Re: NATed endpoints problem (possible bug?)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Please post a sample level 5 log with these two RRQ/RCF sequences.
This scenario should work - I don't know where is the problem.

----- Original Message ----- From: "Victor Huertas Garcia" <vhuertas@xxxxxxxxxxx>
Sent: Thursday, May 26, 2005 9:29 AM


I am using the GNU GK v2.2.2 in a Linux machine. The problem I have found is the following. Imagine that I have two H.323 endpoints which have to register with the GNU GK:

Endpoint 1:
it is NATed (local address = 10.1.3.11, global address = 147.33.22.11) and has this E.164 alias: 931231231.

Endpoint 2:
has a private IP address which is 10.1.3.11 (not NATed) and has this E.164 alias: 937897897

I want to remark that this scenario is perfectly possible, above all if we deal with NAted endpoints (the assignation of IP addresses behind the NAT is out of GK Administrator's control).

Then, what I authenticate is that one alias must belong to a single and unique IP address. Have a look at the following configuration:

[RasSrv::RRQFeatures]
AcceptEndpointIdentifier=1
AcceptGatewayPrefixes=1


[Gatekeeper::Auth]
AliasAuth=sufficient;RRQ
PrefixAuth=required;ARQ
default=allow

[RasSrv::RRQAuth]
931231231=sigip:10.1.3.11
937897897=sigip:10.1.3.11

Note that if I want the NATed endpoint to be registered, the specified IP address has to be the private one (10.1.3.11) and not the global one used by the NAT. Otherwise, the GK sends a RRJ with SecurityDenial reason.

When the Endpoint 1 registers, the GK sends an RCF message (till here, no problem). However, when the Endpoint 2 registers as well, the GK sends as well an RFC message but when I look up the current resgistered endpoints IT IS ONLY DISPLAYED THE Endpoint 2, which is the last one to be registered!! The Endpoint 1 disappears from the resgistered endpoints table!! Therefore Endpoint 1 is not reachable at all!!

Is this a bug in the GNU GK?

Thank you very much for your attention.

Victor



-------------------------------------------------------
This SF.Net email is sponsored by Yahoo.
Introducing Yahoo! Search Developer Network - Create apps using Yahoo!
Search APIs Find out how you can build Yahoo! directly into your own
Applications - visit http://developer.yahoo.net/?fr=offad-ysdn-ostg-q22005
_______________________________________________________

Posting: mailto:Openh323gk-users@xxxxxxxxxxxxxxxxxxxxx
Archive: http://sourceforge.net/mailarchive/forum.php?forum_id=8549
Unsubscribe: http://lists.sourceforge.net/lists/listinfo/openh323gk-users
Homepage: http://www.gnugk.org/

[Index of Archives]     [SIP]     [Open H.323]     [Gnu Gatekeeper]     [Asterisk PBX]     [ISDN Cause Codes]     [Yosemite News]

  Powered by Linux