– Kamailio SIP Server –

Audio only works one way, when connected with client behind nat

Answer

  1. install mediaproxy module
  2. install mediaproxy dispatcher
  3. install mediaproxy server

Follow the install procedure and try using this openser.cfg :

#
 
# ----------- global configuration parameters ------------------------
 
#debug=3         # debug level (cmd line: -dddddddddd)
 
#fork=yes
 
#log_stderror=no        # (cmd line: -E)
 
#log_facility=LOG_LOCAL0
 
/* Uncomment these lines to enter debugging mode
 
fork=no
 
log_stderror=yes
 
*/
 
check_via=no    # (cmd. line: -v)
 
dns=no           # (cmd. line: -r)
 
rev_dns=no      # (cmd. line: -R)
 
#port=5060
 
#children=4
 
fifo="/tmp/openser_fifo"
 
# ------------------ module loading ----------------------------------
 
# Uncomment this if you want to use SQL database
 
loadmodule "/usr/local/openser/lib/openser/modules/mysql.so"
 
loadmodule "/usr/local/openser/lib/openser/modules/domain.so"
 
loadmodule "/usr/local/openser/lib/openser/modules/mediaproxy.so"
 
loadmodule "/usr/local/openser/lib/openser/modules/uri_db.so"
 
loadmodule "/usr/local/openser/lib/openser/modules/sl.so"
 
loadmodule "/usr/local/openser/lib/openser/modules/tm.so"
 
loadmodule "/usr/local/openser/lib/openser/modules/rr.so"
 
loadmodule "/usr/local/openser/lib/openser/modules/maxfwd.so"
 
loadmodule "/usr/local/openser/lib/openser/modules/usrloc.so"
 
loadmodule "/usr/local/openser/lib/openser/modules/registrar.so"
 
loadmodule "/usr/local/openser/lib/openser/modules/textops.so"
 
# Uncomment this if you want digest authentication
 
# mysql.so must be loaded !
 
loadmodule "/usr/local/openser/lib/openser/modules/auth.so"
 
loadmodule "/usr/local/openser/lib/openser/modules/auth_db.so"
 
# ----------------- setting module-specific parameters ---------------
 
# -- usrloc params --
 
modparam("usrloc", "db_mode",   0)
 
# Uncomment this if you want to use SQL database
 
# for persistent storage and comment the previous line
 
modparam("usrloc", "db_mode", 2)
 
# -- auth params --
 
# Uncomment if you are using auth module
 
#
 
modparam("auth_db", "calculate_ha1", yes)
 
#
 
# If you set "calculate_ha1" parameter to yes (which true in this config),
 
# uncomment also the following parameter)
 
#
 
modparam("auth_db", "password_column", "password")
 
# -- rr params --
 
# add value to ;lr param to make some broken UAs happy
 
modparam("rr", "enable_full_lr", 1)
 
modparam("mediaproxy", "natping_interval", 60)
 
modparam("registrar",  "nat_flag",         2)
 
# -------------------------  request routing logic -------------------
 
# main routing logic
 
route{
 
        # initial sanity checks -- messages with
        # max_forwards==0, or excessively long requests
        if (!mf_process_maxfwd_header("10")) {
                sl_send_reply("483","Too Many Hops");
                break;
        };
        if (msg:len >=  2048 ) {
                sl_send_reply("513", "Message too big");
                break;
        };
 
 
        # we record-route all messages -- to make sure that
        # subsequent messages will go through our proxy; that's
        # particularly good if upstream and downstream entities
        # use different transport protocol
        if (!method=="REGISTER") record_route();
 
        # subsequent messages withing a dialog should take the
        # path determined by record-routing
        if (loose_route()) {
                # mark routing logic in request
                append_hf("P-hint: rr-enforced\r\n");
                route(1);
                break;
        };
 
        if (!uri==myself) {
                # mark routing logic in request
                append_hf("P-hint: outbound\r\n");
                route(1);
                break;
        };
 
        # if the request is for other domain use UsrLoc
        # (in case, it does not work, use the following command
        # with proper names and addresses in it)
        if (uri==myself) {
 
                if (method=="REGISTER") {
                       # Uncomment this if you want to use digest authentication
                       if (!www_authorize("sip.com", "subscriber")) {
                               www_challenge("sip.com", "0");
                               break;
                       };
 
                       if (client_nat_test("3")) {
                               setflag(2);
                               force_rport();
                               fix_contact();
                       };
 
                       save("location");
                       break;
 
                };
 
                lookup("aliases");
                if (!uri==myself) {
                        append_hf("P-hint: outbound alias\r\n");
                        route(1);
                        break;
                };
 
                # native SIP destinations are handled using our USRLOC DB
                if (!lookup("location")) {
                        sl_send_reply("404", "Not Found");
                        break;
                };
        };
 
        if (method=="INVITE") {
                t_on_failure("1");
        } else if (method == "BYE" || method == "CANCEL") {
                end_media_session();
        };
 
        if (loose_route()) {
                if (method=="INVITE" || method=="ACK") {
                        use_media_proxy();
                };
                t_relay();
                break;
        };
 
        if (client_nat_test("3") && !search("^Record-Route:")) {
                # Mark as NAT'ed
                force_rport();
                fix_contact();
        };
 
        if (method=="INVITE") {
                t_on_reply("1");
        };
 
        if (method=="INVITE" || method=="ACK") {
                use_media_proxy();
        };
 
        if (!t_relay()) {
            if (method=="INVITE" || method=="ACK") {
                end_media_session();
            };
            sl_reply_error();
        };
 
        append_hf("P-hint: usrloc applied\r\n");
        # route(1);
 
}
 
route[1]
{
        # send it out now; use stateful forwarding as it works reliably
        # even for UDP2TCP
        if (!t_relay()) {
                sl_reply_error();
        };
}
 
failure_route[1] {
    end_media_session();
}
 
onreply_route[1] {
    if (status=~"(183)|(2[0-9][0-9])") {
        if (client_nat_test("1")) {
            fix_contact();
        };
        use_media_proxy();
    };
}

Troubleshooting Stuff