ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    One Way Audio Issues and STUN

    IT Discussion
    5
    43
    2.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DustinB3403D
      DustinB3403 @krisleslie
      last edited by DustinB3403

      @krisleslie said in SIP Desk Phones Not Re-Registering with Main WAN's IP After WAN Fail-back:

      Cloud hosted. I will make a new thread. I apologize.

      No wait, stop.

      Paging @scottalanmiller to fork from here https://mangolassi.it/topic/16604/sip-desk-phones-not-re-registering-with-main-wan-s-ip-after-wan-fail-back/21

      1 Reply Last reply Reply Quote 0
      • JaredBuschJ
        JaredBusch @krisleslie
        last edited by

        @krisleslie said in One Way Audio Issues and STUN:

        Cloud hosted. I will make a new thread. I apologize.

        Ok, so one way issues should happen on ext to ext calls too if it was your firewall. It should not be "only" on external calls.

        1 Reply Last reply Reply Quote 0
        • DustinB3403D
          DustinB3403
          last edited by

          @JaredBusch I might've missed it, but is @krisleslie system hosted offsite on vultr or some such place?

          scottalanmillerS 1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller @DustinB3403
            last edited by

            @dustinb3403 said in One Way Audio Issues and STUN:

            @JaredBusch I might've missed it, but is @krisleslie system hosted offsite on vultr or some such place?

            It's on Rackspace.

            1 Reply Last reply Reply Quote 1
            • S
              scotth
              last edited by scotth

              This may or may not help.... I ran into a SIP issue last fall at one of our sites. I found IPS triggers in the logs and created an exception in the IPS which fixed the issue.
              This started as a one way audio issue.
              Here's a cap of the signature database description. We use Watchguard appliances.

              0_1520972420278_SIP IPS signature trigger.png

              1 Reply Last reply Reply Quote 0
              • K
                krisleslie
                last edited by

                Scott I caught an article on that also this morning how SIP/ALG and IPS need to both be off. Why is it that the things intended to make things "better" tend to need to be off lol. Then when we add STUN to the equation it can also negate any other changes made due to it!

                K scottalanmillerS 2 Replies Last reply Reply Quote 0
                • K
                  krisleslie @krisleslie
                  last edited by

                  The SIP/ALG I forgot to turn off last night as I was too busy trying to test out my WDS server 🙂

                  If I stay late tonight and the office is clear, I'm disabling that ALG it seems to be the common cause of all issues and then as far as IPS getting disabled on the Edge Router I dunno how or even if I should!

                  K 1 Reply Last reply Reply Quote 1
                  • K
                    krisleslie @krisleslie
                    last edited by

                    Hackers are probing us just not in high volume.

                    1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @krisleslie
                      last edited by

                      @krisleslie said in One Way Audio Issues and STUN:

                      Scott I caught an article on that also this morning how SIP/ALG and IPS need to both be off. Why is it that the things intended to make things "better" tend to need to be off lol. Then when we add STUN to the equation it can also negate any other changes made due to it!

                      ALG should normally always be off, and Jarod always disables in on ER devices. We've had good luck in it not breaking there (it definitely breaks on every other device we know of.) ALG is not designed to fix anything, AFAIK, it is literally intended to break SIP, it's never fixed anything and there was nothing to fix.

                      K 1 Reply Last reply Reply Quote 1
                      • K
                        krisleslie @scottalanmiller
                        last edited by

                        @scottalanmiller WOW can I become one of the IETF that proposes things to break things! I'm sure I can do a good job lol

                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @krisleslie
                          last edited by

                          @krisleslie said in One Way Audio Issues and STUN:

                          @scottalanmiller WOW can I become one of the IETF that proposes things to break things! I'm sure I can do a good job lol

                          Not aware of ALG as any standard. Just an industry option for "break SIP".

                          JaredBuschJ 1 Reply Last reply Reply Quote 0
                          • JaredBuschJ
                            JaredBusch @scottalanmiller
                            last edited by

                            @scottalanmiller said in One Way Audio Issues and STUN:

                            @krisleslie said in One Way Audio Issues and STUN:

                            @scottalanmiller WOW can I become one of the IETF that proposes things to break things! I'm sure I can do a good job lol

                            Not aware of ALG as any standard. Just an industry option for "break SIP".

                            ALG was part of the SIP Examples RFC (I have read this before but had to google it up again).

                            https://tools.ietf.org/html/rfc3665

                            The problem with ALG is that, if I understand how it was originally designed, it is basically a MitM on SIP traffic.

                            scottalanmillerS 1 Reply Last reply Reply Quote 1
                            • scottalanmillerS
                              scottalanmiller @JaredBusch
                              last edited by

                              @jaredbusch said in One Way Audio Issues and STUN:

                              The problem with ALG is that, if I understand how it was originally designed, it is basically a MitM on SIP traffic.

                              That's my understanding of it, and how it is implemented. Had no idea there was a standard for that mess.

                              1 Reply Last reply Reply Quote 0
                              • S
                                scotth
                                last edited by

                                I've never turned on ALG. I caught this because I have a catchall proxy at the end of my policies for outgoing TCP/UDP/DNS that might have slipped through my other policies. It makes sure that everything is scanned and IPS hopefully catches what I may have missed.

                                scottalanmillerS 1 Reply Last reply Reply Quote 0
                                • S
                                  scotth
                                  last edited by scotth

                                  I don't like the stock, out of the box -- Allow All to Any
                                  Edit: Outgoing: Allow All to Any

                                  1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @scotth
                                    last edited by

                                    @scotth said in One Way Audio Issues and STUN:

                                    I've never turned on ALG.

                                    On by default, have to manually turn it off.

                                    S 1 Reply Last reply Reply Quote 0
                                    • S
                                      scotth @scottalanmiller
                                      last edited by

                                      @scottalanmiller said in One Way Audio Issues and STUN:

                                      @scotth said in One Way Audio Issues and STUN:

                                      I've never turned on ALG.

                                      On by default, have to manually turn it off.

                                      Not in the Watchguards that I use

                                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @scotth
                                        last edited by

                                        @scotth said in One Way Audio Issues and STUN:

                                        @scottalanmiller said in One Way Audio Issues and STUN:

                                        @scotth said in One Way Audio Issues and STUN:

                                        I've never turned on ALG.

                                        On by default, have to manually turn it off.

                                        Not in the Watchguards that I use

                                        We're discussing Ubiquiti here. That's what the OP is using.

                                        1 Reply Last reply Reply Quote 0
                                        • S
                                          scotth
                                          last edited by

                                          Apologies

                                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller @scotth
                                            last edited by

                                            @scotth said in One Way Audio Issues and STUN:

                                            Apologies

                                            Although nice that WG doesn't turn it on by default, most systems do. Such a bad idea.

                                            S 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 2 / 3
                                            • First post
                                              Last post