Showing results for 
Search instead for 
Did you mean: 

SIP GW behind NAT

Julien Tourel
Level 1
Level 1


My config :

CUCM6-----------ISR2811------(sip)--------NAT+FW-------(sip)--------SIP Provider

ISR2811 and NAT+FW are not the same equipment.

ISR2811 : IP-to-IP feature, only one network interface + private ip address.

NAT+FW : not a Cisco equipment. Do not support SIP inspection to replace private IP address by public, in SIP and SDP payload

Dynamic RTP ports affectation is not my issue. All ports are statiquely mapped to ISR2811.

Since NAT+FW do not provide SIP inspection, is there a way/feature/command to indicate public IP address to the ISR2811 ? The goal is to make all SIP signalisation and SDP fields of outgoing calls directly with the public IP address, instead of private IP address.

Thank you for your help.



4 Replies 4

Level 1
Level 1

1. Change your NAT+FW device

2. Put 2811`s other fast ethernet leg into public network, give a public IP address, let it route SIP packets to SIP Provider.

Thank you for your answer hguner.

Difficult to push that solution. My customer is not ready to change its internet connection today.

Does it mean SIP on GW is not supported behind a non-cisco NAT ?



You can use a non-Cisco device for NAT, but whatever device you use *needs* to be able to do NAT inspection/fixup for SIP.  Otherwise, the other side is not going to get the right address in the SIP SDP for where to send RTP to.  You can run a packet capture, and you'll see the wrong IP in the SDP of the SIP INVITE/18X (or 200/ACK for delayed offer).

With SCCP, since that is proprietary, you need a Cisco NAT device.  SIP is an open standard, so other vendors could work.

I understand intelligence in the NAT is a solution, but not the one I can propose to my customer. So I'm looking for intelligence in the GW.

STUN protocol could be a solution. Is STUN supported in voice GW ?