How to Disable SIP and RTP Processing on your Fortigate for VoIP Goodness!

So I’m sitting there… having moved our SIP Gateway and VoIP Phone system behind the Firewall and then OMG ITS NOT WORKING! I mean, it is, and by it is, I mean, no. It isn’t working. :)   Lo and behold technically OMG THE SOLUTION IS DISABLE SIP!  Well, that sounds pretty ridiculous… But I guess it turns out that the system has a native SIP handler and knows better than we do! Well, you’re wrong. You don’t know better than we do, unless ‘knowing better’ means breaking my SIP traffic!

That said, there are a few other blogs where I found answers which helped lead to this solution (included below) but you know me.. I like to make sure I have a source to refer back to things and of course to share my experience on the matter, thus here it is! :)

Step One: Disable SIP Helper!

  1. config system settings
  2. set  sip-helper disable
  3. set sip-nat-trace disable
  4. REBOOT THE DEVICE!!! (You may want to wait on rebooting until AFTER you do the next few steps!)

Step Two: Delete the SIP Helper

  1. config system session-helper
  2. show (Look for the SIP helper, often object 12)
  3. delete # (whatever number the SIP helper was)

Step Three: Disable RTP Processing

  1. config voip profile
  2. edit default
  3. config sip
  4. set rtp disable

And there you have it! If you did the steps in reverse and then rebooted, your Fortigate should no longer be preventing your SIP traffic from working!  That is also of course ensuring you’re sending all of the right ports through in your firewall rules… that’s up to you to check with your respective VoIP vendor to make sure you have the full compliment of ports, policies, etc!

Good luck! <3

Other blogs which helped solve this!

I won Best of IT Transformation at EMC World for “Ten ways to reduce cost while modernizing your IT” #EMCElect

I’ll tell you, easily one of my LONGEST subject lines ever! But subject length aside, this is actually pretty awesome!

For those of you who missed this, here’s the low down from a blog post I published last October.  EMC Proven Knowledge Sharing Competition – Join Now! Abstracts Due 12NOV #EMCElect

And for what its worth, my marketing director has done an AWESOME coverage of events here Christopher Kusek earns EMC 2015 Knowledge Sharing Award!

So that got it all started… OMG A CONTEST! Well, not even so much as a contest, as it was a raw and heated COMPETITION! What it’d entail initially was submitting an abstract.   And from the Abstract alone you’d be informed whether you’d even be entitled to be ALLOWED to enter the competition.   In my case, my abstract was accepted, awesome.  But then it came down to, “Hey, it’s time to submit your paper!” Well, so there I was… writing my paper, and write it I did!   One thing in particular which was *very* cool, is the fact that the “Judges” of the papers have no idea who the authors are.  No, it’s not like they’re secluded and don’t stay in touch with industry, quite the opposite… They’re SHIELDED from who the submitters are, any type of information is shielded from them, and instead they’re judging the papers based upon the content and not the character of the authors!

Which ultimately is what brought me to this years 2015 EMC World!   I had been informed that I was a “finalist” which means, I’d be 1st, 2nd, 3rd or one of the Best of Tracks… All very secretive, all I knew was, “I WAS IN” I just didn’t know what position or place!

CK EMC Award

That is when it all fell into place! My name called, giving me the absolute honor of “Best of IT Transformation” it was an absolute blast to all happen at once!   Due to the power of… VideoLinkFail you can skip ahead to 16:45 and get to my part of the video :)  Otherwise watch it all the way through, it gives an interesting take and shares information on the EMC Proven Education Ecosystem!

That wasn’t even the half of it though! When I wasn’t on stage wearing horribly uncomfortably shoes (which looked great mind you!) and receiving an award… LOOK AT THAT THING! ITS 8LBS OF CRYSTAL!

Best of IT Transformation

I was spending the bulk of my time ON CAMERA giving individual interviews or group interviews or this and that!

Christopher Kusek - Best of IT Transformation EMC World 2015

But some of you are saying, “You know what? I don’t give a damn about any of that! Show me the money! err, Paper, I MEAN THE PAPER!”

That’s cool, totally respect that… :) Well, here are some links and copies of the paper!

Because I’m obviously a marketing whore (go me, right! :)) There’s also the Xiologix branded version which I actually like how it is formatted better… (Primarily because… I formatted it to make sure data presents on pages the way I prefer from having written a thing or two here and there!) so here are some links to BOTH versions! <3

Read Xiologix Version: Ten ways to reduce cost while modernizing your IT

Ten Ways to Reduce Cost While Modernizing your IT - Xiologix Version

Read EMC Version: Ten ways to reduce cost while modernizing your IT

To follow-up on updates to this presentation and other information around be sure to check out the updated page at our Xiologix site where we’re keeping it updated and current! Christopher Kusek earns EMC 2015 Knowledge Sharing Award!

Also there is a Presentation version of this paper which has been delivered to standing room only audiences across the Pacific Northwest (also regular sitting rooms of folks :)) So if you’re interested definitely reach out <3 :)

Keep on keeping on!

OMG OMG WIN TWO TICKETS TO VMWORLD FROM @VMTURBO!!!

VMturbo VMworld 2015 Sweepstakes!!!

Wow, scream much mr mc screamy?

Hey what can I say, I’m excited… For you, the potential win ners of this contest! And Yes, yes I did apply to this contest too, but hey I’m not some evil bastard who is going to hoard something just so I minimize my odds, you should share it too!   So what’s the deal?

Well, you know how every year various companies which are integral to virtualization tend to give away free passes to VMworld?  This year, we kick it off with VMTurbo providing not one, not two, but THREE possibilities to win, not one, but TWO passes! Wow that’s a lot of math!

OMG WHEN ARE THE DRAWINGS?!

The drawings are MAY 29th, JUNE 19th, and JULY 10TH!!!

This is only for VMworld San Francisco, and of course go read the rules, but click the picture above, the drawings, THIS LINK, there’s a lot of places to ensure that you are ENTERED!

Why does the “Industry” predict what happens when it’s the Community who Adopts?

This is a particularly pressing question that has come up recently.  I even put out a post about it in the SolarWinds Thwack community because they’re such a diverse and engaging community I love the feedback they tend to present!

I’ve seen a lot of predictions over the years, whether it is “This is the year of VDI!” (Currently we are on the 7th “year of VDI”)  Or “Big Data is here!” we all know the infinite number of predictions we constantly hear about, I’ve even included one of my own for the coming 2015 from from? ?SingleHop who hit me up at the end of 2014 saying, “Hey, do you have any IT Predictions for 2015?”

Single Hop 2015 IT Predictions

So I get it. You get it.  But are these really predictions intended to become self-fulfilling prophecies or are they mere posturing while YOU the Community. You the CUSTOMERS of the world are the ones determining whether these predictions actually come to fruition.   Now not all Predictions are within our control, like saying the cost of a particular product or solution will be reduced, that is really up to the industry that bears it, that we constantly fight for pricing on and against. 

But let’s talk about some general purpose predictions and it’s really up to you to decide what YOUR adoption is, I’ll provide some color in some places if you’re not familiar with it so as to give you a baseline to discuss.

Software Defined Storage (SDS)

Everybody and their brother is talking about SDS. “Check out our SDS Solution! It’s awesome!” blah blah blah.  So for the moment, let’s take a sober look at what the SDS space looks like.   VSAN is now available as 2.0 in vSphere 6.0.  However prior to it going GA last week, VSAN alone has ~1200 customers.   That’s pretty significant considering their solution has only existed for LESS than a year. (Compared to other similar solutions, the numbers are in the HUNDREDS not Thousands) so the possibilities look potentially bright, albeit at a cost.  

Now what about vVOLs you say. Yea you can say that, is it too early to tell? Yes. Yes it is FAR too early to tell, because vVols have gone GA LAST WEEK and not every vendor has their support integrated for it.  For what it is worth, vSphere 6.0 having just come out still isn’t fully baked and supported by all of your third-party applications, so if you run a pure-play VMware environment only without Veeam, Zerto and every other billion vendor solution out there and at the same moment your SAN also supports vVols, then sure, but for most of you… You’re going to be waiting a little while (At least 60-90 days for full support and adoption)   So for the meantime you’re still looking at vSphere 5.5 and the respective solutions present there, that’s not a BAD thing, it’s just a factual thing you need to be aware of.

Now to play the devils eggvocate on this a moment, If VMware has Let’s say a million customers, and ~1200 of them are running VSAN today. There’s nothing but room for growth, lots and lots and lots and lots and LOTS of growth.   So it’s not like the tides have been turned, the tipping point as it were (I’m sure that’s somehow relevant :)).   It really comes down to you to decide, “Of the Software Defined Storage strategies available in the market place which ones am *I* liking and seeing value to leverage in my organization” You know or blah blah blah. :)

Software Defined Networking (SDN)

Why yes, let us talk about the SDN space for a moment… The number of solutions available aren’t exactly bursting at the seams.  I mean sure, –14- hours ago, Juniper and Mirantis have expanded their partnership to pursue SDN type joint development, but for the whole of the market-place, that doesn’t mean they have a go to market solution we can adopt.   That said, let’s discuss what we CAN adopt.   VMware NSX, Cisco ACI and OpenFlow.   VMware’s NSX is the best player in town, it has the greatest feature-set and capabilities and will give us visibility and insight into East-West traffic which has essentially been masked as a result of the adoption of Virtualization.  Pretty awesome, right? NSX has been around for ~5 years+ now? And they had 400 customers when VMware acquired Nicira back in 2012, and today they have 400 customers.   I don’t see this puppy jumping off the shelf, when something like VSAN which has been 1.0 has 3x as many customers.   Now, I’ve found that VMware sales people will disagree with me, “We see it everywhere, everyone is interested, stop saying that no one is buying NSX”  Okay, show me the money, stop telling me the rhetoric that YOU are being told.  Like I said, it is the BEST player in town, yet when I talk to guys who run some of the large NSX shops… Well, let’s just say I wish that it worked as well as HA, DRS, or vMotion.   So should you adopt an SDN strategy or should you look at one? I’m sure you’ll be the first to tell me that YOU are indeed looking at one, because we can predict all the hell we want, it’s up to you to decide and enact.

Hybrid Cloud

The Cloud the Cloud the Cloud! This is surprisingly one area where I keep hearing about it from YOU and not in reverse.  Customers and friends who have made such claims as, “Yea, I moved ‘x’ services from On-Premises into Azure” or one who said they’ve moved 100% of their server workload into Azure. Yea, Seriously, Wow!  I’m with you, the proof is in the pudding, and want to see how it tastes 3, 6, 9 months and a year out, but the fact that others are doing it is quite a positive testament to the capabilities.   Oh and people are starting to adopt the same in a vCloud Air type of scenario (Yes, I hate it when they keep changing product names on us, I mean give a brother vCloud Air with Retina at least! :))   So while even *I* have predicted that people will start adopting Disaster Recovery as a Service leveraging capabilities like vCloud Air, I’ll let you know how I see that start to play out vs just saying, “Yea I think people will start to do something like that”.   The year is still early and I’ll actually have some interesting Hybrid Cloud stories to share as the year progresses, but for now, you tell me if you’re seeing adoption of YOURSELVES increase :)

Monitoring and Management

This is often the most overlooked, undervalued and most necessary part of every organization.   Companies who produce tools that allow you to manage your environment, watch over your infrastructure and then start to provide intelligence and guidance as opposed to merely sharing information with you can be few and far between.  Some players in this space like Solarwinds have done more than just simply take a temperature of what people are doing and have started to integrate what matters most to you into a single pane (drink!) to allow for better management.   I’m not saying, Hey stop proceeding down your road of deploying Orion, NPM, SRM, Virtualization Manager, and an infinite number of items that provide insight, however Solarwinds themselves have seen a need for integration, thus their release of AppStack to provide that unified point of management.   The Microsoft Fanboys may say, “I can do everything I ever could want with System Center” and it’s cute that you believe that, but the moment you need to do something non-microsoft centric or provide deeper insight into a Virtual, Storage or Network layer… I’m not saying you won’t see anything, I’m just saying… you’ll have blinders on. :)   The monitoring and management landscape is filled with lots of players, many of whom are one-off and many of whom are trying to be the ‘everything for everyone’ ala HP OpenStack (ouch!) so be wary and be aware.  Though how important is correlation engine analytics and deep inspection visibility and insight into your infrastructure into 2015? Is that something you desire or do you feel it merely a myth?

These are just a handful of items which are often predicted about and in particular have predictions for this year.   What are you seeing be the players in this space that you’re looking into? What do you see yourself straight-up adopting?   You’re the trendsetters, we’re just a bunch of random people touting our thoughts. :)

The EMC VSPEX BLUE is available for Purchase! Also our @Xiologix EMC Storefront for VSPEX BLUE is now LIVE! <3 #EMCElect #vExpert

EMC VSPEX BLUE Storefront by @Xiologix

Whoa whoa whoa, wait a minute, wait just one minute. What what?!   Yea, that’s right! You can finally start buying EMC’s VSPEX BLUE! Awesome right?!  Also if you remember from my last blog post on this subject,  EMC announces Sapphire on Rails! Err… I mean VSPEX BLUE a VMware EVO:RAILS Solution! I stated that this is only available “Through Channel Partners” So an extra ounce of awesome to that is… OMG WE’RE ONE OF THE CHANNEL PARTNERS! <3 <3 <3

EMC has officially announced a channel distribution model for the EMC VSPEX BLUE but in addition to that, they selected ten partners throughout the US to kick things off with this ‘beta program’ of the EMC Storefront.  Interesting stuff…

I know some of you are of the position, “Wow, I just like to walk into a store, order what I want and just go with this” this essentially lets you do that in so many terms.   If you’re not sure whether VSPEX BLUE is a good fit for you, or whether any EVO:RAIL Solution is the right approach for your organization be sure to check out my previous post (mentioned above) to get the long and short, and the respective skinny on whether it is indeed a good fit.

And hell, if it is a good fit… and the EMC Solution in particular is the flag you want to wave, head on over to the Xiologix EMC Store Front and ‘put in an order’ so to speak ;)  I’ll personally say hi and tell you why it’s either a good or horrible idea. (Well, I’m not going to stop guiding, steering and consulting just because something shiny and Blue comes along, right? :))

Though seriously, check it out… A lot of effort went into putting this out there, so why not? Otherwise, good times and start catching the blues! <3