Find answers to your technical questions and learn how to use our products
Search suggestions:
Find answers to your technical questions and learn how to use our products
Search suggestions:
|
NAT Method
|
Description
|
|---|---|
|
STUN
|
STUN ("Session Traversal for NAT") is a mechanism to overcome the effect of some NAT firewalls. In summary:
|
|
TURN
|
TURN ("Traversal Using Relays around NAT") is a NAT traversal mechanism that works by relaying all traffic via a TURN server. This is typically a TURN service provided by the customer's SBC.
|
|
Field
|
Description
|
|---|---|
|
IP Office STUN Server
|
Default = Blank
The IP address or fully qualified domain name (FQDN) of the STUN server the IP Office should use. The system will send basic SIP messages to this destination and from data inserted into the replies can try to determine the type NAT changes being applied by any firewall between it and the ITSP.
|
|
Port
|
Default = 3478.
Sets the port to which the STUN requests are sent.
|
|
Run STUN
|
This button tests STUN operation between the system LAN using the settings above. The results are used to automatically fill the NAT fields with appropriate values discovered by the system. A
information icon is then shown against the fields to indicate that the values were automatically discovered rather than manually entered.
Before using Run STUN, the SIP trunk must be configured.
|
|
Run STUN on startup
|
Default = Off
This option is used in conjunction with values automatically discovered using Run STUN. When selected, the system reruns STUN discovery whenever the system is rebooted or connection failure to the SIP server occurs.
|
|
Field
|
Description
|
|---|---|
|
WebRTC Client STUN Server
|
Default = Blank (use
stun.freeswitch.org:3478)
Set the IP address or FQDN of the STUN server that the clients should use.
|
|
Port
|
Default = 3748
The port the clients should use for STUN.
|
|
WebRTC Client Turn Server
|
Default = Blank
This is used for solutions that use a TURN service configured on an SBC. It provides the IP address or FQDN of the TURN service.
|
icon is shown against the fields to indicate that the values were automatically discovered rather than manually entered.
|
Field
|
Description
|
|---|---|
|
Firewall/NAT Type
|
Default = Unknown
The settings here reflect different types of network firewalls. For descriptions of the various options, see the table below.
|
|
Binding Refresh Time (seconds)
|
Default = 0 (Never). Range = 0 to 3600 seconds.
To keep the firewall port open for incoming calls, the system can send recurring
SIP OPTIONS requests to the remote proxy terminating the trunk. This setting configures the frequency of those requests.
If you do not set a binding refresh time, you may experience problems receiving inbound SIP calls after a short period of normal operation.
|
|
Public IP Address (IPv4)
|
Default = 0.0.0.0
If no address is set, the system's LAN1 address is used.
|
|
SIP Registrar public ports
|
The public port values for UDP, TCP, and TLS.
|
|
Firewall/NAT Type
|
Description
|
|---|---|
|
Blocking Firewall
|
–
|
|
Full Cone NAT
|
A full cone NAT is one where:
|
|
Open Internet
|
If this mode is selected, the IP Office ignores settings obtained by STUN lookups. The IP address used is that of the IP Office system's LAN interface.
|
|
One-To-One NAT
|
This setting supports deployments where the IP Office is behind a NAT that performs IP address translation but not port mappings. All required ports must be open on the NAT.
When set to One-To-One NAT, the following configuration settings are applied and cannot be edited.
|
|
Port Restricted Cone NAT
|
Similar to a Restricted Cone NAT, but the restriction includes port numbers. Specifically, an external host can send a packet, with source IP address X and source port P, to the internal host only if the internal host had previously sent a packet to IP address X and port P. SIP packets needs to be mapped. Keep-alives must be sent to all ports that will be the source of a packet for each ITSP host IP address. If this type of NAT/Firewall is detected or manually selected, no warning will be displayed for this type of NAT.
Some Port Restricted NAT's have been found to be more symmetric in behavior, creating a separate binding for each opened Port, if this is the case the manager will display a warning ‘Communication is not possible unless the STUN server is supported on same IP address as the ITSP’ as part of the manager validation.
|
|
Restricted Cone NAT
|
A restricted cone NAT is one where all requests from the same internal IP address and port are mapped to the same external IP address and port. Unlike a full cone NAT, an external host (with IP address X) can send a packet to the internal host only if the internal host had previously sent a packet to IP address X. SIP packets needs to be mapped. Responses from hosts are restricted to those that a packet has been sent to. So if multiple ITSP hosts are to be supported, a keep alive will need to be sent to each host. If this type of NAT/Firewall is detected or manually selected, no warning will be displayed for this type of NAT.
|
|
Static Port Block
|
Use the RTP Port Number Range specified on the VoIP tab without STUN translation. Those ports must be fixed as open on any NAT firewall involved
|
|
Symmetric Firewall
|
SIP packets are unchanged but ports need to be opened and kept open with keep-alives.
|
|
Symmetric NAT
|
A symmetric NAT is one where all requests from the same internal IP address and port, to a specific destination IP address and port, are mapped to the same external IP address and port. If the same host sends a packet with the same source address and port, but to a different destination, a different mapping is used. Furthermore, only the external host that receives a packet can send a UDP packet back to the internal host. SIP Packets need to be mapped but STUN will not provide the correct information unless the IP address on the STUN server is the same as the ITSP Host.
|
|
Unknown
|
The type of NAT is unknown or could not be determined.
|
46xxsettings.txt file when requested by a remote phone.
|
Field
|
Description
|
|---|---|
|
Public IP Address (IPv4)
|
Default = Blank
The public IPv4 address that routes to the public/external side of the ASBCE. Depending on the customer network, this can be the public IP address of another device such as a firewall that forwards to the SBC.
|
|
Public IP Address (IPv6)
|
Default = Blank
As above but using an IPv6 address. Use of an IPv6 address is supported for:
For further information, see the Deploying Remote IP Office SIP Phones with an ASBCE manual.
|
|
Private IP Address (IPv4)
|
Default = Blank
The private IPv4 address of the ASBCE.
|
|
FQDN
|
Default = Blank
The fully-qualified domain name of the ASBCE. You must set this value.
|
|
SBC Registrar public ports
|
The public ports on which the ASBCE is configured to listen for incoming SIP call.
|