cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
13485
Views
10
Helpful
7
Replies

Voice call issue due to sip alg enabled in Cisco FTD .

Arun_Singh
Level 1
Level 1

There is requirement of disabling SIP Alg as due to some issue in voice call which get disconnected after few minutes . It has been suggested to turn off SIP Alg in our Cisco Ftd firewalls . What would be the impact on traffic and how can I disable SIP Alg in Cisco FTD firewall which are managed through Cisco FMC .

7 Replies 7

>From FTD CLI, enter the command 'configure inspection sip disable'. You can
generalize this from FMC using flexconfig.

The impact is you need to have rules to allow audio ports through FTD as
they are inspected part of sip inspection and allowed without ACLs if you
have sip inspection ON.

RTP ports are UDP 16384 to 32767.

******* Please remember to rate useful posts

After  'configure inspection sip disable' through the cli ,do I need to make changes in Flex config as well or running the command in cli would disable the sip inspection . After analyzing the wireshark logs I come across 401 error for sip protocol .

I created a object for DisableInspectProtocol for sip protocol and call that object in Object by duplicating Default_Inspection_Protocol_disable object in Flexconfig Object .I used that user defined policy in Prepend Flex config and when I was about to deploy and push I got an Warning stating that "need to configure same value for these topologies" in site to site tunnel .

 

My Flexconfig object and policies are ready to be called and push the changes in devices . Please suggest what changes are to be made in the exiting tunnel as in warning not getting much details for the required changes .

Dennis Mink
VIP Alumni
VIP Alumni

Just as a matter of interest. is this a 3rd Party suggestion or does it come from Cisco. also, what voice product signals through this FW? cucm?  cube? cme?

Please remember to rate useful posts, by clicking on the stars below.

Suggestion was from third party voice team and not from cisco . They were suspecting due to sip inspection calls are getting disconnected when the traffic is made to pass through the firewall . When firewall was bypassed they do not observe any issues .

any updates on this issue, I am having a similar issue.

techpros
Level 1
Level 1

I am experiencing an issue where I disable SIP inspection in FTD and it turns itself back on between 3 and 5 days after I disable it.  No Audio internally but outside callers can hear.  Any Suggestions? 

Review Cisco Networking for a $25 gift card