10-21-2017 09:10 AM - edited 03-17-2019 11:26 AM
Hi, hope you are having good time. I have a VPN between our PK and US office, and I am are facing "sip/2.0 403 forbidden" error when I try to call from US to PK extension numbers. US to US and PK to US dialing is perfectly fine, only US to PK dialing is showing this error. I am attaching show ccsip message and show ccsip calls.
can anyone please adivse?
Solved! Go to Solution.
10-23-2017 05:45 PM
Ok so phones on US can't call PK correct, Look at your voice service voip on pki.
Try the following
voice service voip
no ip address trusted list
allow-connections h323 to h323
allow-connections h323 to sip
allow-connections sip to h323
allow-connections sip to sip
10-21-2017 10:12 AM
10-21-2017 11:49 AM
10-21-2017 12:34 PM
10-21-2017 12:39 PM
10-21-2017 09:52 PM
10-22-2017 04:38 AM
10-22-2017 09:53 AM
Since the system is in production/live, can you please let me know how to send configs to you in private!
10-22-2017 01:43 PM
Just pull a show run and pull out all public / private IP you feel are sensitive , any passwords and or hashes, and any DID numbers and or identifying information. If you want to start smaller can you send me back the voice service voip sections from both routers first. I want to check you don't have a toll fraud mechanism enabled that might prevent this call.
10-22-2017 10:13 PM - edited 10-22-2017 10:13 PM
10-23-2017 05:44 AM
Are the addresses your phones and cme tied to called out in your
voice service voip 67
ip address trusted list
Ipv4 xxx
ipv4 xxx
ipv4 xxx
ipv4 xxx
10-23-2017 11:48 AM
there are 3 IPs, One is Public facing interface, second is private IP, and the third is GRE tunnel IP of PK router. other 3 are public IPs of service provider network, I'm not sure why these are here.
10-23-2017 05:41 PM
They are a toll fraud mechanism for now just do
voice service voip
no ipv4 trusted authenciation list
or whatever the command is to disable it.
Test again and let me know the results
capture debug ccsip messages
debug dial-peer
debub voice ccapi inout on both routers as your a making call and the debugs from each router.
. Also what are your inbound and outbound dial-peers you are trying to match on each router
10-23-2017 05:45 PM
Ok so phones on US can't call PK correct, Look at your voice service voip on pki.
Try the following
voice service voip
no ip address trusted list
allow-connections h323 to h323
allow-connections h323 to sip
allow-connections sip to h323
allow-connections sip to sip
10-24-2017 05:08 PM
Any update on this one?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide