Registration/Voice issue over standard IPSec VPN

Unanswered Question
Oct 1st, 2009

Here is another VPN issue i have noticed:

I connected an SR520 to a UC520 with a standard site-to-site VPN crypto-map. I put a 524SG phone at the remote site, and it would not register to the UC520. I then replaced the crypto map configuration with an IPSec Tunnel configuration, and it fired right up. Any idea why the cryptomap setup didnt work with the 524SG phone? I have noticed this twice now. I have either used an ipsec tunnel or a DMVPN config to fix it. My configs are 'standard' and fairly simple, and all other traffic is fine. So it has to be something voip specific that I am missing. I am using routemaps to deny NAT/PAT, specifying the correct interesting traffic, everything i can think of is fine. I have setup tons of VPNs.

I ask because now I am having an issue at another site, with Panasonic VOIP phones and Cisco 871 routers. There is a crypto map ipsec vpn between two sites, all traffic flows ok, but there is no audio when a call connects on the phones. Am I missing something in my crypto map configs that would relate to voip connections getting lost?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading. Tue, 10/06/2009 - 08:53


I also included my CBAC inspection config, wasn't sure if that had something to do with it. I noticed that it is creating inspection sessions when the systems attempt to connect through the VPN, wasn't sure if that was an issue or not. Since I want to allow all traffic through the VPN, should it be excluded from inspection some how?

Attachment: Tue, 10/06/2009 - 12:10

The config i posted is actually from an 871, not an SR520. But i think i've had similar issues on both. Here are both versions:

Cisco IOS Software, C870 Software (C870-ADVIPSERVICESK9-M), Version 12.4(15)T9, RELEASE SOFTWARE (fc5)
Technical Support:
Copyright (c) 1986-2009 by Cisco Systems, Inc.
Compiled Wed 29-Apr-09 05:52 by prod_rel_team

ROM: System Bootstrap, Version 12.3(8r)YI4, RELEASE SOFTWARE

Corp871 uptime is 3 weeks, 3 days, 17 hours, 6 minutes
System returned to ROM by power-on
System restarted at 18:03:18 PCTime Fri Sep 11 2009
System image file is "flash:c870-advipservicesk9-mz.124-15.T9.bin"

Cisco IOS Software, SR520 Software (SR520-ADVIPSERVICESK9-M), Version 12.4(20)T3, RELEASE SOFTWARE (fc2)
Technical Support:
Copyright (c) 1986-2009 by Cisco Systems, Inc.
Compiled Wed 29-Apr-09 08:15 by prod_rel_team

ROM: System Bootstrap, Version 12.3(8r)YI5, RELEASE SOFTWARE

SR520-DEBBIE uptime is 2 weeks, 6 days, 18 hours, 47 minutes
System returned to ROM by reload at 20:27:15 PDT Sun Mar 10 2002
System restarted at 15:16:17 PDT Tue Sep 15 2009
System image file is "flash:sr520-advipservicesk9-mz.124-20.T3.bin"
Last reload reason: Reload Command

Steven Smith Tue, 10/06/2009 - 12:45

Could you do a couple of things for me?

Could you post the appropriate section of the UC500 config?  Also, I have seen a case where upgrading an SR520 to 12.4.24T1 from 12.4.20T2 fixed the issue.  I don't have a bug ID for it, but I am looking for one.  Would you mind upgrading to that version of SR520 code?




This Discussion

Related Content