Inspecting VoIP Traffic
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.40 Locally Managed Administration Guide | 183
n
Phones are connected via VPN Site to Site
.
n
Phones are connected by VPN Remote Access
.
n
Phones are configured with public IP
.
The network objects appear in a table, with a Group name.
Click
New
to add an item.
Select an item and click
Remove
to delete it.
7. Click the
SIP Service
heading to expand the section.
Select the
SIP UDP/TCP ports
, which by default are 5060.
All phones should be configured to use the configured ports.
Click
New
to add a new SIP service.
Click
Remove
to delete a service.
After you apply these settings, rules are automatically created in the
Firewall Access Policy
page for
Outgoing access to the Internet
and
Incoming, Internal and VPN traffic
.
Notes:
n
For an on-premise configuration without PBX, the destination should be the
IP_Phones
object.
n
If you allow access to the PBX portal, another rule is created:
Source
Destination
Application /
Service
Action
Log
Comment
Any
PBX-Server
HTTP/S
Accept
None
Generated rule: SIP
VOIP
Forwarding rules are automatically created in the
Access Policy
>
NAT Rules
page.
Note - For external phones with remote access, the Office Object is automatically created in the
Network
Objects
section and the "
set back connection
" setting is set to "
true
".
Follow these configuration procedures to allow SIP traffic to pass through the gateway when:
n
The SIP server is located on external networks. For more advanced topologies, refer to
.
n
The gateway's NAT configuration is set to its default settings (with internal networks hidden behind its
external IP address).