<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ZBFW with SIP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zbfw-with-sip/m-p/2128697#M392249</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Keith,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exactly, great to have that info,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Jan 2013 20:49:15 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-01-24T20:49:15Z</dc:date>
    <item>
      <title>ZBFW with SIP</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-with-sip/m-p/2128692#M392244</link>
      <description>&lt;P&gt;Hope this is the right spot for this. I am running an 891W with a ZBFW setup as the CPE, software &lt;SPAN style="font-size: 10pt;"&gt;c890-universalk9-mz.150-1.M4.bin. The issue I am working with is we are using a hosted platform for SIP and trying to register a phone through the SBC. I control the ISP side, this is a test with a customer that we have access to the CPE on. The phone registers fine, I can see the SIP pinhole being made and packets flowing. The problem seems to be when the SBC relays the 401 unauthorized to challenge the authentication, it never gets through the firewall. When we checked with a sniffer, we see the packet going out the SBC and the port matches the pinhole on the firewall including the port info, but no packets ever get to the phone. Does anyone know why this would happen?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Also, the phone is sending out PRACK messages, but they never are seen on the SBC side, it seems like they are not flowing through for some reason.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:51:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-with-sip/m-p/2128692#M392244</guid>
      <dc:creator>Keith McElroy</dc:creator>
      <dc:date>2019-03-12T00:51:50Z</dc:date>
    </item>
    <item>
      <title>ZBFW with SIP</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-with-sip/m-p/2128693#M392245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you check what you have configured for this,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also enable the logs,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect log drop-pkt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try to register and do &lt;/P&gt;&lt;P&gt;show logging | include x.x.x.x ( Call manager or host where the phones will register)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2013 17:43:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-with-sip/m-p/2128693#M392245</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-24T17:43:49Z</dc:date>
    </item>
    <item>
      <title>ZBFW with SIP</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-with-sip/m-p/2128694#M392246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, I found the work around. I found the errors for invalid SIP headers, so I ran the "match protocol-violation" bypass and it seems to work. Sort of worries me that there is a problem in the SIP header, but I don't think there is much I can change since it is Polycom phones going to a Broadsoft platform.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2013 19:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-with-sip/m-p/2128694#M392246</guid>
      <dc:creator>Keith McElroy</dc:creator>
      <dc:date>2013-01-24T19:58:05Z</dc:date>
    </item>
    <item>
      <title>ZBFW with SIP</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-with-sip/m-p/2128695#M392247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Keith,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the explanation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you mind to show the community the exact commands you run so we can learn from you .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also please mark the question as answered so future users can learn from this,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5 stars for you &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2013 20:21:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-with-sip/m-p/2128695#M392247</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-24T20:21:28Z</dc:date>
    </item>
    <item>
      <title>ZBFW with SIP</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-with-sip/m-p/2128696#M392248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;class-map type inspect sip match-any SIP&lt;/P&gt;&lt;P&gt; match&amp;nbsp; protocol-violation&lt;/P&gt;&lt;P&gt;class-map type inspect match-any SIP1&lt;/P&gt;&lt;P&gt; match protocol sip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect Out &lt;/P&gt;&lt;P&gt;&amp;nbsp; class type inspect SIP1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspect&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; service-policy sip SIP1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is the basic config I tossed into my outbound policy along with my other config to allow other traffic for users. I am still confused why Polycom has a header failure, but I will have to see if that is something we can have fixed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2013 20:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-with-sip/m-p/2128696#M392248</guid>
      <dc:creator>Keith McElroy</dc:creator>
      <dc:date>2013-01-24T20:43:00Z</dc:date>
    </item>
    <item>
      <title>ZBFW with SIP</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-with-sip/m-p/2128697#M392249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Keith,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exactly, great to have that info,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2013 20:49:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-with-sip/m-p/2128697#M392249</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-24T20:49:15Z</dc:date>
    </item>
  </channel>
</rss>

