Log In

Come Join Us!

Are you a
Computer / IT professional?
Join Tek-Tips Forums!
  • Talk With Other Members
  • Be Notified Of Responses
    To Your Posts
  • Keyword Search
  • One-Click Access To Your
    Favorite Forums
  • Automated Signatures
    On Your Posts
  • Best Of All, It's Free!
  • Students Click Here

*Tek-Tips's functionality depends on members receiving e-mail. By joining you are opting in to receive e-mail.

Posting Guidelines

Promoting, selling, recruiting, coursework and thesis posting is forbidden.

Students Click Here


Sip aware firewalls as SIP Proxy

Sip aware firewalls as SIP Proxy

Sip aware firewalls as SIP Proxy

Hi Guys,

when we connect SIP trunks to the 3300 we always do it by using the MBG as a SIP proxy, this way we don't have that much headaches with SIP.

This weekend I was reading this from the Eng. Guidelines:

The 3300 ICP supports integration with SIP Firewalls. Mitel recommends that a SIP aware
Firewall be configured as the Outbound Proxy through the Network Elements form. Then the
SIP Peer Profiles can reference the Outbound Proxy Server and route all signaling via the

The ingate SIP Firewall is interoperable with the 3300 ICP based SIP solution. You can obtain
the Ingate product documentation at w.ingate_com. The Mitel SIP firewall product is the
MBG. Information is available on Mitel OnLine.

The question is: have any of you ever use a sip aware firewall as a sip proxy? Do one need to do any programing on the firewall? Is the programming on the 3300 the same as if we had the MBG (Network element and then include it in the Sip peer?




RE: Sip aware firewalls as SIP Proxy

I have used the Ingate firewall and there is considerable programming. The programming on the 3300 is the same.

RE: Sip aware firewalls as SIP Proxy

Never used one myself. Think SIP aware means a firewall that understands messaging and can pass it without issue once it has been configured.

I'd tell you a UDP joke but I'm afraid you won't get it. TCP jokes are the best because you always get them.

RE: Sip aware firewalls as SIP Proxy

Most of my SIP/3300 installs have direct SIP Peer connection to carrier (Windstream/Paetec); The carrier providing and programming any routers & firewalls involved.

RE: Sip aware firewalls as SIP Proxy

We have used SIP aware routers. The general issue is the SIP carrier will need a specific IP in the SIP header (more than likely the IP the SIP service authenticates with), however with some non SIP aware firewalls the internal IP of the handset / device making the call may be sent in the header and therefore the SIP carrier just drops the packets and the call fails.
As you say MBG gets around this, we have used some Cisco and Juniper firewalls to overcome, however this has been problematic.
We generally recommend the use of MBG however if the customer has a SIP aware firewall inplace and they are able to open the required ports and create the required NAT rules this is of course a cost saving as you dont need MBG, licences etc

Red Flag This Post

Please let us know here why this post is inappropriate. Reasons such as off-topic, duplicates, flames, illegal, vulgar, or students posting their homework.

Red Flag Submitted

Thank you for helping keep Tek-Tips Forums free from inappropriate posts.
The Tek-Tips staff will check this out and take appropriate action.

Reply To This Thread

Posting in the Tek-Tips forums is a member-only feature.

Click Here to join Tek-Tips and talk with other members!

Close Box

Join Tek-Tips® Today!

Join your peers on the Internet's largest technical computer professional community.
It's easy to join and it's free.

Here's Why Members Love Tek-Tips Forums:

Register now while it's still free!

Already a member? Close this window and log in.

Join Us             Close