Currently running fortigate 60f on 6.4.9 and I can assure you this guide works. If it doesn't, run the following on the fortigate Config voip profile Edit default Config sip Set rtp disable End End Then reboot the FW.
very nice explained and detailed video. I did manage to disable SIP ALG but having issues with full-cone test failing on port 5060 and all media ports.
This tutorial should help to set up your firewall. If you're using Issabel then in addition to firewall you will have to set up NAT in General/Advanced SIP/PJSIP settings (eg. directmedia, externip, localnet, etc...)
You do all know that you can open the ports to run the port checker which will pass, then you can close the ports you don't want and do not run the checker...
Currently running fortigate 60f on 6.4.9 and I can assure you this guide works. If it doesn't, run the following on the fortigate
Config voip profile
Edit default
Config sip
Set rtp disable
End
End
Then reboot the FW.
Great video. I was actually facing similar problem. Thanks for the solution
you saved me man nice video.
very nice explained and detailed video.
I did manage to disable SIP ALG but having issues with full-cone test failing on port 5060 and all media ports.
fixed it. the issue was with the geolocation in the inbound firewall rule.
Nice that it worked 👍
Bloodly Awesome, this helped me HEAPS!
thanks alot
i want to ask abiut using another based asterisk - issabel
if i followed same instructions do i have to disable NAT on the issabel or not
This tutorial should help to set up your firewall. If you're using Issabel then in addition to firewall you will have to set up NAT in General/Advanced SIP/PJSIP settings (eg. directmedia, externip, localnet, etc...)
thanx man
Very nice and helpful video! Could also please make for sophos XG series
Thanks a lot It's pass all 3CX Version 18.0 and FG Version 6.2.9
Thanks 👍
I hope it’ll help someone. And I’m glad you enjoyed it
You do all know that you can open the ports to run the port checker which will pass, then you can close the ports you don't want and do not run the checker...