One Way VOIP Audio Quick Fix

Поделиться
HTML-код
  • Опубликовано: 4 окт 2024
  • Buy Hardware: bit.ly/2QZVeqh
    Get Consulting: bit.ly/36FinSU
    My Other Projects:
    Office Of The CISO: bit.ly/3HGMH1o
    Packet Llama: bit.ly/3SEX3H4
    ###### SOCIAL LINKS ######
    Twitter: bit.ly/2WXiRAv
    Facebook: bit.ly/3eigz4D
    Instagram: bit.ly/3cZneAz
    ######################

Комментарии • 87

  • @FortinetGuru
    @FortinetGuru  3 года назад +9

    Hey Guys, my fat butt keeps saying "hosted" when talking about on-prem. That's my bad! What VOIP setups do you run and what types of issues are you running into?

    • @wiziek
      @wiziek 3 года назад

      I think on-prem isn't really dying that fast. Up until last year I was working for small PBX manufacturer in Europe, company started in 90-ties and has grown since those years, they are still popular on local country market, have some foreign clients in Europe, despite still not having typical cloud or VM solution. What's funny they have even now pretty big share on local market beside Cisco, Siemens or Alcatel and some bigger customers like military, hospitals. With one hospital I think they had pretty nice setup, three seperate PBXes which were joined by fiber which hospital had between each building in differents part of town, whole system had unified internal phone numbers (so calling from one PBX to other could be done using short numbers like calling within same PBX or office) and main device had SIP TRUNK that allowed external calls.

    • @Redirected68
      @Redirected68 2 года назад

      Fax issue from Zerox Versa Link failing using G3 protocol outbound only, and only to certain numbers. Works EVERYTIME to home Cable modem/ATA line. Also works from a "1988" (just old) printer outbound. Variables: Cisco Analog GW VG-XXX, OBS SIP, Zerox Versa Link, G3 Protocol. Any ideas?

  • @JuanDiaz-h5z
    @JuanDiaz-h5z Месяц назад

    Great video! Your solution is helpful. As an MSP, we often deploy Thirdlane Multi Tenant PBX (hosted) with hardware like Yealink and Cisco (Thirdlane is excellent for MSPs due to their great support and margins). Your fix has significantly aided our techs in resolving audio issues. Thanks!

  • @DimusTech
    @DimusTech 3 года назад +3

    Oh I had those happen so much... I always did the same solution as the internet suggested like you did here but this is the first time I got some explanation here what's going on. Thanks!

  • @jpm1211
    @jpm1211 3 года назад +1

    Nice timing, thanks Mike! We just did our cutover this past weekend (6 FGs, FAZ, FMG, and EMS) and I've gotten a few reports of dropped calls from outside callers. We host our Callmanager onsite with SIP trunks coming through (now) the FG 200F so I was just getting ready to start digging into debugging the problem. Now I'm going to follow your suggestion and see if it eliminates the problem.

  • @iddmuia
    @iddmuia 3 года назад

    Thank you very much for this, I deployed an IPSec SD-WAN last week and have been facing a one-way voice issue. I have a hosted YearStar Pbx and phones powered by a cisco 9200 Switch. I hope to do the test tomorrow again and see how it goes. Fingers crossed.

  • @CarsAndGadgetsAu
    @CarsAndGadgetsAu 3 года назад +2

    Thanks for making this video. I wish I had seen this about 6 months ago. We went to a Mitel phone system which used a larger number of ports that fall out of the default port range (~10,000 lower from memory) and we had to.change the proxy helper mode after researching the issue for a couple of weeks. I can get the specifics when I'm in the office if you'd like :-)

  • @WiFiTube
    @WiFiTube 3 года назад +1

    I love the slogan. :-D
    "If (Fortinet) Support was good, I would be broke"

  • @alxirr
    @alxirr 3 года назад +2

    Thanks for possible I have seen this issue before. Thanks for one solution to try .

  • @christianleblhuber2702
    @christianleblhuber2702 3 года назад

    Thank you. helped also a lot on a hosted pbx and a fortigate with os 7.0.0. we had some difficulties with the quality in the first 5 seconds of the connection. This advice solved this. Great.

  • @patlach
    @patlach 3 года назад +3

    if you are using a Panasonic system KX-NS and up. Take off the h323, the mgcp and the sip

    • @floriancoors7684
      @floriancoors7684 3 года назад

      If you are using a Panasonic you better get another PBX - :)

  • @gskapbt
    @gskapbt 11 месяцев назад

    Bro thanks this video 100% worked for me. I’m a voice guy. Thanks again

  • @wiziek
    @wiziek 3 года назад

    When I was working for VoIP PBX manufacturer as support we often recommended either disabling or enabling SIP ALG, most of the time disabling it. Another thing would be double NAT due to poor quality of local ISPs (often those were smalls wisps) or due to client using LTE router with their own second router but no bridge, where double NAT came from.

  • @bavobostoen
    @bavobostoen Год назад

    Thanks, please also create the (promised) more involved/detailed video about fortunate & voip. Best regards!

  • @mattb474
    @mattb474 3 года назад +1

    Couple of extra settings that have helped me with VOIP issues are
    config system settings
    set sip-nat-trace disable
    set sip-help disable (Setting was removed in 6.2 onwards *i think*)
    end
    config voip profile
    edit default
    config sip
    set status disable
    end
    end

    • @nbctcp3450
      @nbctcp3450 2 года назад

      set sip-help disable
      replaced by
      set sip-expectation disable

  • @mattadams1771
    @mattadams1771 3 года назад +1

    Been there done that with ALG. Nice Tenable shirt also.

    • @FortinetGuru
      @FortinetGuru  3 года назад

      I think you got one the same time I did 😉

  • @BesnikZabergja
    @BesnikZabergja 2 года назад

    Hi, I have a freeppx behind Fortigate, I did port forwarding though I have no audio whatsoever!

  • @giancarlosrm
    @giancarlosrm Год назад

    I really like this video!!! help me to fix all my voip issues with fortigate

  • @Furcas
    @Furcas 3 года назад

    Can confirm, this will fix this issue and sip drops with nec PBX systems. Specifically the sv8500 and sv9500 systems. They both will get really intermittent performance with the alg set to proxy. Deleting the session helper was necessary too. I ran into this a little over a year ago and it drove me up a wall.

    • @FortinetGuru
      @FortinetGuru  3 года назад

      Yeah. First time I hit this I was bashing my head against the wall.

    • @wiziek
      @wiziek 3 года назад

      I'd delete or disable SIP ALG to be honest.

  • @jeremysellers1997
    @jeremysellers1997 2 года назад

    Have a on prem pbx looks to be using port 10000. Session helper was kernel based and session 13 was already cleared. Seeing latency and jitter on internal and external calls. Also on a side note I have a third party nms that’s showing broadcast storms on my fortilink vlan. These are used of course as uplink but I feel it may also impact voip quality

  • @piratev20
    @piratev20 3 года назад

    Please upload a video of Link aggregation between Cisco Meraki switches and Fortinet Firewall

  • @serlegar
    @serlegar 3 года назад

    Those should be the default config of the Fortigate. Whenever a customer tell me that he will be running SIP throught the network, I change those options.

  • @nishant3258
    @nishant3258 11 месяцев назад

    Can you tell some troubleshoot steps for ghost calls.
    We used custom ports instead of 5060

  • @jackypoupot890
    @jackypoupot890 3 года назад

    Testing many times it works !

  • @ThomasPaine71
    @ThomasPaine71 3 года назад +1

    I'm looking to stand up some sort on an on prem pbx like asterix or something like that with a couple of phones. Would like to see what you put up in your lab.

    • @FortinetGuru
      @FortinetGuru  3 года назад

      For sure. Asterix was the one I was looking at as well.

    • @wiziek
      @wiziek 3 года назад

      You can try using FreePBX, it is based on asterisk but with built in GUI. Owner company Sangoma even bought Digium which is company that started and is updting Asterisk. To be honest if you didn't really work with VoIP or did just basic stuff managing Asterisk could be annoying for you, you'd be using Linux terminal but also Asterisk commands which may be confusing for non-voip person. With FreePBX (which you don't have pay for, there are some extras but most stuff works fine, you just need spare PC or VM for it, Sangoma hardware isn't mandatory and those are just PC with analog or t1 pcie cards) you can try to click some options with GUI.

  • @utiputin1405
    @utiputin1405 3 года назад

    It Will be great to fix an issue with a Panasonic KX-NS700 and no-way audio
    Recently moved from the PFsense to Fortigate 7.0.1
    In PFsense there were just port-forwarding rules to make phones works
    UDP 2727,9300 -> int. PBX IP - it is for signalling, allow phones to be registered
    UDP 16000-16511 -> int. PBX SUBCARD IP - actually voice streaming
    Created the same VIPs and policies in Forti, got phones successfully connected and registered, phones are able to dial int and ext phone numbers but there is no sound at all.
    Fix from this video does not resolve my issue.
    Any thoughts on how to fix it?

  • @camryds
    @camryds 3 года назад

    I have issues with wifi calling at home -- nothing custom, but I get audio cut off in and out. sounds like packet drops where voice just fades away and drops off here and there. something tells me I need QoS setup for this.

  • @krock404
    @krock404 2 года назад

    Seeing this issue with one of our deployments. 3 offices and a colo facility. Offices had sonicwalls and MPLS and everything worked fine. Replaced office sonicwalls with Fortigates (colo is still a sonicwall) and seeing one way audio issue with our SIP conference phones. If user calls any ext within an office from SIP conf phone everything is fine. Issue happens only when calling another office extension from SIP conf phone where we get one way audio. Outside calls from SIP Conf phones is fine as well. Using Mitel system. The conference phone model is UC 360 if that helps. Tried setting the mentioned settings on all of the office Fortigates. Issue persists. The PBX is located behind the Sonicwall at the colo facility. Any ideas?

  • @steves4522
    @steves4522 3 года назад

    Hi There, would be interested to know how you resolved this issue with a PBX hosted on premise using custom sip ports? Thanks.

  • @osanderr
    @osanderr 2 года назад

    Hi Mike, how are you?, do you have any video about QoS?... i want configure it for SSL-VPN connection and prioritize the quality for Microsoft teams and zoom meeting

  • @tecnologiadainformacao-ifm4550
    @tecnologiadainformacao-ifm4550 2 года назад

    Hello, how do I configure my VOIP telephony in fortigate version 7.0.5? I can't configure!

  • @shahbazsandhu1031
    @shahbazsandhu1031 2 года назад

    Hi Mike, I disabled the SIP-ALG but the customer is still experiencing the issues as they hosted a JIVE cloud PBX and was advised to enable the NAT Keep-alives and to increase SIP UDP timeouts to a minimum of 90 sec. However, their recommendation would be 300 seconds or longer. ( If the UDP timeout is set to lower, not receive any incoming calls and all calls will be directed to the vociemail )
    But I checked that the UDP idle timer is set to 180 seconds.
    Can you please advise me on this?

  • @andreslopez180
    @andreslopez180 3 года назад

    Thanks mike great video. Question
    Where can I find info regarding the recommended users per each firewall. For example. On the 60F the max recommended users is X.
    Not sure if this is a thing with fortinet but it’s on my correct vendor and I don’t like it at all. One of the reason why I’m moving away from them.

    • @FortinetGuru
      @FortinetGuru  3 года назад +1

      I focus on bandwidth. If I have a gigabit fiber line outside which firewall is necessary to flow 1 gigabit of protected data. Users isn’t a good example because one power user (or server) can be drastically different than another.

  • @OscarBailly
    @OscarBailly 10 месяцев назад

    Hello, Have you had any audio issues with Grandstream GRP 2615 phones using Fortinet Firewall and switches? Do we need to make any changes on the FortiGate switches or the IP Phones?

  • @olusoladamilare7639
    @olusoladamilare7639 2 года назад

    dear mike,
    please i am having issue with SIP VOIP on fortinet,
    i have followed the tutorial and disable the alg sip and switched to kernel mode but still the call center are not receiving calls.
    please what do i do?

  • @chbboy93
    @chbboy93 3 года назад

    I've got another question for you. Why does one need appliances to enable security? Shouldn't it be possible that it's all just software and maybe even cloud-based? E.g. Barracuda is rolling out cloud-based SD-WAN, why wouldn't that happen with anything security related going forward?

    • @FortinetGuru
      @FortinetGuru  3 года назад

      No one NEEDS appliances, it is just another layer of the defense in depth approach. You want your security to be layered either way

  • @madil1977
    @madil1977 2 года назад

    Dear kindly i need your help find the below Cisco cme configuration my question is when i call from 300 extension to 307 it should be both SIP and sccp phone ring together
    voice register dn 3
    number 307
    voice register pool 3
    id mac ABCD.13AD.1306
    number 3 dn 3
    ephone-dn 2 dual-line
    number 307
    ephone 2
    device-security-mode none
    mac-address C062.6B62.7D57
    type 7942
    button 1:2

  • @paul-xo4pw
    @paul-xo4pw 2 года назад

    hi i currently have GAMMA sip trunks and they basically 'lock out' and i cant make or receive calls to the on site pbx. If i reset firewall it comes to life and works fine as long as calls are being processed. When the system becomes idle the lines 'lock up' again. i have removed SIP ALG but the 'pinhole' to keep alive keeps on closing, do you have any help or advice

  • @ssciarrino
    @ssciarrino 2 года назад

    I have an on prem Voip System on a separate Vlan with the Fortigate in between. I have 3-4 phones out of 200 that gets one way audio could this help or would everyone get one way audio?

  • @fredericohlow533
    @fredericohlow533 3 года назад

    Hi, do you know if there is a problem with this fix if „Central NAT“ is used?
    Thanks a lot.

  • @kirkirization
    @kirkirization Год назад

    iam ne to that but all service are ok olny pbx i cant reach though fortinrt firewall

  • @hennessy6996
    @hennessy6996 3 года назад +1

    Cool.

  • @user-yk9sk7pg6v
    @user-yk9sk7pg6v 2 года назад

    Hello Guru, I do not have personal access to the internet router/modem - will I be able to disable SIP ALG? Clients cannot hear me on one app (one-way audio), and on another app, calls are oftentimes dropping... It's getting crazy over here. I was told to disable SIP ALG in order to resolve the issue, however, I am currently tethering a phone data plan to my MAC to work from home (will not have router access/private internet for a few weeks more) - thanks, man!

    • @FortinetGuru
      @FortinetGuru  2 года назад

      Alg on the modem / router / firewall is independent and has to be adjusted accordingly.

  • @mdmc1877
    @mdmc1877 11 месяцев назад

    Do I need a reboot after this?

    • @FortinetGuru
      @FortinetGuru  11 месяцев назад +1

      Just a clearing of sessions

  • @kirkirization
    @kirkirization Год назад

    i use pbx out of my office and when i open by http iget it but my extention cant connect my firewall fortinet 100f am new in fortinet

  • @gentianlamcaj5448
    @gentianlamcaj5448 3 года назад

    Hi, thank you for the video. I have another issue: when using sd-wan with dua-home ISP and primary link goes down the Voip phones stuck on No service for two minutes due to session table pronlem. Do you have any solution for that? Thank you!

    • @FortinetGuru
      @FortinetGuru  3 года назад

      Lower session timeouts or configure voice services to recheck / synchronize faster.

  • @RohitSingh-ir1dd
    @RohitSingh-ir1dd 3 года назад

    Hello sir I need some practices tool software for configure fortingate firewall please help

  • @aakuad4665
    @aakuad4665 3 года назад

    But how does voip works if pbx is on cloud and ip phones have private ips behind fortigate ? Disabling alg or session helper would block incoming traffic.

    • @FortinetGuru
      @FortinetGuru  3 года назад

      Most hosted (cloud) driven systems the phones reach out. Not the other way. An always on connection allowing two way comms

  • @zjkosterkid2006
    @zjkosterkid2006 3 года назад

    Do you have a "default config" you use for ensuring your whole network is set up for VOIP traffic (ie. 1 universal config for any VOIP provider) or do you set each vendor up differently? Would love to understand the process (not just learn the steps) of setting your network up with the best possible VOIP settings from FortiGate to FortiSwitch to FortiAP.

    • @FortinetGuru
      @FortinetGuru  3 года назад +1

      I disable the two options mentioned here and let it ride. Otherwise, I use LLDP on FortiSwitches to place the phones in a VOICE / VOIP / PHONES (whatever you really want to call it) VLAN that does not have UTM on it.

    • @jpm1211
      @jpm1211 3 года назад +1

      SIP is SIP. And Mike has a couple real nice vids on setting up the "voice VLAN" scenario, helped me out a lot trying to wrap my brain around The Fortinet Way of doing VLANs.

  • @bobbygage3008
    @bobbygage3008 3 года назад

    We have Cisco phone system when first installed FortiGate we changed both of these settings and have had no issues. But after upgrading from 6.2.6 (with no issues) to 6.4.3 and also attempted 6.4.4 we have had issues. Most issues are a normal working call droppes to one way audio. The other end can't hear us. We have our Cisco phone system in house. Our SIP provider tells us we are dropping packets. Bandwidth, CPU all looks good no issues. Even contacted ISP no issues. Multiple calls to Fortigate is not getting my anywhere. We do have SD wan and thought that was is but forced SIP to only use one port and still no go. Any suggestions? We have a 301E. Last step is to setup span ports and record traffic on a few laptops for a day and see if I can find any packets that are not getting passed on.

    • @FortinetGuru
      @FortinetGuru  3 года назад

      Would need to know more about your setup. Model fortigate, fortiswitches?,Ha? etc architecture etc

  • @hudsonatlantis6754
    @hudsonatlantis6754 3 года назад

    I disable ALG as a rule if voice is involved on the LAN

  • @zacharyarmijo9573
    @zacharyarmijo9573 2 года назад

    It keeps giving me command error??

  • @bwilkin23
    @bwilkin23 3 года назад

    Would this possibly help with an issue where users VOIP from a Jabber smart phone has a bit of delay from their SSL VPN connections? I've found this delay is enough for most users to give up and switch to just forwarding calls to their cells. I thought maybe this was just poor enough internet connection that the latency is noticeable but do you think this setting could be related?

    • @FortinetGuru
      @FortinetGuru  3 года назад

      This will assist on items that utilize SIP protocols

  • @carlosquevedo2767
    @carlosquevedo2767 3 года назад

    I have another issue, incoming calls drop after 30 seconds using FG200E, have you any video about this, please?

    • @FortinetGuru
      @FortinetGuru  3 года назад

      What system? (PBX etc)

    • @carlosquevedo2767
      @carlosquevedo2767 3 года назад

      @@FortinetGuru is a UCM6308, I already figured out the solution to this issue. Thank you for your videos, and all your time.

    • @FortinetGuru
      @FortinetGuru  3 года назад +1

      Okie dokie. Post the solution if you don’t mind so if others are suffering it they will have a solution.

  • @יורםכהן-ה9ע
    @יורםכהן-ה9ע 2 года назад

    Hi
    Disabling sip alg
    Still getting one way audio on ip phones from time to time.
    Using on prem lg pabx registered to sip server via fg100e.
    Using custom sip ports for rtp.
    Any suggetions ?

  • @tonyd6853
    @tonyd6853 Год назад

    1/100 is a lot of complaints.

    • @FortinetGuru
      @FortinetGuru  Год назад

      The closer to zero the better but I agree.

  • @mehrhardt
    @mehrhardt 3 года назад

    Other then your boldness saying that ALL Fortinet support sucks (honestly it is hard to find good and loyal talent BUT I know first hand Fortinet puts 200% into vetting the best it can get in a very competitive market of limited talent)...this is a VERY long winded way of getting to the point. I have been supporting the Fortinet phone system since Talkswitch days (9 plus years) so I am kinda an authority on this. If I was allowed to make support videos for Fortinet products (conflict of interest and all that) I would give you an example of a better explanation. Either way your technical is on point but your 'getting to the point' needs bit of fine tuning. Cheers and all the best in your ventures.

  • @lillysuggs9782
    @lillysuggs9782 Год назад

    Uh for y’all’s non techs wth is he saying??? I need help!!

  • @muhammedsavad6009
    @muhammedsavad6009 3 года назад +1

    👍

    • @rahish135
      @rahish135 3 года назад

      Hi Fortinet Guru, Please explain Explicit proxy packet flow with LDAP authentication in Fortinet Firewall.