Re: Kamailio behind NAT
Sergio Charrua via sr-users <[email protected]>
| Newsgroups | gmane.comp.voip.ser |
|---|---|
| Message-ID | <CALZWR5ztNEoGbmRHwi6byx2MorE+Q8nT5OHuTKw7m83NWk=6DA@mail.gmail.com> |
Try the following routing block. It needs to be called before you t_relay()
your call.
What this does is use the same IP:PORT where your kamailio received the
INVITE, but for outbound, so in the case you have Kamailio listening in
multiple SIP:PORT sockets, if Kamailio receives the INVITE into Kamailio's
10.0.0.1:5068 it will use that address to also relay the call. If the
receiving address is 10.20.0.2:5080 it will also use that same address to
relay the call.
route[PIN_SOCKET] {
# routing block that sets the socket IP:PORT to SIP messages
# sent to the egress side
if (is_method("INVITE") && !has_totag()) {
dlg_manage();
$var(proto) = $pr; # "udp" / "tcp"
xlog("L_DEBUG", "PIN_SOCKET - stored dlg_sock=< $pr:$Ri:$Rp > \n");
$dlg_var(send_sock) = "$pr:$Ri:$Rp"; # e.g. udp:10.20.0.4:5061
}
# choose the socket we’ll force
if ($dlg_var(send_sock) != $null) {
$var(sock) = $dlg_var(send_sock);
} else {
$var(proto) = $pr;
xlog("L_DEBUG", "PIN_SOCKET - setting $pr:$Ri:$Rp \n");
$var(sock) = "$pr:$Ri:$Rp"; # requests without dialog
}
xlog("L_DEBUG", "PIN_SOCKET - forcing <$var(sock)> (recv
$pr:$Ri:$Rp)\n");
set_send_socket($var(sock)); # some versions need this form
(unquoted)
xlog("L_DEBUG", "PIN_SOCKET - $$var(sock) = $var(sock) -
$$dlg_var(send_sock) = $dlg_var(send_sock) \n");
}
route[RELAY] {
if (is_method("INVITE|UPDATE")) # |BYE
{
if (!t_is_set("branch_route")) t_on_branch("MANAGE_BRANCH");
if (!t_is_set("onreply_route")) t_on_reply("MANAGE_REPLY");
if (!t_is_set("failure_route")) t_on_failure("MANAGE_FAILURE");
}
route(PIN_SOCKET);
if (!t_relay())
{
xlog("L_INFO","RELAY - Returned from event");
sl_reply_error();
}
exit;
}
Hope this helps!
Atenciosamente / Kind Regards / Cordialement / Un saludo,
*Sérgio Charrua*
On Thu, Sep 4, 2025 at 9:23 AM Martin Nyström via sr-users <
[email protected]> wrote:
> I did the suggested changes, I think. But the INVITE sent from Kamailio to
> Asterisk still holds the external advertised DNS in the RR.
>
>
>
> Here’s the INVITE sent to Asterisk from Kamailio:
>
>
>
> eth1 Out IP 10.3.124.192.5060 > 10.2.5.206.5080: SIP: INVITE
> sip:[email protected] SIP/2.0
>
> INVITE sip:[email protected] SIP/2.0
>
> Record-Route: <sip:sbc.coolcompany.com
> ;lr;ftag=5914da19-6958-4b8f-b521-d74c78af6120>
>
> Record-Route: <sip:sip-provider.com;lr=on>
>
> Call-ID: [email protected]
>
> CSeq: 25896 INVITE
>
> From: <sip:[email protected]
> >;tag=5914da19-6958-4b8f-b521-d74c78af6120
>
> To: <sip:[email protected]>
>
> Contact: <sip:[email protected]:5080>
>
> Via: SIP/2.0/UDP sbc.coolcompany.com:5060
> ;branch=z9hG4bKb32c.739784aeb0177ad4d3e181098a071abb.0;rport
>
> Via: SIP/2.0/UDP sip-provider.com
> ;branch=z9hG4bKb32c.79821495565acb8af61a7ebecb22b26d.0
>
> Via: SIP/2.0/UDP sip-provider.com:5060
> ;branch=z9hG4bK-323035-3a9c396118a108606e6234ff3013ed5b
>
> Max-Forwards: 67
>
> Content-Type: application/sdp
>
> User-Agent: XXXX
>
> Content-Length: 293
>
>
>
>
>
> Asterisk attempts to reply to the BYE on the external IP:
>
>
>
> <--- Transmitting SIP request (616 bytes) to UDP:sbc.coolcompany.com:5060
> --->
>
> BYE sip:[email protected]:5080 SIP/2.0
>
> Via: SIP/2.0/UDP 10.2.5.206:5080
> ;rport;branch=z9hG4bKPj917dd0c5-192b-457d-ae1a-ef693895e0c7
>
> From: <sip:[email protected]
> >;tag=1f88f783-83a4-419f-a7c3-3c37a40dada6
>
> To: <sip:[email protected]
> >;tag=3c6c6d47-8beb-4c71-a829-15138869defd
>
> Call-ID: [email protected]
>
> CSeq: 25915 BYE
>
> Route: <sip:sbc.coolcompany.com
> ;lr;ftag=3c6c6d47-8beb-4c71-a829-15138869defd>
>
> Route: <sip:x.x.x.x;lr>
>
> Reason: Q.850;cause=16
>
> Max-Forwards: 70
>
> User-Agent: xxxx
>
> Content-Length: 0
>
>
>
>
>
>
>
> Here’s again my dumbed down CFG with changes:
>
>
>
> debug=2
>
> log_stderror=yes
>
> fork=yes
>
> tcp_accept_no_cl=yes
>
> onsend_route_reply=yes
>
> pv_buffer_size=2048
>
> enable_tls=1
>
>
>
>
>
> listen=udp:<LOCAL_IP>:5060 advertise <DOMAIN>:5060
>
> listen=tcp:<LOCAL_IP>:5060 advertise <DOMAIN>:5060
>
> listen=tls:<LOCAL_IP>:5061 advertise <DOMAIN>:5061
>
>
>
> # INFO: Asterisk gateway listening
>
> listen=udp:<LOCAL_IP>:5080
>
> listen=tcp:<LOCAL_IP>:5080
>
> listen=tls:<LOCAL_IP>:5081
>
>
>
> local_rport=on
>
>
>
>
> mpath="/usr/local/lib/kamailio/modules_k/:/usr/lib/x86_64-linux-gnu/kamailio/modules/"
>
>
>
> loadmodule "rr.so"
>
>
>
> modparam("rr", "force_send_socket", 1)
>
>
>
> route {
>
>
>
> route(FROM_PROVIDER);
>
> exit;
>
>
>
> }
>
>
>
> route[RELAY] {
>
>
>
> if(!t_relay()) {
>
>
>
> sl_reply_error();
>
>
>
> }
>
>
>
> exit;
>
>
>
> }
>
>
>
> route[FROM_PROVIDER] {
>
>
>
> # INFO: The Asterisk
>
> ds_select_dst(100, 4);
>
>
>
> if(!has_totag()) {
>
> record_route();
>
> }
>
>
>
> route(RELAY);
>
> exit;
>
>
>
> }
>
>
>
>
>
> /M
>
>
>
> *From: *Martin Nyström <[email protected]>
> *Date: *Wednesday, 3 September 2025 at 10:59
> *To: *[email protected] <[email protected]>, Kamailio (SER) - Users
> Mailing List <[email protected]>
> *Subject: *Re: [SR-Users] Kamailio behind NAT
>
> Using a different port for Asterisk is not a bad idea. I might just try
> that. I will return with the results or any follow up questions.
>
>
>
>
>
>
>
> /M
>
>
>
> *From: *Daniel-Constantin Mierla <[email protected]>
> *Date: *Wednesday, 3 September 2025 at 10:54
> *To: *Kamailio (SER) - Users Mailing List <[email protected]>
> *Cc: *Martin Nyström <[email protected]>
> *Subject: *Re: [SR-Users] Kamailio behind NAT
>
> *CAUTION:* This email originated from outside the organization. Do not
> click links or open attachments unless you recognize the sender and know
> the content is safe.
>
>
>
> Hello,
>
>
>
> the simplest way is to listen on another port (e.g., 5080) and use that
> socket to communicate with Asterisk. For that listen parameter, do not set
> the advertise address. You can use $fs or force_send_socket() to specify
> the socket to be used for sending out to Asterisk.
>
>
>
> The alternative is to play in the config file with the function of the rr
> module that allow you to set the address in the Record-/Route headers, but
> it may increase the complexity of the config.
>
>
>
> Cheers,
> Daniel
>
>
>
> On 03.09.25 10:42, Martin Nyström via sr-users wrote:
>
> Hello,
>
>
>
> I am not successful in my attempts to configure my Kamailio to work behind
> NAT.
>
>
>
> The flow of an incoming call is Provider (Internet) -> AWS LoadBalancer ->
> Kamailio -> Asterisk
>
>
>
> Both the Kamailio and Asterisk is on the internal network. The issue I am
> having is that I need to add Record-Route to the traffic sent back towards
> the provider, but not to the Asterisk. Currently when I add the
> record_route() the header is sent to Asterisk which makes it reply to the
> Kamailio advertised external address for ACKs, BYEs etc.
>
>
>
> I have dumbed down my Kamailio config as much as possible for this, to
> show what I am currently doing.
>
>
>
>
>
> debug=2
>
> log_stderror=yes
>
> fork=yes
>
> tcp_accept_no_cl=yes
>
> onsend_route_reply=yes
>
> pv_buffer_size=2048
>
> enable_tls=1
>
>
>
> listen=udp:<LOCAL_IP>:5060 advertise <EXTERNAL_DOMAIN>:5060
>
> listen=tcp:<LOCAL_IP>:5060 advertise <EXTERNAL_DOMAIN>:5060
>
> listen=tls:<LOCAL_IP>:5061 advertise <EXTERNAL_DOMAIN>:5061
>
>
>
> local_rport=on
>
>
>
>
> mpath="/usr/local/lib/kamailio/modules_k/:/usr/lib/x86_64-linux-gnu/kamailio/modules/"
>
>
>
> # MODULES
>
> loadmodule "..."
>
>
>
> route {
>
>
>
> route(FROM_PROVIDER);
>
>
>
> }
>
>
>
>
>
> route[RELAY] {
>
>
>
> if(!t_relay()) {
>
>
>
> sl_reply_error();
>
>
>
> }
>
>
>
> exit;
>
>
>
> }
>
>
>
> route[FROM_PROVIDER] {
>
>
> # The Asterisk that should not receive the external dns in
> the record route header
>
> ds_select_dst(100, 4);
>
>
>
> # INFO: This adds the Record-Route in all directions
>
> if(!has_totag()) {
>
> record_route();
>
> }
>
>
>
> route(RELAY);
>
> exit;
>
>
>
> }
>
>
>
>
>
>
>
>
>
>
>
> /M
>
>
>
> __________________________________________________________
>
> Kamailio - Users Mailing List - Non Commercial Discussions -- [email protected]
>
> To unsubscribe send an email to [email protected]
>
> Important: keep the mailing list in the recipients, do not reply only to the sender!
>
>
>
> --
>
> Daniel-Constantin Mierla (@ asipto.com)
>
> twitter.com/miconda -- linkedin.com/in/miconda
>
> Kamailio Consultancy, Training and Development Services -- asipto.com
>
> __________________________________________________________
> Kamailio - Users Mailing List - Non Commercial Discussions --
> [email protected]
> To unsubscribe send an email to [email protected]
> Important: keep the mailing list in the recipients, do not reply only to
> the sender!
>
__________________________________________________________
Kamailio - Users Mailing List - Non Commercial Discussions -- [email protected]
To unsubscribe send an email to [email protected]
Important: keep the mailing list in the recipients, do not reply only to the sender!