New SIP ALG configuration options What’s new in FortiOS Version 4.0 MR1
FortiGate Version 4.0 MR1 Administration Guide
34 01-410-89802-20090903
http://docs.fortinet.com/ • Feedback
• Logging enhancements
• Antivirus changes
• Reliable syslog
• Web filtering combined block/exempt list
• Web filtering by content header
• Safe search
• Data Leak Prevention supports international character sets
• SNMPv3 enhancements
• Schedule groups
New SIP ALG configuration options
The following SIP application level gateway (ALG) configuration options for have been
added to FortiOS 4.0 MR1. You can configure these options from the CLI using the
following command:
config application list
edit <list_name>
config entries
edit 1
set category voip
set application SIP
set open-register-pinhole {disable | enable}
set open-contact-pinhole {disable | enable}
set rfc2543-branch {disable | enable}
end
end
Opening and closing SIP register and non-register pinholes
You can use open-register-pinhole and open-contact-pinhole to control
whether the FortiGate unit opens register and non-register pinholes. Non-register pinholes
are usually opened for SIP invite requests.
For more information, see “Opening and closing SIP register and non-register pinholes”
on page 515.
Support for RFC 2543-compliant branch commands
The rfc2543-branch CLI keyword of the config application list command has
been added to support RFC 2543-complaint SIP calls involving branch commands that
are missing or that are valid for RFC 2543 but invalid for RFC 3261.
For more information, see “Support for RFC 2543-compliant branch commands” on
page 516.