cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
956
Views
0
Helpful
8
Replies

PIX 515E ....UDP Port Mismatch

dennisbarnes
Level 1
Level 1

Hi ,

I am trying to make SIP calls, our PIX firewall keep changing the port from 5060 to something like 1172 or any other, our partner where we actually terminate our calls need us to send all SIP traffic through port 5060.

Can any one please help me to resolve this issue, my UA and all other internal servers sending calls on 5060 except my PIX. We are using PIX 515E.

Regards,

Dennis Barnes

8 Replies 8

pkapoor
Level 3
Level 3

Check your translation statements.

Thanks for the reply, my translation statement is like this

"static (inside,outside) udp 65.200.193.65 5060 10.6.11.11 5060 netmask 255.255.255.255 0 0 "

65.200.193.65 is my outside address, known by service provider.

10.6.11.11 is the address of SIP proxy that's how I make it work all the time , but rite now its keep changing port number and since we are commited to send all traffic to port 5060 our call attempts were not sucessful.

Is 65.200.193.65 the only public IP you have. If not, then set a static translation (1-to-1) for the 10.6.11.11 instead of using port re-direction.

Let me know if this works.

Unfortunately yes...We do have more public IP addresses but our service provider has only this public IP address.

I try to get a range open from them can you please tell me what do u mean by static translation or 1-1 mapping, the translation rule which I am using right now is it not an example of 1-1 mapping because my routable address mapped directly with 10.6.11.11 i.e our SIP Proxy server.

A static 1-to-1 translation would be:

static (inside,outside) 65.200.193.65 10.6.11.11 netmask 255.255.255.255 0 0

What you are doing currently is called port-redirection.

Before trying the above, you may also want to try enabling/disabling the following commands:

fixup protocol sip 5060

fixup protocol sip udp 5060

I will definitely try this after hours and let u know about my findings, can I have your e-mail address so that we can talk about the results.

Once again thanks for replies..

I will not be accessing my emails for the next 3 days. So, just make your post here and I'll catch it here.

Thanks I will keep you posted...

Review Cisco Networking for a $25 gift card