Because of Corvid-19 more people are working from home. This means telephones need to connect also from home. This is not my forte. They mostly ask to configure portforwards for both the registration and the audio. The audio ussualy needs an portrange. This is where my question comes in:
To setup a range of ports I use this:
ip nat pool natpool 192.168.36.208 192.168.36.208 netmask 255.255.255.0 type rotary ip nat inside destination list portrange pool natpool
ip access-list extended portrange permit tcp any any eq www permit udp any any eq 5060 permit udp any any range 16000 16511 permit tcp any any range 16000 16511 deny ip any any
I'm not using a dialer of gig interface, becaus of the IP nat inside command.
>> RTP has a broad range of ports assigned 16384 - 32767 UDP. However different vendors use different ports (e.g. CUCM uses only a number 24576-32767/UDP) hence you may want to check the ASterisk Documentation to make sure you open only concerned ports.
Hello Append your acl to allow the following voip and signaling taffic and test again: permit udp any any eq 16384 32767 permit tcp any any eq 1720
Regards your NAT statements, you have destination nat to a single internal host, So your present nat pool statement wouldn’t require the rotary command?
DNAT would be most applicable when you have a virtual ip address related to multiple internal physical servers So I would expect your nat pool to state multiple internal hosts and then have a the access-list to state a specific public ip address! However, without knowing you topology this may not be applicable.
Example: Host 126.96.36.199 is your inside global vip address ip nat pool natpool 192.168.36.208 192.168.36.211 netmask 255.255.255.0 type rotary ip nat inside destination list portrange pool natpool
ip access-list extended portrange permit udp any host 188.8.131.52 eq 16384 32767 permit tcp any host 184.108.40.206 eq 1720 permit tcp any host 220.127.116.11 eq www permit udp any host 18.104.22.168 eq 5050
Please rate and mark as an accepted solution if you have found any of the information provided useful. This then could assist others on these forums to find a valuable answer and broadens the community’s global network.