, J. Oquendo |
|---|---|
| Previous by Thread: | Re: [nn] NAT -> SIP Issues, John Klasa |
| Indexes: | [Date] [Thread] [Top] [All Lists] |