cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1445
Views
0
Helpful
1
Replies

SIP Inspection Issue on FWSM

cco1
Level 1
Level 1

Hi everyone,

we've got a problem regarding the SIP Inspection Protocol Helper on the FWSM (Firmware 4.0(10)).

When initiating phone calls via VoIP(SIP), users reported a delay of about 2 secs before hearing the dial tone.

Looking at the firewall logfile at that time reveals Deny-Messages for the RTP-Data between our VoIP-Server

and the VoIP-Provider's gateway. They last exactly the same time (about 2 secs), the users told us:

09:18:12: Deny udp src vlan123:<IP-VoIP-Provider-Gateway>/1234 dst vlan456:<IP-Our-VoIP-Server>/56789 by access-group "abc" [0x0, 0x0]
09:18:12: Deny udp src vlan123:<IP-VoIP-Provider-Gateway>/1234 dst  vlan456:<IP-Our-VoIP-Server>/56789 by access-group "abc" [0x0,  0x0]
(...)

09:18:15: Deny udp src vlan123:<IP-VoIP-Provider-Gateway>/1234 dst  vlan456:<IP-Our-VoIP-Server>/56789 by access-group "abc" [0x0,  0x0]

09:18:15: Deny udp src vlan123:<IP-VoIP-Provider-Gateway>/1234 dst  vlan456:<IP-Our-VoIP-Server>/56789 by access-group "abc" [0x0,  0x0]

After that 2 seconds, we can see no more Deny-Messages. When doing a packet-capture, we even see

normal traffic between the Server and the Gateway.

So it seems, that when using the SIP Inspection Engine on the FWSM, we always have a delay, before the

FWSM dynamically generates the ACEs needed for the RTP-Data.

My question to you is, have you ever seen that behaviour of your Firewall?

Does anyone know, if it's just the lame SIP Protocol Helper, that needs a few secs for creating ACEs?

Or is it a bug and should be treated by the TAC-guys?

Thanks in advance!

Regards,

Marco

1 Reply 1

Jennifer Halim
Cisco Employee
Cisco Employee

As you are already running quite the latest version of FWSM (4.0.10), the current latest is 4.0.11, it seems that it might be a new bug that needs to be investigated further by TAC.

I would suggest that you open a TAC case to get it further investigated. Thanks.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: