You need a Stun Server...vovida.org works for me<br><br><div><span class="gmail_quote">On 11/11/05, <b class="gmail_sendername">Enrique Leon</b> &lt;<a href="mailto:enrique.leon.acedo@gmail.com">enrique.leon.acedo@gmail.com
</a>&gt; wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">Second post<br><br>I have installed Asterisk on SuSE 10.0 with an active firewall/NAT filter.
<br>The server has connection to my own Intranet (private IP) and to Internet<br>Everything works well for clients behind and in front-of the firewall<br>but they can not communicate with each other. Signalling gets through
<br>but the audio gets blocked by the firewall/NAT.<br><br>So, I open-up ports 10.000 -to- 20.000 in the fw so that the udp/rtp packages<br>cuold get through but it has not been successful.<br><br>I am using xlite for clients and have no pot cards installed ( digium
<br>fxo,fxs, etc).<br><br>Does anyone knows what else to do?<br><br>Has anyone come accross (and solved) this type of problem?<br><br>Firewall configuration is as follows:<br><br><br>FW_DEV_EXT=&quot;eth-id-00:0d:87:5c:44:e5&quot; #eth1
<br>FW_DEV_INT=&quot;eth-id-00:06:4f:0e:ca:99<br>eth-id-00:40:f4:9f:12:25&quot; #eth0 wlan0<br>FW_ROUTE=&quot;yes&quot;<br>FW_MASQUERADE=&quot;yes&quot;<br>FW_MASQ_DEV=&quot;$FW_DEV_EXT&quot;<br>FW_MASQ_NETS=&quot;<a href="http://192.168.100.0/255.255.255.0">
192.168.100.0/255.255.255.0</a>&quot;<br>FW_SERVICES_EXT_TCP=&quot;53 http https ssh&quot;<br>FW_SERVICES_EXT_UDP=&quot;5060 5061 53&quot;<br>FW_SERVICES_INT_TCP=&quot;21 3128 5056 53 5801 5901 80 8080<br>epmap http microsoft-ds netbios-ssn smtp ssh&quot;
<br>FW_SERVICES_INT_UDP=&quot;5060:5075 53 bootps netbios-dgm<br>netbios-ns&quot;<br>FW_SERVICES_INT_RPC=&quot;mountd nfs nfs_acl nlockmgr<br>portmap status ypbind&quot;<br>FW_SERVICES_ACCEPT_EXT=&quot;0/0,udp,5060:5075&quot;
<br>FW_TRUSTED_NETS=&quot;<a href="http://192.168.100.0/255.255.255.0">192.168.100.0/255.255.255.0</a>&quot;<br>FW_FORWARD=&quot;0/0,<a href="http://192.168.100.0/255.255.255.0,udp,5060">192.168.100.0/255.255.255.0,udp,5060
</a>&quot;<br>FW_FORWARD=&quot;0/0,<a href="http://192.168.100.0/255.255.255.0,udp,10000">192.168.100.0/255.255.255.0,udp,10000</a>&quot;<br>FW_FORWARD=&quot;<a href="http://192.168.100.0/255.255.255.0,0/0,udp,10000">192.168.100.0/255.255.255.0,0/0,udp,10000
</a>&quot;<br><br><br>Sip Configuration:<br><br>[general]<br>bindport=5060<br>bindaddr=<a href="http://0.0.0.0">0.0.0.0</a><br>srvlookup=no<br>externrefresh=10<br>externip=<a href="http://201.208.246.178">201.208.246.178</a>
<br>nat=yes<br>localnet=<a href="http://192.168.100.0/255.255.255.0">192.168.100.0/255.255.255.0</a>;<br><br><br>RTP configuration:<br><br>[general]<br>rtpstart=10000<br>rtpend=20000<br>rtpchecksums=yes<br><br>Regards, Enrique Leon
<br>_______________________________________________<br>--Bandwidth and Colocation sponsored by <a href="http://Easynews.com">Easynews.com</a> --<br><br>Asterisk-Users mailing list<br><a href="mailto:Asterisk-Users@lists.digium.com">
Asterisk-Users@lists.digium.com</a><br><a href="http://lists.digium.com/mailman/listinfo/asterisk-users">http://lists.digium.com/mailman/listinfo/asterisk-users</a><br>To UNSUBSCRIBE or update options visit:<br>&nbsp;&nbsp; <a href="http://lists.digium.com/mailman/listinfo/asterisk-users">
http://lists.digium.com/mailman/listinfo/asterisk-users</a><br></blockquote></div><br>