If it matters, your gateway is handling nat traversal via the ITSP very
differently than a siptrunk. It's a gateway and not a siptrunk using
sipxbridge. Endian only handles SNAT, source/softwires, but not symmetric
NAT which is a requirement for sipxbridge. Your gateway (which is probably
an FXS ATA) from acanac could also employ a stun server or other methods to
traverse to their network so audio will work. There is probably nothing from
you getting its local IP address and setting it up as a gateway in sipx and
sending all calls to the AA or an extension. If so, that's nifty.

For example, I have a voipo account for home use, it uses a linksys spa, I
only needed to forward a couple of ports from my endian firewall at home in
order for it to get out, register, and be usable. I can also connect a
softphone to a test sipx server at my office but it would NEVER connect no
matter what I did (and have 2 way audio for either direction on received or
placed calls), until I put up a pfsense firewall and configured it properly.
Your gateway (which is probably an FXS ATA) from acanac could also employ a
stun server or other methods to traverse to their network so audio will
work.

If you are trying to connect to an ITSP with a siptrunk via sipxbridge, and
your server is behind nat (or some of your remote users), you should employ
a firewall capable of symmetric nat where sipx is located. I have a lot of
customers using endian, but not with sipxbridge, because endian
DOES_NOT_DO_THAT <period>.

So if the question is "I want to employ sipxbridge at home with my ITSP to
connect to a siptrunk provider and I use an Endian firewall, how do I do
that?", the answer is "use a firewall capable of doing symmetric NAT, I
don;t think endian is capable of doing so." If you dispute the capabilities
of Endian, I suggest you post a question to a guru on their list of how to
configure symmetric NAT. There might be a way to manually change this via VI
but not from the user web interface. It is not on the list of features for
the Open Source of the paid commercial version. If you get a way to make
symmetric nat working on endian somehow, posting this would be a good idea.

The sipxproxy (sipxroxd) is only used to connect many users inside your lan
to a single external sip server, not for a b2bua like sipxbridge or for
remote users connecting from the outside to sipxecs inside behind an endian
firewall.

Maybe a wiki page explaining firewalls used, with tips and tricks is needed
here in regard to this type of question (what is generally known to work).

Tony

On Thu, Oct 29, 2009 at 8:05 AM, Black, Dave <[email protected]> wrote:

>  Yup.. I use Endian EFW (Community), in my case, also installed under
> VMware.    Have been using 2.2 since May and just upgraded to 2.3
> yesterday.   Works great.   I use OpenVPN to connect remote phones so the
> firewall doesn’t really play a role for that.  I don’t do too much with
> SipxBridge, but do have a  gateway configured to connect to Acanac, a small
> ITSP out of Mississauga.  I use them primarily for testing configurations.
>
>
>
> By default, Endian will have the outbound firewall enabled.  Don’t enable
> the SIP proxy in Endian.  All I need to do with Endian to connect to Acanac
> was to open up the outbound firewall (all ports, TCP/UDP) to the IP
> addresses Acanac provided me.  When Sipx registers with Acanac,  Endian
> automatically uses the allow established rules and creates the necessary NAT
> translations as ports are requested…  That was it for me..
>
>
>
> Dave B.
>
>
>
>
>
>
>
>
>
>
>
> *From:* [email protected] [mailto:
> [email protected]] *On Behalf Of *Tony Graziano
> *Sent:* October 29, 2009 6:09 AM
> *To:* Picher, Michael
> *Cc:* sipx-users
> *Subject:* Re: [sipx-users] sipxecs behind endian firewall
>
>
>
> Just to save you some trouble, Endian does not do symmetric nat at all.
>
>
>
> *Symmetric NAT*
>
> §  Each request from the same internal IP address and port to a specific
> destination IP address and port is mapped to a unique external source IP
> address and port.
>
> §  If the same internal host sends a packet even with the same source
> address and port but to a different destination, a different mapping is
> used.
>
> §  Only an external host that receives a packet from an internal host can
> send a packet back.
>
>
>
> It can do SNAT, nut this is not souce based NAT, it is softwires nat, which
> is used for encapsulation. Replacing it would be your best option. It it
> matter, pfsense has a vmware loadable image you can use, and is very easy on
> system resources.
>
>
>
>
>
>
>
> On Thu, Oct 29, 2009 at 4:08 AM, Picher, Michael <[email protected]>
> wrote:
>
> I have not tested that firewall personally.
>
> As a general rule however, you would want to make sure and disable the
> sip proxy in endian.
>
> Mike
>
>
> -----Original Message-----
> From: [email protected]
>
> [mailto:[email protected]] On Behalf Of Francis
> Tinio
> Sent: Thursday, October 29, 2009 3:00 AM
> To: sipx-users
> Subject: [sipx-users] sipxecs behind endian firewall
>
> Hi.
>
> >From a previous topic I wa having, it seems that endian might be a
> cuplrit with sipx working behind an endian firewall.  unfortunately for
> me, I'm in no position to replce the firewall right now as it will be
> more work to change.
>
> has anyone been able to get sipx to work behind endian firewall?  any
> pointers?  did you enable sip proxy in endian fw?
>
> thanks in advance.
>
> francis
> _______________________________________________
> sipx-users mailing list [email protected]
> List Archive: http://list.sipfoundry.org/archive/sipx-users
> Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-users
> sipXecs IP PBX -- http://www.sipfoundry.org/
> _______________________________________________
> sipx-users mailing list [email protected]
> List Archive: http://list.sipfoundry.org/archive/sipx-users
> Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-users
> sipXecs IP PBX -- http://www.sipfoundry.org/
>
>
>
>
> -
>
> _______________________________________________
> sipx-users mailing list [email protected]
> List Archive: http://list.sipfoundry.org/archive/sipx-users
> Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-users
> sipXecs IP PBX -- http://www.sipfoundry.org/
_______________________________________________
sipx-users mailing list [email protected]
List Archive: http://list.sipfoundry.org/archive/sipx-users
Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-users
sipXecs IP PBX -- http://www.sipfoundry.org/

Reply via email to