We are using sonicwall NSA 2400, it always keep said my External port != internal port,
How to check my port is be symmetric? isit any log will show?



Tony Graziano wrote:


On Wed, Feb 3, 2010 at 3:18 PM, Winson (Elabram) <winson.k...@elabram.com> wrote:
Dear all Expert !
Hi i stuck in the firewall NAT mapping for my Sipbridge - ISTP .

I try direct use the modem connected to sipXecs and open the port 5060,5080, 30000-31000,16384-16482(ISTP) is wan work.

after i plug in the firewall, the softphone show me is error 408,time out.
Then i check the sipbridge.log it show me:


Remote Host:202.85.243.87---- Port: 5060----\nREGISTER sip:sip.pennytel.com SIP/2.0\r\nCall-ID:......
Remote Host:202.85.243.87---- Port: 5060----\nSIP/2.0 401 Unauthorized\r\nCall-ID: ........
Remote Host:202.85.243.87---- Port: 5060----\nREGISTER sip:sip.pennytel.com SIP/2.0\r\nCall-ID:.........
Remote Host:202.85.243.87---- Port: 5060----\nSIP/2.0 200 OK\r\nCall-ID:........
.... WARNING External port != internal port your NAT may not be symmetric.


It is because i did'n set the NAT policy from my firewall (sonicwall) will become this problem?

What firewall are you using? It does not appear you are using a symmetrical port NAT method.

What is this? In order to connect the media stream (default 30000-31000 udp), the firewall "must" be symmetrical, if it leaves (rtp/media) on port 30123 then it must come back on port 30123, for instance.


_______________________________________________
sipx-users mailing list sipx-users@list.sipfoundry.org
List Archive: http://list.sipfoundry.org/archive/sipx-users
Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-users
sipXecs IP PBX -- http://www.sipfoundry.org/

Reply via email to