03-30-2015 11:42 AM - edited 03-18-2019 04:16 AM
Hi folks,
We are deploying a new project with Mobile Remote Access solution in order to allow Jabber client to communicate from internet. These are the version and servers that we have:
CUCM 10.5.1
Presence 10.5.1
Expressway-C and Expressway-E running 8.5.1 (Both were installed with the version 8.2 and were upgraded to the version 8.5.1)
This is a simple topology of our environment. Expressway is using two interfaces and its external interface is behind NAT 1 to 1 (with the proper public IP address configured on the IP settings):
The issue we facing is very weird. The external Jabber clients are able to register and make calls to the internal devices properly, however, when the call is connected, we have no RTP from both sides.
After performing some debugs we came to conclusion that it might be some king of bug on VCS Expressway. This is what happens:
The most weird point is that, If I reboot Expressway-E, the first call made after the reboot works just fine (we have RTP in both directions), however, the next call attempts have the same symptom, no RTP at all. Then another reboot makes the first call to work correctly.
Has anybody here got a issue like that?
Thanks in advance.
Paulo Souza
06-24-2017 04:39 PM
I have the same problem... did you find a solution ?
10-15-2017 09:59 PM
I ended up getting this working with the following - http://cookbook.fortinet.com/configure-hair-pinning-fortigate/
It has to do with the way the Fortinet does it's NAT when using a VIP.
So for example my Expressway-E server has an IP address of 10.1.1.1 and an external address of 192.1.1.1
My DNS is jabber.lab.com pointing to 192.1.1.1 both internally in my domain and externally. It is important that internal and external clients use the external address so they must be the same.
On the Fortinet my Expressway-E is shown as a VIP with a static NAT so 10.1.1.1 <-> 192.1.1.1 on any interface.
When my Expressway-C needed to connect to the Expressway-E via the external address it was failing.
The solution was to follow the article I linked to at the start of this post. In this article be aware that in point 2 where they are editing the match-vip setting the edit 2 relates the rule you are changing this setting on.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide