K
K
Kirill 12015-04-13 11:57:03
Asterisk
Kirill 1, 2015-04-13 11:57:03

Connecting via SIP through a tunnel, how?

Good afternoon, there is an Asterisk server in the central office currently working on E1, there is a desire to leave E1 for SIP, one of the Big Three operators offers connection via SIP, but only if the facility has their Internet connected.
A remote object, a connection is made to the router from a provider where there is a SIP connection.
The task from the central office through the tunnel to go to this SIP.
Now I'm training on cats: I'm trying to get Asterisk to connect via SIP to zadarma servers through a remote router.
In the office, I put in (Mangle) traffic from the server via UDP on ports 5060, 5061, 10000-20000 from the server and set it on a remote router, in the firewall I specify from the remote server to allow access to the list of servers.
Authorization does not pass, i.e. asterisk (actually, I tried it from a working machine through a SIP client) does not connect.
If you also turn everything with icmp, then the pings are wrapped through remote control.
Tell me, maybe I'm somewhere, I'm not finishing something?

Answer the question

In order to leave comments, you need to log in

4 answer(s)
C
Cyril 1, 2015-04-14
@SmileyK

Dmitry Luponos : 3d1d0e3244e6423487075e76c3cd09e1.pngI have zadarma as a test until the operator pulls out his output via SIP (why the operator is because the multi-channel number is promoted)
So the problem still persists, if I turn on the soft background from the PC according to this scheme, then it will log in to the SIP zadarm server 's, but Asterisk does not want to log in and work in this scheme ...
in fact, only this is poured into the logs on asterisk

[2015-04-14 10:56:52] NOTICE[2024] chan_sip.c: -- Registration for '[email protected]' timed out, trying again (Attempt #3224)
until I understand where the problem is...
Although in PBX it displays something else, 6919007f58ee483e8ae352d8343c10c5.pngbut in the personal account zadarma does not show that it is connected, damn it, does anyone have any ideas?
we continue: for some reason, a strange thing, if I do tracert from the asterisk server, it is lost somewhere on the hops of the provider
[[email protected] ~]# tracepath sip.zadarma.com
 1:  1.1.1.17 (1.1.1.17)                                0.261ms pmtu 1500
 1:  1.1.1.3 (1.1.1.3)                                1.288ms
 1:  1.1.1.3 (1.1.1.3)                                2.400ms
 2:  1.1.1.3 (1.1.1.3)                                2.186ms pmtu 1430
 2:  1.1.2.11 (1.1.2.2)                           29.142ms
 3:  ххххх.synterra-ug.ru (ххх.ххх.ххх.ххх)      30.127ms asymm  4
 4:  xxx..ti.ru (ххх.ххх.ххх.ххх)              30.349ms asymm  5
 5:  xxx..ti.ru (ххх.ххх.ххх.ххх)          53.029ms
 6:  xxx..retn.net (ххх.ххх.ххх.ххх)            45.125ms
 7:  xxx..retn.net (ххх.ххх.ххх.ххх)         69.101ms asymm  9
 8:  xxx..retn.net (ххх.ххх.ххх.ххх)                      69.147ms asymm  7
 9:  xxx..deac.net (ххх.ххх.ххх.ххх)              69.166ms asymm  8
10:  no reply
11:  no reply
12:  no reply
13:  no reply
14:  no reply

it is strange and with asteriska plugging on this address gate09.zadarma.com (178.16.26.122) resolves with sip.zadarma.com although when choosing a tracer to a different address everything goes great .... (
zadarma is just as badly reached through the proxy server, but it can be reached,
asterisk in the central office connected through a remote branch, phew.
Thanks to everyone who took part.

A
Armenian Radio, 2015-04-13
@gbg

It is most reliable to put an intermediate asterisk at the entry point to the tunnel.
Well, do not forget that this configuration is, in fact, enabling asterisk through NAT. If you have a gray ip, you get a chain of two NATs, through which Asterisk usually does not work.

V
Vladimir, 2015-04-13
@rostel

  1. build a tunnel to the remote one in any way
    c p.4 the main ambush:
    if there are other operators accessed through another NAT, asterisk with chan_sip will never understand this, i.e. two external IPs can only be provided if a smart router is able to edit SIP headers normally.
    chan_pjsip seems to be capable, but I haven't personally tested it.

D
Dmitry Luponos, 2015-04-14
@Bessome

solved a similar problem (TDE100 + remote office) by forwarding the network over VPN
habrahabr.ru/post/218367

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question