| Author |
Message |
kchung54
New Forum Member


Joined: Jan 09, 2005
Posts: 4
Location: Denver, CO USA
|
Hi all:
I'm new to this forum, Vonage & Voip. Does anybody have a similar setup as I do?
I'm particularly interested in hearing of people's successes/difficulties with a Cisco PIX 501. I can't seem to get my setup configured properly!
I currently have a static IP set on the ATA - should this matter? Will this make life easier/difficult for me?
My ATA "seems" to be plugged in and functioning normally. The LED for the phone is lit like it's supposed to, but I have no dial-tone. I can access the interactive voice prompts without issue!
Should the fixup protocols on the PIX help me here?
Any info/hints would be much appreciated!
Regards,
Kelvin |
|
|
|
|
 |
rebus
Vonage Forum Evangelist


Joined: Dec 04, 2004
Posts: 448
Location: Tampa Bay
|
|
|
|
 |
kchung54
New Forum Member


Joined: Jan 09, 2005
Posts: 4
Location: Denver, CO USA
|
Hi Rebus:
Thanks for the link -- I have already taken a look at this document, but this one does not address the issue that I only have a single IP on the outside world -- I have tried to set all the port forwarding, but have run into a bit of a snag with the fact that I am used to assigning static port forwards one port at a time. Do I really need to add a single line for each port forward between the range of 10000 and 20000?
Kelvin |
|
|
|
|
 |
kchung54
New Forum Member


Joined: Jan 09, 2005
Posts: 4
Location: Denver, CO USA
|
Ok, thought I'd add a little more information to see if this helps. I have the following object group defined:
object-group service Vonage udp port-object range 5060 5061 port-object eq domain port-object eq tftp port-object range 10000 20000
Then I have the following access list defined:
access-list OUTSIDE permit udp host 192.168.1.5 object-group Vonage interface outside object-group Vonage
Am I on the right track so far?
Then, I began defining my statics:
static (inside,outside) udp interface 5060 192.168.1.5 5060 netmask 255.255.255.255 0 0 static (inside,outside) udp interface 5061 192.168.1.5 5061 netmask 255.255.255.255 0 0 static (inside,outside) udp interface domain 192.168.1.5 domain netmask 255.255.255.255 0 0 static (inside,outside) udp interface tftp 192.168.1.5 tftp netmask 255.255.255.255 0 0 static (inside,outside) udp interface 10000 192.168.1.5 10000 netmask 255.255.255.255 0 0
...at which point I decided to seek help, because I MUST be doing something wrong -- I shouldn't have to define each port, do I? Is there a way to do this with ACL's instead?
Kelvin |
|
|
|
|
 |
sajer
Full Forum Member


Joined: Dec 16, 2004
Posts: 59
|
I am using a Voip service successfully behind a PIX firewall. It is not a Vonage Voip service, but that should not make a difference. I'm not the guy that configured the PIX, so I don't have all the details, but my setup is like this:
- ATA devices uses DHCP rather than static ip address - fixup sip protocol is turned on on the PIX - no port forwarding at all on the PIX
I know that Vonage recommends turning port forwarding on, but in many (most?) cases it works fine without it. I'm not sure whether that is going to work for you, but I would start with this minimal configuration -- which basically involves turning only sip protocol fixup on -- and then if it doesn't work try adding in port forwarding. |
|
|
|
|
 |
kchung54
New Forum Member


Joined: Jan 09, 2005
Posts: 4
Location: Denver, CO USA
|
Thanks Sajer, for the advice -- after I had posted parts of my config, I decided to go back and try to simplify everything as well!
So, I switched my ATA back to DHCP, where it pulls an IP just fine, and I removed all the additional configs that I put in.
My PIX has the two following fixups in place:
fixup protocol sip 5060 fixup protocol sip udp 5060
Are you able to verify if you have both these lines in your PIX?
Thanks again!
Kelvin |
|
|
|
|
 |
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum |
All times are GMT - 5 Hours | |