Untangle Networks [home]


Go Back   Untangle Forums > Application Forums > Firewall

Closed Thread
 
LinkBack Thread Tools
Old 02-02-2010, 06:46 PM   #1 (permalink)
Untangler
 
Join Date: Apr 2009
Posts: 39
coreybrett is on a distinguished road
Question Firewall not blocking a SIP phone

I’m really confused.

I have the default action of UT firewall set to “Block”.

I have a few rules to allow the basics (HTTP, HTTPS, POPS, IMAPS, etc).

Even when I disable all my rules, my SIP phone is able to make and receive calls.

My computer (connected to the same switch as the phone) is unable to access the web at all while those rules are disabled.

I even disabled the rules, and restarted the UT box, and the phone was able to work after the UT box came back up while my computer was not.

After enabling the rules my computer can connect as normal, the point being, I know the rules and firewall are working, I just don’t understand my the phone is.

I assumed I would need to open the ports used for SIP, but apparently not (I can’t even block them).

Could someone explain this please?

The reason I even care is because I am in the process of learning/deploying a SIP PBX.
coreybrett is offline  
Old 02-02-2010, 06:51 PM   #2 (permalink)
Master Untangler
 
Join Date: Aug 2008
URLs submitted: 2
Posts: 304
Danp is on a distinguished road
Default

There's a SIP Helper in UT, which is probably enabled and that is allowing the SIP traffice to pass. Try disabling it.
Danp is offline  
Old 02-02-2010, 06:53 PM   #3 (permalink)
Untangler
 
Join Date: Apr 2009
Posts: 39
coreybrett is on a distinguished road
Default

Where would I do that?
coreybrett is offline  
Old 02-02-2010, 07:25 PM   #4 (permalink)
Master Untangler
 
Join Date: Aug 2008
URLs submitted: 2
Posts: 304
Danp is on a distinguished road
Default

From the wiki: http://wiki.untangle.com/index.php/VoIP_FAQs
Danp is offline  
Old 02-02-2010, 07:32 PM   #5 (permalink)
Untangler
 
Join Date: Apr 2009
Posts: 39
coreybrett is on a distinguished road
Default

You rock! Thanks, I should have looked for “VOIP” not “SIP” in the wiki.
coreybrett is offline  
Old 02-02-2010, 11:05 PM   #6 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 7
Posts: 9,951
sky-knight is on a distinguished road
Default

The SIP Helper isn't involved here. But SIP and IAX are bypassed by default so no rack rule will work.
__________________
Intouch Technology
Rob Sandling, BS:SWE, MCP
Office: 480-272-9889
rob@intouchtechllc.com
sky-knight is online now  
Old 02-03-2010, 03:05 PM   #7 (permalink)
Master Untangler
 
Mathiau's Avatar
 
Join Date: Feb 2008
Location: Costa Frickn' Rica
Posts: 824
Mathiau is on a distinguished road
Send a message via AIM to Mathiau Send a message via MSN to Mathiau Send a message via Yahoo to Mathiau
Default

So you would have to make a specific block rule for it then?
Mathiau is offline  
Old 03-31-2010, 06:35 PM   #8 (permalink)
Untangler
 
Join Date: Jul 2008
Posts: 30
xsara is on a distinguished road
Default

Quote:
Originally Posted by sky-knight View Post
The SIP Helper isn't involved here. But SIP and IAX are bypassed by default so no rack rule will work.
I'd like to block SIP and IAX traffic from all incoming destinations but our own company IPs. I don't want to remove these from the Bypass rules in the even that it effects VoIP performance?

Any advice?

Cheers
xsara is offline  
Closed Thread

Tags
firewall not working, sip

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:51 PM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.3.2