Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

SIP trunk ideal / Timeout issue with ASA firewall

Hi,

We are having SIP trunk for Enterprise LYNC Voice functionality. The LYNC servers are behind ASA firewall. when the call is initiated traffic comes via SIP trunk to firewall & then to LYNC servers & to users using LYNC client on system.

 

We are facing issue like during starting hours of business , we observe that SIP trunk being ideal. means when we try to call from outside to LYNC client in our network , call is not successful. when trying for 3-4 times continuously call gets connected & then it start working normally .

 

i want to detect why call is not connecting in 1st attempt ?  when we check logs on firewall, when the 1st call initiated we didn't see any SIP/RTP traffic on firewall & once call connected RTP traffic seems flowing normally .

 

The SIP timeout values are default (30 mins)

 

timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
  inspect sip

 

I checked some cisco documentation where cisco advice to configure layer 7 SIP OPTIONS ping . but i am not sure how to configure that.

Can anyone help me out with this issue ?

 

6 REPLIES

Vinayak,You can try

Vinayak,

You can try configuring Qos in ASA to prioritize the voice traffic.

 

Regards

Karthik

New Member

Hi Karthik, The QOS is

Hi Karthik,

 

The QOS is already configured on EDGE switch where the SIP trunk & firewall connected. the call flow works fine but facing issue only connecting for the 1st time.

Hi Vinayak,Do you have the

Hi Vinayak,

Do you have the Qos set in ASA for the same? We have the similar setup working fine with the Qos setup in switches as well as on the ASA, which flows through the tunnel.

 

Regards

Karthik

New Member

Hi Karthik,i am not sure

Hi Karthik,

i am not sure about QoS on firewall . can you please tell me how to implement qos on firewall.

Hi Vinayak,You can refer the

Hi Vinayak,

You can refer the below mentioned document for your scenario if that helps.

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/82310-qos-voip-vpn.html

 

Regards

Karthik

New Member

Re: Hi Vinayak,You can refer the

yes.

object-group service sip udp
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
inspect sip

687
Views
0
Helpful
6
Replies
CreatePlease login to create content