Trimline Premium Member join:2004-10-24 Windermere, FL |
Trimline
Premium Member
2014-Sep-5 11:43 am
[Other] Fax Machine Ringing Every 10 MinutesI have my fax machine registered through VoIP.ms. It works just dandy on an HT502. This morning, I hear it hang up numerous times. I look in the VoIP.ms logs and there are no calls registered.
I go to pull the Netgear R7000 logs, and behold, this is what I see:
[LAN access from remote] from 195.154.233.112:5070 to 192.168.1.117:5062, Friday, Sep 05,2014 08:17:41 [LAN access from remote] from 195.154.233.112:5070 to 192.168.1.117:5062, Friday, Sep 05,2014 08:24:12 (EVERY TEN MINUTES...) [LAN access from remote] from 195.154.233.112:5070 to 192.168.1.117:5062, Friday, Sep 05,2014 11:01:29 [LAN access from remote] from 195.154.233.112:5071 to 192.168.1.117:5062, Friday, Sep 05,2014 11:11:55 [LAN access from remote] from 195.154.233.112:5070 to 192.168.1.117:5062, Friday, Sep 05,2014 11:21:51
If I look up that IP, it belongs to a French ISP. I hooked up a phone and answered, but nobody is there. What I find odd is that they can even get in to my LAN. My Asterisk server remains unaware, which as it should be.
I'm aware of SipVicious (which I expect) and the like, but how did they even get this far?
Has anyone experienced this before? |
|
MangoUse DMZ and you get a kick in the dick. Premium Member join:2008-12-25 www.toao.net 1 edit |
Mango
Premium Member
2014-Sep-5 11:57 am
said by Trimline:What I find odd is that they can even get in to my LAN. Either you have port forwarding or DMZ turned on, or your router is operating in full cone NAT mode. Fix that! Edit: If you do not have port forwarding or DMZ configured, you may want to confirm my guess about your router operating in full cone NAT mode by running DogFace05's utility: » toao.net/580 |
|
Trimline Premium Member join:2004-10-24 Windermere, FL |
Trimline
Premium Member
2014-Sep-5 12:40 pm
Interesting. I don't have a DMZ configured or port forwarding. I ran DogFace's utility and it reported:ESTUN_RES_NAT_FULL_CONE: Behind full-cone NAT
Now trying to figure out why this started. I did upgrade the firmware from Netgear a few days ago. As of an hour ago, and a router reboot, I no longer see these entries.
Any advice? |
|
MangoUse DMZ and you get a kick in the dick. Premium Member join:2008-12-25 www.toao.net |
Mango
Premium Member
2014-Sep-5 12:47 pm
Check ADVANCED > Setup > WAN Setup. Is NAT Filtering set to Secured or Open?
And do you have Disable SIP ALG checked?
I guess, but do not know for sure, that either or both of those may change the behaviour.
m. |
|
Trimline Premium Member join:2004-10-24 Windermere, FL |
Trimline
Premium Member
2014-Sep-5 12:55 pm
NAT |
I thought the same thing... I doubled-checked the settings. Not sure I want to go down the SIP ALG setting. I did unplug the ATA for a while as well, and of late, no more attempted connections. I'll keep a watch out on this one. Thanks. |
|
MangoUse DMZ and you get a kick in the dick. Premium Member join:2008-12-25 www.toao.net |
Mango
Premium Member
2014-Sep-5 1:02 pm
said by Trimline:no more attempted connections. Unless you solve the problem, they'll be back. |
|
·Fido MikroTik RB750Gr3 MikroTik wAP AC Panasonic KX-TGP500
|
to Trimline
Change the port that your HT502 listens on to something outside the 5060 - 5080 range. |
|
Trimline Premium Member join:2004-10-24 Windermere, FL |
Trimline
Premium Member
2014-Sep-5 1:25 pm
Thanks! Just did that as well. |
|