Jaan Posted February 24 Posted February 24 (edited) Morning everyone. I'm looking for some insight from those running VOIP traffic through a Sophos XGS. We recently migrated our VOIP solution from a dedicated 2nd gateway to passing through our XGS, and it’s been a struggle. This struggle is well documented online when using VOIP with a XGS. Current Config: VOIP VLAN on a dedicated FW rule (No Web Filtering, IPS, or App Control, no port restrictions out). SIP Helper/ALG disabled via Sophos CLI. UDP timeouts adjusted per Sophos/VOIP Supplier best practices. The Issue: Despite these changes, we’re seeing dropped calls and "No Service" errors on 70% of handsets today. Phones have valid IPs and are reachable, but won't come "back online" even after a reboot. I'm currently caught in a finger-pointing loop between my VOIP supplier and Sophos support. Has anyone dealt with similar stubbornness on the XGS? Is there a "hidden" setting I’m missing, or does this sound like a carrier-side outage? Any input would be great Current module config on XGS; Edited February 24 by Jaan
Wave9_Lee Posted February 24 Posted February 24 We don't see any issues when using Sophos XGS with Voip - on the contrary. you already have an allow any rule on you VLAN So to help rule out LAN issues you could configure a port directly on the XGS and plug a phone(s) in and/or during a quiet period, bypass the XGS and plug a phone(s) directly into your ISP router? Do you have a backup connection you could use for elimination purposed? I would advise having a backup connection in any case and particuarly if you have VoiP.
Jaan Posted February 24 Author Posted February 24 We do have a back up line...... connected to the xgs 😁 connecting a phone to a 5g router works fine.... currently have about approx 30 phones working and 30 phones not.... one of those days.... non of the phones are hitting a block rule on the firewall. Infact all i see is allow. Rebooting the xgs brought some back online and other offline.....
lg-wave9 Posted February 24 Posted February 24 (I'm sure you've checked this, sorry to be obvious), but is the XG doing DHCP for this VLAN? Is there anything else that could be giving out DHCP leases for the same scope? If the XG is doing DHCP for the phones, do you see a non-working phone in the DHCP lease table? (Network->DHCP, IPv4 leases). If the MAC addresses are seen by the firewall, try an allow-all with the source MAC of a phone that's not working. 1
Jaan Posted February 24 Author Posted February 24 (edited) DHCP & DNS are managed via Windows Server. All handsets (working and non-working) are receiving correct leases and updating DNS records as expected. Ping is successful to all handsets. The web management portals for all phones are accessible over the network. Using the phones onboard diagnostic tools, both functional and non-functional phones can successfully ping external targets (e.g., 8.8.8.8). The VoIP VLAN is currently bypassed by the Web Filter, Application Control, and IPS. Firewall logs show traffic hitting the explicit "Allow All Outbound" rule for this VLAN. The core issue is inconsistency. While the network environment and security policies are identical for all devices on this VLAN, a subset of phones remains non-functional while others operate normally. is it friday yet? Edited February 24 by Jaan
NegativeKillDeath Posted February 24 Posted February 24 Do the subset of phones have anything in common? Same switch or building location? Could it be a switch port has lost its VLAN settings after a power blip?
Jaan Posted February 24 Author Posted February 24 nope its random. IP addresses for voip phones are given once the switch drops them on vlan60 via lldp-med. No phones are on our other ipranges
lg-wave9 Posted February 24 Posted February 24 Have you got two WAN links which are active, by any chance? If so, try an SD WAN route for that VLAN to send all the traffic out of one link only (to rule out asynchronous routing) 1
Jaan Posted February 24 Author Posted February 24 Great minds....already tried this to pass all the voip through our back-up wan..no change, just the external ip changed on our pbx for the phones that worked... i could try a rule to force just on our primary
lg-wave9 Posted February 24 Posted February 24 Hi there, Do you have a LAG on the LAN set? If so, and you remove one of the cables from that LAG, does that make any difference? (not sure if you'd need to restart a phone or two, but... just a thought).
Jaan Posted February 24 Author Posted February 24 No change. Tried both links.... at least i've tested that works now lol
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now