I didn't know what firewall you are using. Pfsense will keep the state open, there in no setting needed.
Their inhouse test is going through nat? And has a firewall? If not their test is flawed. Do a wan pcap to port 5060, full detail and specify their gateway address and run it beginning at 18 minutes into a call that drops in20. They should do the same. ============================ Tony Graziano, Manager Telephone: 434.984.8430 Fax: 434.984.8431 Email: [email protected] LAN/Telephony/Security and Control Systems Helpdesk: Telephone: 434.984.8426 Fax: 434.984.8427 Helpdesk Contract Customers: http://www.myitdepartment.net/gethelp/ ----- Original Message ----- From: [email protected] <[email protected]> To: [email protected] <[email protected]> Sent: Fri Oct 15 01:32:01 2010 Subject: Re: [sipx-users] system configs I'm not familiar with that setting. Where is it found in pfSense? (Although this problem also occurs with a Vyatta firewall). And I'm a little confused as to how the firewall would know the value in the SE header. Can you elaborate? On Fri 15.Oct.10 00:59, Tony Graziano wrote: >Firewll has a ttl on your media nat session. > >What is it? >============================ >Tony Graziano, Manager >Telephone: 434.984.8430 >Fax: 434.984.8431 > >Email: [email protected] > >LAN/Telephony/Security and Control Systems Helpdesk: >Telephone: 434.984.8426 >Fax: 434.984.8427 > >Helpdesk Contract Customers: >http://www.myitdepartment.net/gethelp/ > >----- Original Message ----- >From: [email protected] ><[email protected]> >To: [email protected] <[email protected]> >Sent: Fri Oct 15 00:53:43 2010 >Subject: Re: [sipx-users] system configs > >I think that's what they've done, but apparently the calls don't drop on >their system. > >Myself, I think they are on the wrong track. They are saying it's a >problem with their Underlying Carrier and that's what they are >attempting to debug. > >What I see is that Sipx sends an INVITE with SE of 600 (I reduced it >from the original 1800 to make it easier to debug). They send a 200 OK >with no SE header so no Session Timer will be in effect. And, they claim >that they don't use Session Timers. Yet they send a BYE after 600 >seconds. I've tried different valuse: the original default of 1800, and >660 just to confirm it. They always send the BYE at the end of that >time. > >On Thu 14.Oct.10 23:51, Tony Graziano wrote: >>But why don't you have them setup the system and a test trunk of their >>own. >> >>That should be so much easier. >>============================ >>Tony Graziano, Manager >>Telephone: 434.984.8430 >>Fax: 434.984.8431 >> >>Email: [email protected] >> >>LAN/Telephony/Security and Control Systems Helpdesk: >>Telephone: 434.984.8426 >>Fax: 434.984.8427 >> >>Helpdesk Contract Customers: >>http://www.myitdepartment.net/gethelp/ >> >>----- Original Message ----- >>From: Tony Graziano <[email protected]> >>To: [email protected] <[email protected]> >>Sent: Thu Oct 14 18:10:30 2010 >>Subject: Re: [sipx-users] system configs >> >>You would have to send them a backup and theywould have everything. >> >>Pins, sip passwords, everything except root passwd. >> > >I would stay away from that. >>============================ >>Tony Graziano, Manager >>Telephone: 434.984.8430 >>Fax: 434.984.8431 >> >>Email: [email protected] >> >>LAN/Telephony/Security and Control Systems Helpdesk: >>Telephone: 434.984.8426 >>Fax: 434.984.8427 >> >>Helpdesk Contract Customers: >>http://www.myitdepartment.net/gethelp/ >> >>----- Original Message ----- >>From: [email protected] >><[email protected]> >>To: [email protected] <[email protected]> >>Sent: Thu Oct 14 17:00:13 2010 >>Subject: [sipx-users] system configs >> >>I'm still working with Flowroute on a dropped call problem. They have >>setup a SipX test system, but are not able to duplicate the problem. >>They would like me to send my configuration files so they can load them >>into their system. >> >>1. Is this possible? What would I need to send, and is there a way to >>only include the config for the Flowroute gateway? >> >>2. What are the security/privacy worries with doing this? >> > >-- >Dan McDaniel >[email protected] >Key fingerprint = CAEC B8D9 3701 86CF D3B2 1E99 D8BB F217 455C AD36 >_______________________________________________ >sipx-users mailing list >[email protected] >List Archive: http://list.sipfoundry.org/archive/sipx-users/ >_______________________________________________ >sipx-users mailing list >[email protected] >List Archive: http://list.sipfoundry.org/archive/sipx-users/ > -- Dan McDaniel [email protected] Key fingerprint = CAEC B8D9 3701 86CF D3B2 1E99 D8BB F217 455C AD36 _______________________________________________ sipx-users mailing list [email protected] List Archive: http://list.sipfoundry.org/archive/sipx-users/ _______________________________________________ sipx-users mailing list [email protected] List Archive: http://list.sipfoundry.org/archive/sipx-users/
