[YMCS/YDMP Free Trial Program]Yealink would like to offer Free Trial Program of Yealink device management service for our current eligible customers. You can see the details below.
https://www.yealink.com/ydmp-freetrial-2020


Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
T20P: VPN/OpenVPN - Just SIP or also RTP?
Author Message
ruiseixas Offline
Junior Member
**

Posts: 34
Joined: May 2013
Reputation: 0
Post: #8
RE: T20P: VPN/OpenVPN - Just SIP or also RTP?
(12-02-2013 06:05 PM)dlmc Wrote:  
(11-09-2013 06:55 AM)ruiseixas Wrote:  One problem that remains is that if I call a number in the same LAN, the RTP traffic leaves that LAN because the SIP server works as a RTP Proxy, making the RTP traffic available in the Internet, despite being private between Algeria and Portugal!

same LAN as what ?

Your OpenVPN server endpoint, should be running a SIP ALG (thus rewriting the media IPs to that of the OpenVPN server endpoint inside the tunnel) causing all SIP (port 5060) and RTP data to always be inside the tunnel no matter what IPs are given out by upstream SIP server or upstream media proxy server.

On Linux (which OpenWRT is based this a pair of kernel modules nf_conntrack_sip and nf_nat_sip) ensure the stream in and out is symetric. For example one common problem for Asterisk is that is does not examine the inbound packet local IP to ensure to reuse it in the reply and ends up using the default IP provided by the kernel in the reply. This can be fixed up using Linux netfilter DNAT and SNAT rules (on the Asterisk box or on the OpenVPN server endpoint box) to help it be symetric allowing SIP ALG kernel modules to work.

Same LAN in the sense that I'm using Getonsip.com trough the same gateway, and they force the use of a proxy in that case, so if two phones are in the same LAN, the proxy of Getonsip is used like shown in the next picture:

[Image: image070.png]

For more details see the next page:
One field to consider adding to the Client's VPN config file is this:
Code:
# Uncomment this section for a more reliable detection when a system
# loses its connection.  For example, dial-ups or laptops that
# travel to other locations.
ping 30
ping-restart 300
persist-key
;persist-tun

This allows the connection to be restarted in case you use Dyndns when your dynamic IP changes, and this way you still connected to the same LAN via VPN!
03-08-2014 05:41 AM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Post Reply 


Messages In This Thread
RE: T20P: VPN/OpenVPN - Just SIP or also RTP? - ruiseixas - 03-08-2014 05:41 AM

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  T28P - OpenVPN TLS error: Unsupported protocol 1sae 0 995 07-18-2023 06:50 AM
Last Post: 1sae
  T19PE2 openvpn? bozko 0 5,112 10-11-2020 11:43 AM
Last Post: bozko
  how to connect yealink T23G to mikrotik openvpn server m.taghavi 4 13,876 10-11-2020 11:31 AM
Last Post: bozko
  openvpn[1205]: RESOLVE: Cannot resolve host address: myfake.dns.net:1194 rafael.catelecom 2 7,957 11-07-2019 02:24 PM
Last Post: rafael.catelecom
  How to change voice when busy, waiting and other.. T20P marin 0 4,195 04-11-2019 12:53 PM
Last Post: marin
  T20P Issues uploading VPN configuration mikeymike20 1 6,913 06-13-2018 07:24 AM
Last Post: Michael_Yealink
  Yealink Phones + OpenVPN Ramkumar 0 5,462 05-28-2018 06:14 AM
Last Post: Ramkumar
  SIP T20P unlock help afsfwmw90rfj 1 8,289 06-23-2017 08:24 AM
Last Post: Klaus_Yealink
  T19 E2 with openvpn TLS handshake failed Samcotec 2 10,067 04-28-2017 02:59 PM
Last Post: Michael_Yealink
  T21P E2 OpenVPN Disconnects acca 1 9,258 11-02-2016 07:53 PM
Last Post: acca

Forum Jump:


User(s) browsing this thread:

Contact Us   Yealink   Return to Top   Return to Content   Lite (Archive) Mode   RSS Syndication