NetTalk with ASA Firewalls

I have been dealing with issues with NetTalk not working as expected with my ASA5505. Symptoms I have seen are it will work for a bit with a solid green and then green would start blinking indicating connections are blocked by firewall and eventually it will turn red and can’t receive inbound or make outbound calls.

Tonight I decided to look more into it.

So far have made following changes

1. Disable SIP inspection in default global policy

2. Created translations for ports 5085, 12000 and 12001 and allowed inbound access on 5085, 12000 and 12001 to NetTalk Device

static (inside,outside) udp interface 5085 192.168.0.60 5085 netmask 255.255.255.255
access-list inbound extended permit udp any interface outside eq 5085

static (inside,outside) udp interface 12000 192.168.0.60 12000 netmask 255.255.255.255
access-list inbound extended permit udp any interface outside eq 12000

static (inside,outside) udp interface 12001 192.168.0.60 12001 netmask 255.255.255.255
access-list inbound extended permit udp any interface outside eq 12001

We will see how it works for next few days and continue further troubleshooting.

 

Update 2

Above mentioned step did not resolve the issues, it worked for about 10 hours and then outbound connection to 199.193.188.184 will disappear and greenlight will start blinking and then eventually turned red.

I ended up implementing DMZ on ASA updated ASA to 8.4 and so far so good since yesterday night. Now one issue I have on hand is ASA 5505 with 8.3 or higher needs 512MB of minimum ram mine has only 256 MB so looking for after market ram for ASA 5505 seems like it needs to be DDR3200 and following afer market models appear to be working

HYS64D128320HU-5-B
KVR400/512R

Advertisements

Leave a comment

Filed under Uncategorized

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s