05-11-2011 03:56 PM - edited 03-16-2019 04:56 AM
I have ASA 5510 appliance with 8.2.4 IOS, we implement voip between outside and inside interfaces, the connection betwen two ip phones drops after 30 sec.
05-16-2011 08:09 AM
Can you collect packet captures off of the inside and outside interface of the ASA for the failed call?
-Felipe
05-17-2011 02:46 AM
Hello
I send you some files, in the sniffer one the comunication is between phone ip 172.26.200.104 and 172.26.200.105 in outside both, the PBX is 172.25.0.229, and is in inside.
In this log example I show you the call between 172.240.102 and172.26.200.104
May 11 13:59:40 172.25.0.209 :May 11 13:17:22 CEDT: %ASA-session-6-302013: Built inbound TCP connection 1107558 for WAN:172.24.0.102/1026 (172.24.0.102/1026) to LAN:172.25.0.229/1720 (172.25.0.229/1720)
May 11 13:59:40 172.25.0.209 :May 11 13:17:22 CEDT: %ASA-session-6-302013: Built outbound TCP connection 1107559 for WAN:172.26.200.104/1720 (172.26.200.104/1720) to LAN:172.25.0.229/12783 (172.25.0.229/12783)
May 11 13:59:40 172.25.0.209 :May 11 13:17:22 CEDT: %ASA-session-6-302003: Built H245 connection for faddr 172.26.200.104/0 laddr 172.25.0.229
May 11 13:59:40 172.25.0.209 :May 11 13:17:22 CEDT: %ASA-session-6-302004: Pre-allocate H323 UDP backconnection for faddr 172.26.200.104/5010 to laddr 172.24.0.102
May 11 13:59:40 172.25.0.209 :May 11 13:17:22 CEDT: %ASA-session-6-302004: Pre-allocate H323 UDP backconnection for faddr 172.26.200.104/5011 to laddr 172.24.0.102
May 11 13:59:40 172.25.0.209 :May 11 13:17:22 CEDT: %ASA-session-6-302015: Built outbound UDP connection 1107562 for WAN:172.24.0.102/5010 (172.24.0.102/5010) to WAN:172.26.200.104/5010 (172.26.200.104/5010)
May 11 13:59:40 172.25.0.209 :May 11 13:17:25 CEDT: %ASA-session-6-302003: Built H245 connection for faddr 172.24.0.102/0 laddr 172.25.0.229
May 11 13:59:40 172.25.0.209 :May 11 13:17:27 CEDT: %ASA-session-6-302015: Built outbound UDP connection 1107563 for WAN:172.24.0.102/5011 (172.24.0.102/5011) to WAN:172.26.200.104/5011 (172.26.200.104/5011)
May 11 14:00:10 172.25.0.209 :May 11 13:17:52 CEDT: %ASA-session-6-302014: Teardown TCP connection 1107560 for WAN:172.26.200.104/0 to LAN:172.25.0.229/12784 duration 0:00:30 bytes 0 Pinhole timeout
May 11 14:00:10 172.25.0.209 :May 11 13:18:01 CEDT: %ASA-session-6-302014: Teardown TCP connection 1107559 for WAN:172.26.200.104/1720 to LAN:172.25.0.229/12783 duration 0:00:39 bytes 951 TCP Reset-I
May 11 14:00:10 172.25.0.209 :May 11 13:18:01 CEDT: %ASA-session-6-302016: Teardown UDP connection 1107564 for WAN:172.26.200.104/0 to WAN:172.24.0.102/5011 duration 0:00:39 bytes 0
May 11 14:00:10 172.25.0.209 :May 11 13:18:01 CEDT: %ASA-session-6-302016: Teardown UDP connection 1107563 for WAN:172.24.0.102/5011 to WAN:172.26.200.104/5011 duration 0:00:33 bytes 364
May 11 14:00:10 172.25.0.209 :May 11 13:18:01 CEDT: %ASA-session-6-302016: Teardown UDP connection 1107562 for WAN:172.24.0.102/5010 to WAN:172.26.200.104/5010 duration 0:00:38 bytes 62176
May 11 14:00:10 172.25.0.209 :May 11 13:18:01 CEDT: %ASA-session-6-302016: Teardown UDP connection 1107561 for WAN:172.26.200.104/0 to WAN:172.24.0.102/5010 duration 0:00:39 bytes 0
May 11 14:00:10 172.25.0.209 :May 11 13:18:01 CEDT: %ASA-session-4-106023: Deny udp src WAN:172.24.0.102/5010 dst WAN:172.26.200.104/5010 by access-group "WAN_access_in" 0x0, 0x0
Regards,
Nombre
Departamento de Informática y Telecomunicaciones
Antes de imprimir este mensaje, asegúrese de que es necesario. El medio ambiente está en nuestra mano.
05-16-2011 05:39 PM
does it still happen if you disable service-policy?
05-17-2011 02:16 AM
N, service policy is enabled, I can send you runnig-conf.
Saludos,
Nombre
Departamento de Informática y Telecomunicaciones
Antes de imprimir este mensaje, asegúrese de que es necesario. El medio ambiente está en nuestra mano.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide