<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SIP trough ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204545#M1065266</link>
    <description>&lt;P&gt;Everything I´ve been reading so far about SIP through ASA says that you need to perform inspect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;To support SIP calls through the ASA, signaling messages for the media connection addresses, media ports, and embryonic connections for the media must be inspected, because while the signaling is sent over a well-known destination port (UDP/TCP 5060), the media streams are dynamically allocated. Also, SIP embeds IP addresses in the user-data portion of the IP packet. SIP inspection applies NAT for these embedded IP addresses."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/inspect_voicevideo.html#wp1204403" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/inspect_voicevideo.html#wp1204403&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You said above that you turned inspection off, right?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-If I helped you somehow, please, rate it as useful.-&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2017 21:16:46 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2017-10-24T21:16:46Z</dc:date>
    <item>
      <title>SIP trough ASA</title>
      <link>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204454#M1065263</link>
      <description>&lt;P&gt;Hello !&lt;/P&gt;
&lt;P&gt;I have VoIP SIP servers in my internal network. Now I want to provide SIP softphones to register on servers and use internal VoIP resources. I put on ASA with public address between Internet and my intranet. Also, I NAT-ed address off my servers to public address and,with ACL allowed&amp;nbsp; any address outsdie to connect to SIP servers. I turned SIP inspection off. Well, softphones are registred on servers,I can place the call and everything looks fine.But,after 60 sec,Phones lose registration...Why?Please help me, it is pretty urgent.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:34:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204454#M1065263</guid>
      <dc:creator>tandrejevic</dc:creator>
      <dc:date>2020-02-21T14:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: SIP trough ASA</title>
      <link>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204520#M1065264</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/341431"&gt;@tandrejevic&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;And why do you think ASA is the problem? Do you have some evidence of it?&lt;/P&gt;
&lt;P&gt;Which Voip system do you have? Asterisk ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 20:38:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204520#M1065264</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-10-24T20:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: SIP trough ASA</title>
      <link>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204533#M1065265</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your interest. We have Avaya system and if I put softphone in inside ASA (in intranet exactly) everything works fine...Also,if I&lt;/P&gt;
&lt;H3 class="r"&gt;&lt;A href="https://www.google.rs/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=1&amp;amp;cad=rja&amp;amp;uact=8&amp;amp;ved=0ahUKEwi4yNKvkYrXAhWnAcAKHd7ADB4QFggmMAA&amp;amp;url=https%3A%2F%2Fsupportforums.cisco.com%2Ft5%2Ffirewalling%2Fdenied-due-to-nat-reverse-path-failure%2Ftd-p%2F1414247&amp;amp;usg=AOvVaw2lR-At34BrOvux7vob9I-P" data-href="https://supportforums.cisco.com/t5/firewalling/denied-due-to-nat-reverse-path-failure/td-p/1414247" target="_blank"&gt;Denied due to NAT reverse path failure&lt;/A&gt;&lt;/H3&gt;
&lt;P&gt;try trace on ASA ,I get massage ,,denied due to NAT reverse path failure"&lt;/P&gt;
&lt;P&gt;I heve done NAT with:&lt;/P&gt;
&lt;P&gt;object network-object SM1&lt;/P&gt;
&lt;P&gt;host 192.168.1.15&lt;/P&gt;
&lt;P&gt;nat (inside,outside) static 217.X.X.15&lt;/P&gt;
&lt;P&gt;and configured ACL&lt;/P&gt;
&lt;P&gt;access-list OUTSIDE permit tcp any host 192.168.1.15 eq 5061&lt;/P&gt;
&lt;P&gt;I tried with&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list OUTSIDE permit ip any host 192.168.1.15&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but,with same result.&lt;/P&gt;
&lt;P&gt;What I am missing ?&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 20:58:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204533#M1065265</guid>
      <dc:creator>tandrejevic</dc:creator>
      <dc:date>2017-10-24T20:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: SIP trough ASA</title>
      <link>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204545#M1065266</link>
      <description>&lt;P&gt;Everything I´ve been reading so far about SIP through ASA says that you need to perform inspect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;To support SIP calls through the ASA, signaling messages for the media connection addresses, media ports, and embryonic connections for the media must be inspected, because while the signaling is sent over a well-known destination port (UDP/TCP 5060), the media streams are dynamically allocated. Also, SIP embeds IP addresses in the user-data portion of the IP packet. SIP inspection applies NAT for these embedded IP addresses."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/inspect_voicevideo.html#wp1204403" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/inspect_voicevideo.html#wp1204403&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You said above that you turned inspection off, right?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-If I helped you somehow, please, rate it as useful.-&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 21:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204545#M1065266</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-10-24T21:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: SIP trough ASA</title>
      <link>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204547#M1065267</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes,I turned sip inspection off...But before I had turned off - situation was same...I will read post in the link which you send me. Tomorrow I will try again to turn sip inspection on. Do you mind that sip timeouts in basic ASA configuration have some influence in my problem ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;kind regards&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 21:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204547#M1065267</guid>
      <dc:creator>tandrejevic</dc:creator>
      <dc:date>2017-10-24T21:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: SIP trough ASA</title>
      <link>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204559#M1065268</link>
      <description>&lt;P&gt;I think so. Although you problem is related to phone registration and not voice communication itself.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Is there any debug on the Avaya side to help you why phone loses connection?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 21:42:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204559#M1065268</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-10-24T21:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: SIP trough ASA</title>
      <link>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204561#M1065269</link>
      <description>&lt;P&gt;Flavio,&lt;/P&gt;
&lt;P&gt;just one more question ... Our server actually uses port 5061 (tls). Is it&lt;BR /&gt;sip inspection enough? How I can add&amp;nbsp; inspection port 5061 ?&lt;/P&gt;
&lt;P&gt;Thanks for your time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 21:46:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204561#M1065269</guid>
      <dc:creator>tandrejevic</dc:creator>
      <dc:date>2017-10-24T21:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: SIP trough ASA</title>
      <link>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204566#M1065270</link>
      <description>&lt;P&gt;Flavio&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will try to see what Avaya ,,says"...Thanks anyway.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 21:50:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sip-trough-asa/m-p/3204566#M1065270</guid>
      <dc:creator>tandrejevic</dc:creator>
      <dc:date>2017-10-24T21:50:02Z</dc:date>
    </item>
  </channel>
</rss>

