At a handful of locations when someone calls in and the staff go to pick-up the call it does not pick-up and continues to ring on other phones in the office. When they place someone on hold, sometimes it does not come off hold and they call is dropped. When they transfer someone it does not always transfer the call.
Cisco Call Manager shop.
We have SIP ALG disabled, does not seem to help.
This is at a remote location with excellent response time and no packet loss.
The location is connected back to the main office over a VPN tunnel from the Palo to an ASA at the corp office. The call manager is at the corp office where the phones register too.
No NAT is in use.
If I put the old ASA back in place at the remote office it works fine.
Everything you describe seems to be affected by call control vs the audio.
What do the logs show for the firewall.
Are you using AppID rules or do you have a range of ports opened up.
What do you see for logs on the CM when this is occuring.
Can you plug a phone into an available (and configured interface/maybe new zone on the FW) and see if it works, without sending traffic through the VPN.
For now we allow everything through the VPN, service is set to "any". Is that what you are asking? Not sure on the logs for the CM side, I'll get the info tomorrow from the voice engineer. In order for the phone to register with the CM at this remote site it has to go over the VPN. If I switch back to my old ASA, things are fine. I have other palo altos at other sites with the exact same configuration and hardware setup and no issues.Just this site and one other.
Do you have any profiles (URL Filtering, Threat, Antivirus) set to the rule allowing this traffic or not? What you are talking about is all in actual control traffic as @SteveCantwell mentioned. You might want to also enable logging on the interzone-default policy and ensure that your applications are actually being identified properly and you aren't silently dropping any of the traffic.
No URL, no Threat, no Antivirus between the two zones. I'll turn on interzone logging and see what I get.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!