Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Connectivity Failure with SIP server: NAT and IOS Firewall

I have searched the community for the problem I am having (string: pre-generated session) and have found a number of unanswered questions regarding a similar issue to mine. Any assistance would accordingly be widely appreciated.

Platform: Cisco 877 ADSL Router
Software Version: C870 Software (C870-ADVIPSERVICESK9-M), Version 12.4(24)T1

Connectivity Problem Description: 
When the ISP resets the router ip address, ATM0 goes up and down and a new
address is acquired, the Lynksys SPA9000 is subsequently unable to register with the SIP
server. When the nat session is cleared the SPA9000 registers fine and all is OK until
the next ISP reset.


1. The IOS firewall pre-generates a new session with the new global source address

2. the NAT session between the old source IP address and the Sipgate server persists.

3. When I clear ip nat trans *, the problem is resolved, the pre-gen session disappears
and the SPA9000 resigsters.

How do I configure to make sure the old NAT session times out itself when the new
source IP address is acquired?

Setting the default NAT TCP timeout to less than 24 hrs may provide a solution but
it will not resolve the problem.  UDP NAT timeout is short, so this is possibly not
the problem.

I would be most grateful if you could suggest what may be sustaining the 'false' NAT session
with the old source IP address.  It is almost as if the firewall is proxying this session?

S_Router#sh ip inspect sis

Established Sessions
 Session 848FF6A8 (>( sip SIS_OPEN
 Session 848F7128 (>( udp SIS_OPEN
 Session 848F9AE0 (>( udp SIS_OPEN
 Session 848FDAD8 (>( smtp SIS_OPEN
 Session 848FB6B0 (>( tcp SIS_OPEN
 Session 84902328 (>( tcp SIS_OPEN
Half-open Sessions
 Session 848F7C48 (>( udp SIS_OPENING
 Session 848FB3E8 (>( udp SIS_OPENING
 Session 848F44A8 (>( udp SIS_OPENING
Pre-generated Sessions
 Pre-gen session 848F76B8[1024:65535]=>[1024:1024] sip

S_Router#sh ip nat trans

Pro Inside global         Inside local          Outside local         Outside global

* old Inside Global IP address

New Member

Re: Connectivity Failure with SIP server: NAT and IOS Firewall

Did you manage to get to the bottom of this problem and find a permanent workaround.  I am experiencing mildly similar issues.