Timeout NAT session

Options

Good morning everyone,
I have this question: What can happen to the firewall if it blocks 4 to 10 access requests every minute? Could it affect some devices on the internal lan that need to maintain active NAT sessions?
Because sometimes IP phones show "No Service" for 1 or 2 minutes and then come back to work.
I have a USG FLEX 50 (USG20-VPN), connected via wan with public IP on Vodafone connection.

And I set NAT session with command "session timeout udp-connect 120 "

Thank you

All Replies

  • osake_li_09
    osake_li_09 Posts: 9
    First Anniversary Friend Collector First Comment
    edited June 2023
    Options

    @Gabriele

    session timeout udp-connect 120 means the timeout for UDP sessions to connect or deliver and for ICMP sessions. You may want to verify with the phone manufacturer/provider to see how often the phone checks registration and then increase UDP session timeout.

    And 10 access blocks every minute, I also don't it would cause a flood attack.

  • Zyxel_James
    Zyxel_James Posts: 624  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    UDP session with VoIP service may be timing out causing the phones to lose connection. Please try Increasing the UDP session timeout to 180 seconds or more.

    Do you enable SIP ALG?

    Did the monitor log show anything while no service?

Security Highlight