Uploaded image for project: 'FreePBX'
  1. FreePBX
  2. FREEPBX-21102

Firewall does not create rule for networks in "Match (Permit)" on PJSIP trunks

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Open
    • Priority: Minor
    • Resolution: Unresolved
    • Affects Version/s: 14
    • Fix Version/s: None
    • Labels:
      None
    • Asterisk Version:
      16
    • Distro Version:
      12.7.6-1910-1.sng7
    • Distro:
      FreePBX Distro

      Description

      When pjsip trunks are created, the SIP server address gets an "ACCEPT" rule in the 'fpbxsmarthosts' chain in the firewall, but addresses in the "Match (Permit)" field do not. (in PJSIP Settings > Advanced). 

      For providers such as VoIP Innovations with multiple origination servers, this will result in only calls that come in via the primary server being answered by Asterisk, whereas any calls coming from Secondary, Tertiary, etc will not make it to Asterisk.

      Workarounds are to either add all the provider's servers in the firewall networks manually, or enable Responsive Firewall which will allow Asterisk to decide whether to accept or reject the traffic. 

        Gliffy Diagrams

          Attachments

            Activity

              People

              • Assignee:
                Unassigned
                Reporter:
                ngingras Nathan Gingras
              • Votes:
                1 Vote for this issue
                Watchers:
                6 Start watching this issue

                Dates

                • Created:
                  Updated:

                  NextupJiraPlusStatus

                  Error rendering 'slack.nextup.jira:nextup-jira-plus-status'. Please contact your Jira administrators.