跳转到主要内容

Juniper SSG防火墙 SIP呼出失败案例

故障描述

  某移动呼叫中心,使用SSG520M-SH做出口网关,大部分座席可以SIP协议呼出,部分无法呼出,

故障分析

  进入Juniper SSG防火墙用get event查看日志如下:

SSG520-> get event
Total event entries = 3072
Date       Time     Module Level  Type Description
2014-06-18 16:35:12 system notif 00767 Cannot allocate SIP call because
                                       device is fielding too many calls.
2014-06-18 16:35:12 system notif 00767 Cannot allocate SIP call because
                                       device is fielding too many calls.
2014-06-18 16:35:11 system notif 00767 Cannot allocate SIP call because
                                       device is fielding too many calls.
2014-06-18 16:35:11 system notif 00767 Cannot allocate SIP call because
                                       device is fielding too many calls.

上述日志确定,SIP资源不足无法创建。

SSG520-> get sip setting
SIP ALG                                    : enabled
Maximum number of SIP Calls                : 192
Maximum Call Duration                      : 43200 seconds
Inactive Media timeout                     : 120 seconds
T1 interval                                : 500 milli seconds
T4 interval                                : 5 seconds
C interval                                 : 3 minutes
 SIP hold retain resource                  : Disabled
SIP Application Screen Configuration
-------------------------------------
 Unidentified messages in nat mode         : dropped
 Unidentified messages in route mode       : passed
 SIP denial of service protect timeout     : 5
 SIP global denial of service protect      : Disabled
 SIP denial of service protect server IP   :

查看最大会话为192.

SSG520-> get sys-cfg | in sip
default sip call num number: 192
max sip call num number: 384

默认为192.最大SIP 呼叫为384.

处理过程

  SSG520->set envar max_sip_call_num=384  //修改SIP最大Call-Num为384,
  SSG520-> save //保存
  SSG520-> reset //重启

重启后显示如下

SSG520-> get alg sip setting
SIP ALG                                    : enabled
Maximum number of SIP Calls                : 384
Maximum Call Duration                      : 43200 seconds
Inactive Media timeout                     : 120 seconds
T1 interval                                : 500 milli seconds
T4 interval                                : 5 seconds
C interval                                 : 3 minutes
 SIP hold retain resource                  : Disabled
SIP Application Screen Configuration
-------------------------------------
 Unidentified messages in nat mode         : dropped
 Unidentified messages in route mode       : passed
 SIP denial of service protect timeout     : 5
 SIP global denial of service protect      : Disabled
 SIP denial of service protect server IP   :

 

 

建议/总结

  无