For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Johan_Lundström's avatar
Johan_Lundström
Icon for Nimbostratus rankNimbostratus
Sep 24, 2014

NAT sip traffic with a F5

Hi guys,

 

I have some problems getting SIP traffic through my F5 running 11.3.H8.

 

We have a private network 192.168.100.0/24 talking SIP via a VIP on port UDP/5060. I have inserted a VIA header so the SIP server knows where to return the packets. When we insert the VIA header we add enough bytes to make the packet larger than 1500 bytes and since the DF flag is set our upstream switch will chop off all bytes after 1500 and the auth part gets corrupted. This leads to a 403 Forbidden instead of a 401 Not Authorized.

 

Any suggestions on how to solve this is greatly appriciated

 

Johan

 

No RepliesBe the first to reply