ass17 Posted May 15, 2017 Posted May 15, 2017 Hi All, We have a dilemma, we are moving away from ISDN to SIP for phones but we don't want to route it through smoothwall, we want to keep the phones on 100% of the time. BT will not allow us to modify the Cisco router config to go through it direct and block specific incoming traffic etc... What are our options? Have you created a secondary firewall/gateway on spare IPs? We are thinking of buying either second hand Cisco router or build a custom Linux box. Has anyone done similar or offer advice? Thanks
SchoolsBroadband Posted May 15, 2017 Posted May 15, 2017 Have you thought of putting sip on a separate broadband line e.g fttc and a big standard firewall? You may also want to look at end to end qos to guarantee call quality. We do all of that as standard so let me know if of interest. Thanks a good luck. Dave
ass17 Posted May 15, 2017 Author Posted May 15, 2017 (edited) Thanks Dave, Don't think the budget stretches that far. We have a well designed network with QoS Voice on high priority. And all our VoIP Avaya phones are connected to 2920 HP switches. When BT turn us over we need either an additional firewall that is independent of our main firewall, one reason is for maintenance and many others I'm sure. Edited May 15, 2017 by ass17
localzuk Posted May 16, 2017 Posted May 16, 2017 We route our SIP traffic through our Sophos UTM. Not had any issues - no noticeable latency added to calls etc...
DSapseid Posted May 16, 2017 Posted May 16, 2017 I have my SIP running through a separate BT Infinity connection (£30ppm) which even when paying for this cost the savings on the actual calls and the line rental saved from ISDN and I'm still noticing a 20% saving per month.
ass17 Posted May 16, 2017 Author Posted May 16, 2017 We route our SIP traffic through our Sophos UTM. Not had any issues - no noticeable latency added to calls etc... Is Sophos your main firewall or a secondary? If Sophos is you main when happens when you do maintenance on it and the phones go down?
localzuk Posted May 16, 2017 Posted May 16, 2017 (edited) Is Sophos your main firewall or a secondary? If Sophos is you main when happens when you do maintenance on it and the phones go down? Main firewall. Maintenance happens out of hours only - there's no-one in to need the phones at 3am in the morning on a Saturday/Sunday night. My thought would be if that phone uptime is so important, maybe you should invest in a HA cluster of Smoothwall boxes? That way you can do maintenance on one and the other will take over. Edited May 16, 2017 by localzuk
FN-GM Posted May 16, 2017 Posted May 16, 2017 We send our SIP trunks via our perimeter firewall then through Smoothwall. No issues at all. Updates etc also happen out of hours so we don't go cutting the internet / phones off for people.
ass17 Posted May 16, 2017 Author Posted May 16, 2017 Main firewall. Maintenance happens out of hours only - there's no-one in to need the phones at 3am in the morning on a Saturday/Sunday night. 3am!! Do you get paid enough to warrant being up or do you schedule at that time hoping all is well when you wake up? [emoji1]
localzuk Posted May 16, 2017 Posted May 16, 2017 3am!! Do you get paid enough to warrant being up or do you schedule at that time hoping all is well when you wake up? [emoji1] All scheduled. With the number of devices we have, compared to staff, it'd be impossible to babysit all updates on all servers etc... So, scheduling is a necessity.
ass17 Posted May 16, 2017 Author Posted May 16, 2017 My thought would be if that phone uptime is so important, maybe you should invest in a HA cluster of Smoothwall boxes? That way you can do maintenance on one and the other will take over. This option is one we have been thinking about for some time but again cost could be a few thousand.
ass17 Posted May 16, 2017 Author Posted May 16, 2017 We send our SIP trunks via our perimeter firewall then through Smoothwall. No issues at all. Updates etc also happen out of hours so we don't go cutting the internet / phones off for people. Why not direct through smoothwall?
mrbios Posted May 16, 2017 Posted May 16, 2017 Why won't BT change any settings on the Cisco? My FreePBX box uses its built in firewall and has a direct connection from VM > ISP router with a public IP on the PBX external interface. No NAT to traverse and less components between phone system and external world in the event of any issues.
FN-GM Posted May 16, 2017 Posted May 16, 2017 @ass17 Our network topology means all internet traffic goes via 2 firewalls.
ass17 Posted May 16, 2017 Author Posted May 16, 2017 Why won't BT change any settings on the Cisco? My FreePBX box uses its built in firewall and has a direct connection from VM > ISP router with a public IP on the PBX external interface. No NAT to traverse and less components between phone system and external world in the event of any issues. We asked them and they said no, they won't support us if we change it.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now