Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


3448 posts

Uber Geek
+1 received by user: 1204

Subscriber

Topic # 225403 16-Nov-2017 20:46
Send private message

So I have a super random fault with a SIP trunk. It's only cropping up very randomly and been really hard to get any decent info..

 

But I finally managed to make it fault with a packet capture running. My only annoyance was I did the capture off the PPPoE interface and not LAN bridge so I don't know what actually got to the LAN.

 

So the PBX receives an INVITE from the SIP proxy, but then right after that, the router "replies" with an "ICMP 590 Destination unreachable (port unreachable)"

 

I kind of take that for what it is, the port was unreachable. My thought process goes there was no state in the sessions table that matched so it couldn't get through the NAT.

 

Do people agree? Maybe just pull my registration timer (currently 120) and notfy timer (currently 30s) right down? Increase the UDP timeout (currently 1m) in the sessions table?

 

My main annoyance is this is my standard router config and a standard PBX config in use on 300+ other sites. Also a VERY basic network.


Create new topic
672 posts

Ultimate Geek
+1 received by user: 112


  Reply # 1903071 17-Nov-2017 00:52
Send private message

It’s late and havent really had much of a think on it but in the interest of helping I’ll throw my initial thoughts below:

My first thought is that you could be right, if the Nat is timing out just before it re-establishes the session it could mean the majority of calls work but the odd one drops.

Unreachable may not mean the Nat translation has expired it could also mean the packet couldn’t reach the destination, maybe the switch inbetween went down? Maybe there is a loop?

In order to narrow it down further we’ll need to know more about the problem.

What exactly happens? What specifically are you trying to fix?


672 posts

Ultimate Geek
+1 received by user: 112


  Reply # 1903072 17-Nov-2017 01:05
Send private message

Also, when you say he PBX receives the invite did you packet capture this on the PBX?

What are you doing while packet capturing? Initiating a incoming call?

The ICMP590 message in reply, is that going out the WAN to your SIP trunk provider? Where is this destined?



3448 posts

Uber Geek
+1 received by user: 1204

Subscriber

  Reply # 1903114 17-Nov-2017 08:20
Send private message

ArcticSilver: Also, when you say he PBX receives the invite did you packet capture this on the PBX?

What are you doing while packet capturing? Initiating a incoming call?

The ICMP590 message in reply, is that going out the WAN to your SIP trunk provider? Where is this destined?

 

The issue is incoming calls are failing - but only very randomly which is why I think it may be a timing issue.

 

Yea sorry should have been clearer. I only got a capture from the PPPoE interface. And I really wish I had something running on the PBX interface too because that probably would have been more interesting. The problem has been trying to actually capture the behavior because it is so random.

 

So I know the WAN interface of the router receives the INVITE, and the the router replies with the ICMP 590.


427 posts

Ultimate Geek
+1 received by user: 80


  Reply # 1903119 17-Nov-2017 08:38
Send private message

Without a packet capture from the PABX ethernet port it's hard to say exactly what the issue is. The ICMP unreachable message could be being generated by the PABX, obviously it will always come from the router when looking at a packet capture on the WAN port.




3448 posts

Uber Geek
+1 received by user: 1204

Subscriber

  Reply # 1903128 17-Nov-2017 09:14
One person supports this post
Send private message

Mattmannz:

 

Without a packet capture from the PABX ethernet port it's hard to say exactly what the issue is. The ICMP unreachable message could be being generated by the PABX, obviously it will always come from the router when looking at a packet capture on the WAN port.

 

 

 

 

Yep agreed. I've got a raspberry Pi with a network monitoring package on it that is going to let me run much more prolonged captures than I can do on the router. So will get that in place on a mirrored port to the PBX and see what's happening there.


854 posts

Ultimate Geek
+1 received by user: 53

Subscriber

  Reply # 1903147 17-Nov-2017 10:22
Send private message

If you can - set your NAT Session timeout timeout to 90 seconds on the router.

 

set qualify on your sip trunk - the default is 60 seconds for most devices when qualify is enabled. This will keep the UDP session in the nat translation table on your router.  Trying to set qualify below 60 seconds often wont help - because it wont be accepted in many cases its easier to set the Nat Session timeout higher. 


1531 posts

Uber Geek
+1 received by user: 379


  Reply # 1903150 17-Nov-2017 10:24
Send private message

Does the router have an IP helper for the SIP protocol?

854 posts

Ultimate Geek
+1 received by user: 53

Subscriber

  Reply # 1903152 17-Nov-2017 10:27
Send private message

MadEngineer: Does the router have an IP helper for the SIP protocol?
Agreed look for this if you havent already SIP ALG is always the first thing you should turn off.


1531 posts

Uber Geek
+1 received by user: 379


  Reply # 1903161 17-Nov-2017 10:50
Send private message

This is mikrotik specific but may be of interest: https://mum.mikrotik.com/presentations/US17/presentation_4321_1496084451.pdf as it has good explanations and example sniffs

251 posts

Ultimate Geek
+1 received by user: 46


  Reply # 1903166 17-Nov-2017 10:59
One person supports this post
Send private message

rphenix:

 

MadEngineer: Does the router have an IP helper for the SIP protocol?
Agreed look for this if you havent already SIP ALG is always the first thing you should turn off.

 

 

Turning off the SIP ALG is not a smart idea unless you known that is the issue. Turning off the SIP ALG may result in things like NAPT being applied to SIP traffic which will break everything SIP related. 


1531 posts

Uber Geek
+1 received by user: 379


  Reply # 1903172 17-Nov-2017 11:28
Send private message

^+1

Create new topic

Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

N4L helping TAKA Trust bridge the digital divide for Lower Hutt students
Posted 18-Jun-2018 13:08


Winners Announced for 2018 CIO Awards
Posted 18-Jun-2018 13:03


Logitech Rally sets new standard for USB-connected video conference cameras
Posted 18-Jun-2018 09:27


Russell Stanners steps down as Vodafone NZ CEO
Posted 12-Jun-2018 09:13


Intergen recognised as 2018 Microsoft Country Partner of the Year for New Zealand
Posted 12-Jun-2018 08:00


Finalists Announced For Microsoft NZ Partner Awards
Posted 6-Jun-2018 15:12


Vocus Group and Vodafone announce joint venture to accelerate fibre innovation
Posted 5-Jun-2018 10:52


Kogan.com to launch Kogan Mobile in New Zealand
Posted 4-Jun-2018 14:34


Enable doubles fibre broadband speeds for its most popular wholesale service in Christchurch
Posted 2-Jun-2018 20:07


All or Nothing: New Zealand All Blacks arrives on Amazon Prime Video
Posted 2-Jun-2018 16:21


Innovation Grant, High Tech Awards and new USA office for Kiwi tech company SwipedOn
Posted 1-Jun-2018 20:54


Commerce Commission warns Apple for misleading consumers about their rights
Posted 30-May-2018 13:15


IBM leads Call for Code to use cloud, data, AI, blockchain for natural disaster relief
Posted 25-May-2018 14:12


New FUJIFILM X-T100 aims to do better job than smartphones
Posted 24-May-2018 20:17


Stuff takes 100% ownership of Stuff Fibre
Posted 24-May-2018 19:41



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.