Configuring SIP
SIP support
FortiGate Version 4.0 Administration Guide
434
01-400-89802-20090424
From the CLI you can configure additional SIP, SCCP, as well as SIMPLE extensions. For
more information, see the description of the
config sip
,
config sccp
, and
config
simple
subcommands of the
application
You can also block SIMPLE sessions by enabling block login for the SIMPLE application.
For more information, see
“Application Control” on page 523
.
Enabling SIP logging
You can log SIP events in a protection profile.
Go to
Firewall > Protection Profile
. Open an existing profile or select
Create New
to
create
a new profile. Expand
Logging
. Select
Log VoIP Activity
to log VoIP events.
For more information about enabling and configuring logging, see
Enabling advanced SIP features in an application list
You can configure advanced SIP features for an application list.
For more information, see the
.
Turning on SIP tracking
The FortiGate SIP ALG (Application Level Gateway) tracks the SIP session over its life
span. A SIP session (or SIP dialog) is normally established after the SIP INVITE
procedure. The ALG then tracks this call as a SIP session. A session can end by regular
BYE procedure, such as callers hanging up the phone, or by an unexpected signalling or
transport error.
You can continue tracking a SIP session for a specified period of time even when RTP
(Real-time Transport Protocol) is lost.
From the CLI, type the following commands:
config application list
edit <list_name>
config entries
edit 12
set call-keepalive <integer>
end
end
Managing RTP pinholing
Once you create a firewall policy that allows SIP, the FortiGate ALG will automatically
open the respective RTP ports as long as the SIP session is alive.
You can also manually close RTP ports. This may be useful in cases where the FortiGate
unit only acts as a signalling firewall while RTP is bypassed. Therefore, no pinholes need
to be created.
From the CLI, type the following commands:
config application list
edit <list_name>
config entries
edit 12
set rtp disable
end
end
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...