Enabling SIP transformation makes the firewall non responsive.

Description

It is often necessary to enable SIP transformation if the PBX server is on Internet and the devices are behind the firewall.
It is disabled when the PBX server and endpoints are behind the firewall.


This document will help to resolve the issue if the  firewall freezes when SIP transformation is enabled

And therefore, no access to the firewall.



Cause

Main cause will be the misconfiguration on the firewall.

But customer can also check with the provider for SIP control ports and include these accordingly.


Resolution

Firstly, need to check if the settings are correct and where the PBX server is located.

Also, check the required ports/services which has to be enabled on the firewall as per the document from the provider.

Mostly, the issue is with the service object groups which are not required but have been added.

As an example, please see below:

-------VOIP Services-------
UUID: 00000000-0000-000b-0400-2cb8ed5e2840
properties: 0x0000000e
   member: Name:HTTP Handle:4
   member: Name:HTTPS Handle:6
   member: Name:DNS (Name Service) Handle:46
   member: Name:ICMP Handle:60
   member: Name:FWB 3478 TCP Handle:307
   member: Name:FWB 3478 UDP Handle:308
   member: Name:FWB 65061 TCP Handle:315
   member: Name:FWB 65061 UDP Handle:318


The above service includes HTTP, HTTPS, DNS and ICMP.
Firewall in SIP transformation will not transform anything on HTTP, HTTPS, DNS and ICMP.

And hence will unnecessarily generate too much traffic which will subsequently hang the device, once SIP transformation is enabled.

Removing the not required services from the group will fix the issue.

For reference:

How to configure VoIP to use any VoIP phone system (best practices) | SonicWall

Related Articles

  • SonicOS 8.1.0 FAQ
    Read More
  • SonicWall GEN8 TZs and GEN8 NSas Settings Migration
    Read More
  • Getting started with SonicWall firewalls
    Read More
not finding your answers?