Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Rhinorhino on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN Phones cannot connect

Status
Not open for further replies.

Gorellana

IS-IT--Management
Joined
Dec 19, 2012
Messages
14
Hi, once again i need to ask you for support on this configuration issues on the Avaya IPO 500 V2, I performed a test a week ago, going from my ISP directly to the central via the WAN port and the connection from the outside was successfull.

However, now i cannot connect to it form outside my network.

I have been doing several test, and when I set a PC on the IP that i´m giving to the IPO, i can ping the pc remotely and it responds via the ip, but once i place the cable on the IPO, the ping stops and the phones are not connecting, is there a configuration guide i should see or something i'm missing?

As stated before, i'm an IT specialist, but i have little to none knowledge on Avaya VoIP technology and configuration.

here is some extra explanation on what i have set up:
-Avaya IPO
** LAN IP: 11.0.0.15
** WAN IP: 200.31.4.4 (for example)
The WAN port is connected directly to my ISP router, using one of my public IP assigned

On the config file of the IPO, i have Lan 1, the values described before, on Lan 2, the address described before and the mask according to my isp public IP provided.

I´d like to have some way to fix this and to check if everything is ok.

Thanks on advance!
 
do you have an IP route in the IPO that is like this
IP 0.0.0.0
mask 0.0.0.0
LAN2
your gateway for LAN2 aka you ISP (Example 200.31.4.x)

Joe W.

FHandw, ACSS (SME), ACIS (SME)



Give a tech a solution and he will be back tomorrow to ask you the next question, teach a tech how to read the manual and he will be able to solve the problems for a life time.
 
Hi Westi, yes i do have that route, also i have been watching LAN 2 info and it has the following:
IP address: Public IP assigned by my ISP 200.31.4.4
IP Mask: Mask provided by ISP 255.255.255.248
Primary trans IP address: GW of my ISP 200.31.4.3

IP route: 0.0.0.0
IP mask: 0.0.0.0
GW IP address: 200.31.4.3
Destination: Lan 2

Using this settings i cannot hit my IPO from the outside with ping
 
If you have assigned the system a public IP then you can't use the VPN function on IP phones, also if you are trying a straightforward IP phone connection to the external address that will not work either as user side NAT will break it :-)


Avaya Implementation Qualified Professional Specialist Technical Engineer (AIQPSTE)
 
We had an Issue with Phones connecting to our IPO from a Remote Office. We were not using the LAN2 Interface, but we had a Site to Site VPN and the Phone was behind the Remote VPN Link.

Connectivity was good, though the Phone would stick in Discover mode forever.

You didn't mention what the Phone was actually doing so I'm not sure where in the Process of registering the phone it is failing.

The provider we were using (Comcast) was Blocking packets that had Specific QoS Tagging, Specifically the DiffServ Settings for SIG DSCP 34 (System, LAN, VoIP, DiffServ). Any Packet with 34 DSCP tag on it (even though it was embedded in a VPN Tunnel as the QoS Tag is placed on the Encoded Tunnel Packet) the ISP Dropped the Packet.

We ended up having to Change to SIG DSCP 26 and the Remote Phones would then be able to Register.

Scott<-
 
Hi, thanks to all for your answers!

I've managed to get the problem solved somehow, but i need to know if what I did will be enough.

I placed the LAN2 connection into a paralel exit from my ISP, so i'm no longer behind the NAT, however i have some questions, and maybe if you can assist me i could end this assignment:

[ol 1]
[li]How many phones can i connect this way, i mean is there a limit?[/li]
[li]Is there a way to ensure calls quality, or to improve it?[/li]
[li]I believe this is a network hazard, however it was the only way I figured how to do it, is there some other way?[/li]
[li]If there is some sort of prject regarding this kind of need, to place remote phones on different locations, could someone give me some advise?[/li]
[/ol]

Best regards and thanks for your assistance!
 
We have a Cisco ASA5510 Head end Firewall. We have Several remote Sites that all use either a Cisco PIX 506, ASA5510 or a RV220W to remote into the Corp Site. Every device behind the Remote VPN appliance is behind it and thus has secure access to the Corp Network. This includes all of the Phones at the site. Many have 1-2 phones, though one site has 12 or more all using the VPN Link to access the IPO. No need to place the IPO on a Public IP and it is secured behind a firewall.

Scott<-
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top