[asterisk-users] IAX2 over OpenVPN connection.... working but

Duncan Turnbull duncan at e-simple.co.nz
Sun Dec 9 14:10:17 CST 2012



On 10/12/2012, at 8:54 AM, Stephen Brown <stephen.brown75 at gmail.com> wrote:

> 
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> So a friend of mine and I setup a static key based point to point
> OpenVPN connection from my box to his for the express intent of carrying
> IAX traffic encrypted.
> 
> His network on his lan is 172.30.1.0/24 and mine is 10.0.30.0/24. His
> PBX is located at 172.30.1.48 and mine is at 10.0.30.2. We had an
> existing working IAX trunk in place prior to the VPN, and after we
> brought the VPN up we set the host= parameter within Asterisk
> accordingly on each end to match the local IP's and discovered it did
> not work. The trunk remained in an UNKNOWN status on each end, even
> though we could ping each box locally, SSH, and even SIP worked.
> 
> Here's where I am baffled and I am hoping someone with intricate
> knowledge of this implementation may be able to explain it to me. What
> we had to do to get this working was to set the host= parameter to the
> respective endpoint IP's of the VPN tunnel, 172.10.1.1 in my case, and
> 172.10.1.2 in his case. Calls flow normally now and we cannot understand
My guess is asterisk is replying using the tunnel ip address which your original box won't accept unless you actually sent to that address. Thats what I see on our remote openvpn tunnels. If you want to know whats going on use tcpdump to check packets through the tunnel. 

> how or why. I would have assumed with a destination of either LAN as

> defined by the routing table it would have left out on the OpenVPN
> connection by default, and what's even more strange is that IAX is the
> only protocol that does not appear to function as intended.
> 
> Any takers? :)
> 
> 
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v2.0.17 (MingW32)
> 
> iEYEARECAAYFAlDE7GcACgkQ3sJXNEncx7is9QCcCciMYFJ7ZXjYxuHC2EYD0PZY
> waAAniNNx8GuC5To7ajlGR5sYs3yftFK
> =lcWJ
> -----END PGP SIGNATURE-----
> 
> 
> --
> _____________________________________________________________________
> -- Bandwidth and Colocation Provided by http://www.api-digital.com --
> New to Asterisk? Join us for a live introductory webinar every Thurs:
>               http://www.asterisk.org/hello
> 
> asterisk-users mailing list
> To UNSUBSCRIBE or update options visit:
>   http://lists.digium.com/mailman/listinfo/asterisk-users




More information about the asterisk-users mailing list