Objective
Configure an Untangle firewall to use with 8x8 services.
Applies To
- Untangle Firewalls
General Information
The purpose of this article is to provide a sample configuration. At the time of article creation, this device was in a known working state on the firmware used.
Keep in mind different firmware versions will interact with hosted VoIP services in different ways. While this device may be fully functional on the tested and/or current firmware version, it is possible newer revisions will cause disruptions in service or make a device fully compliant with the required settings for hosted VoIP services where it was previously not.
Note: User guide for Untangle firewall is available on their wiki page.
Administrative Information
- In a browser on a computer on the same network as the Untangle firewall, navigate to your Untangle device IP address you have assigned to it.
- Log in with admin and password credentials (This is the password you set when you initially setup Untangle. Password recovery can also be found on their wiki page.
This has been tested on Untangle version 14.0.0.
Adding/editing 8x8 subnets is recommended when available. Review the Traffic Shaping and Specific Subnet/Port Configuration section of X Series Technical Requirements.
Procedure
Enabling Bypass VoIP
- Click on Config at the top of the page.
- Click Network
- Click Bypass Rules
- Make sure Bypass VoIP is checked
dding 8x8 Subnets
- Click on Config at the top of the page
- Click Network
- Click Filter Rules
- Click Add
- Set description 8x8 Subnets
- Click Add Condition
- Select Destination Address (ex. 8x8 West DC 1, 8x8 East DC 2)
- Add 8x8 Subnets
Uncheck Enable SIP NAT Helper
- Click on Config at the top of the page
- Click Network
- Click Advanced
- Under Options Tab, Uncheck Enable SIP NAT Helper
Setting up Access Rules
- Click on Config at the top of the page
- Click Network
- Click Advanced
- Click Access Rules
- Click Add
- Set the description for each subnet (ex. 8x8 West DC 1, 8x8 East DC 2)
- Click Add Condition
- Select Destination Address
- Add each subnet
Allowing Session through Shield
- Click on Config on the top of the page
- Click System
- Click Shield
- Click Add
- Click Add Condition
- Destination Address: IS
- Add 8x8 Subnets
- Select Action and then Pass