I've been trying to get my head around this.
Just noticed today that my SIP trunk isn't registreing at the provider.
The Asterisk log only shows timeouts, and I can't see anything in the logs on Sophos.
[2017-10-08 21:25:33] NOTICE[2462] chan_sip.c: -- Registration for 'xxxxxxxx@sip.viptel.dk' timed out, trying again (Attempt #4)
[2017-10-08 21:25:33] NOTICE[2462] chan_sip.c: -- Registration for 'yyyyyyyy@sip.viptel.dk' timed out, trying again (Attempt #4)
[2017-10-08 21:25:53] NOTICE[2462] chan_sip.c: -- Registration for 'xxxxxxxx@sip.viptel.dk' timed out, trying again (Attempt #5)
[2017-10-08 21:25:53] NOTICE[2462] chan_sip.c: -- Registration for 'yyyyyyyy@sip.viptel.dk' timed out, trying again (Attempt #5)
The SIP module is loaded on Sophos (tried unloading it which changed absolutely nothing)
Any ideas to test?
Hi Mortem
please have a look at this Thread, maybe you're hit by IPS Module as well ;)
Yours Lukas
lna@cema
SCA (utm+xg), SCSE, SCT
Sophos Platinum Partner
I see nothing in the logs that indicate anything have been blocked from Asterisk.
And the server that is running Asterisk is hit by a firewall (above normal LAN-to-WAN rule) that disables IPS, APS and web filter for clientless servers.
Regards,
Morten Trab
Hi,
I get traffic blocked when the DOS attacks is enabled, but nothing shows in the logs. When I disable DOS attacks, traffic flows, downside is this enable/disable for the entire XG not just a rule.
Ian
XGS118 - v21.5.0
XG115 converted to software licence v21.5.0
If a post solves your question please use the 'Verify Answer' button.
This make no sence to me - but ...
Disabled and re-enabled DoS protection, and now it works.
Regards,
Morten Trab