Registrierungsproblem - was geht hier schief ?

betateilchen

Grandstream-Guru
Mitglied seit
30 Jun 2004
Beiträge
12,882
Punkte für Reaktionen
0
Punkte
0
Irgendjemand eine Idee ?

Code:
<-- SIP read from 84.163.90.248:5060:
REGISTER sip:pbx.gs-info.net SIP/2.0
Via: SIP/2.0/UDP 84.163.90.248;branch=z9hG4bKb2b267334
Content-Length: 0
To: 72 <sip:[email protected]>
From: 72 <sip:[email protected]>;tag=6b1e73623dd1656
Call-ID: [email protected]
CSeq: 1906374836 REGISTER
Contact: 72 <sip:[email protected]>
User-Agent: MxSipApp/4.5.6.42 MxSF/v3.2.7.33
Route: <sip:pbx.gs-info.net>


--- (10 headers 0 lines)---
Using latest REGISTER request as basis request
Sending to 84.163.90.248 : 5060 (non-NAT)
Transmitting (no NAT) to 84.163.90.248:5060:
SIP/2.0 100 Trying
Via: SIP/2.0/UDP 84.163.90.248;branch=z9hG4bKb2b267334;received=84.163.90.248
From: 72 <sip:[email protected]>;tag=6b1e73623dd1656
To: 72 <sip:[email protected]>
Call-ID: [email protected]
CSeq: 1906374836 REGISTER
User-Agent: Asterisk PBX
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY
Contact: <sip:[email protected]>
Content-Length: 0


---
Transmitting (no NAT) to 84.163.90.248:5060:
SIP/2.0 401 Unauthorized
Via: SIP/2.0/UDP 84.163.90.248;branch=z9hG4bKb2b267334;received=84.163.90.248
From: 72 <sip:[email protected]>;tag=6b1e73623dd1656
To: 72 <sip:[email protected]>;tag=as0f94219a
Call-ID: [email protected]
CSeq: 1906374836 REGISTER
User-Agent: Asterisk PBX
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY
Contact: <sip:[email protected]>
WWW-Authenticate: Digest realm="asterisk", nonce="5c7df880"
Content-Length: 0
 
Ich spreche normalerweise nicht SIP, aber... das sieht so aus, als würde der Request zunächst mal ohne Authentisierung über die Leitung gehen und dann kommt ein Authentisierungschallenge zurück:

WWW-Authenticate: Digest realm="asterisk", nonce="5c7df880"

Das sollte nun in Folge mit einem korrekten REGISTER mit diesem Token (nonce) und dem richtigen Response-Code beantwortet werden.

--gandalf.

PS: Das Thema Authentisierung ist bei SIP etwas häßlich, weil mit viel Rechenarbeit verbunden, wenn man das manuell nachvollziehen will, aber http://www.informatik.uni-bremen.de/~prelle/terena/cookbook/main/ch04s03.html ist eine gute Zusammenfassung.
 
Ich würde mal sagen, dass bisher noch alles normal aussieht. Die nächste Nachricht von deinem Client und die Antwort von Asterisk wäre interessant.
 
Maik schrieb:
Ich würde mal sagen, dass bisher noch alles normal aussieht. Die nächste Nachricht von deinem Client und die Antwort von Asterisk wäre interessant.

Schon klar ... das Dumme ist nur: Da kommt nicht mehr viel nach dem 401 :gruebel:

Code:
<-- SIP read from 84.163.79.98:5060:
REGISTER sip:pbx.gs-info.net SIP/2.0
Via: SIP/2.0/UDP 84.163.79.98;branch=z9hG4bK2402d4114
Content-Length: 0
To: 1011018 <sip:[email protected]>
From: 1011018 <sip:[email protected]>;tag=3fce43768f0988f
Call-ID: [email protected]
CSeq: 978863032 REGISTER
Contact: 1011018 <sip:[email protected]>
User-Agent: MxSipApp/4.5.6.42 MxSF/v3.2.7.33


--- (9 headers 0 lines)---
Using latest REGISTER request as basis request
Sending to 84.163.79.98 : 5060 (non-NAT)
Transmitting (no NAT) to 84.163.79.98:5060:
SIP/2.0 100 Trying
Via: SIP/2.0/UDP 84.163.79.98;branch=z9hG4bK2402d4114;received=84.163.79.98
From: 1011018 <sip:[email protected]>;tag=3fce43768f0988f
To: 1011018 <sip:[email protected]>
Call-ID: [email protected]
CSeq: 978863032 REGISTER
User-Agent: Asterisk PBX
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY
Contact: <sip:[email protected]>
Content-Length: 0


---
Transmitting (no NAT) to 84.163.79.98:5060:
SIP/2.0 401 Unauthorized
Via: SIP/2.0/UDP 84.163.79.98;branch=z9hG4bK2402d4114;received=84.163.79.98
From: 1011018 <sip:[email protected]>;tag=3fce43768f0988f
To: 1011018 <sip:[email protected]>;tag=as2bed64a8
Call-ID: [email protected]
CSeq: 978863032 REGISTER
User-Agent: Asterisk PBX
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY
Contact: <sip:[email protected]>
WWW-Authenticate: Digest realm="asterisk", nonce="28df5041"
Content-Length: 0


---
Scheduling destruction of call '[email protected]' in 15000 ms
vs4509*CLI>
<-- SIP read from 84.163.79.98:5060:
REGISTER sip:pbx.gs-info.net SIP/2.0
Via: SIP/2.0/UDP 84.163.79.98;branch=z9hG4bKc58fad09f
Content-Length: 0
To: 1012345 <sip:[email protected]>
From: 1012345 <sip:[email protected]>;tag=4dcff1acaf3ceef
Call-ID: [email protected]
CSeq: 922552752 REGISTER
Contact: 1012345 <sip:[email protected]>
User-Agent: MxSipApp/4.5.6.42 MxSF/v3.2.7.33


--- (9 headers 0 lines)---
Using latest REGISTER request as basis request
Sending to 84.163.79.98 : 5060 (non-NAT)
Transmitting (no NAT) to 84.163.79.98:5060:
SIP/2.0 100 Trying
Via: SIP/2.0/UDP 84.163.79.98;branch=z9hG4bKc58fad09f;received=84.163.79.98
From: 1012345 <sip:[email protected]>;tag=4dcff1acaf3ceef
To: 1012345 <sip:[email protected]>
Call-ID: [email protected]
CSeq: 922552752 REGISTER
User-Agent: Asterisk PBX
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY
Contact: <sip:[email protected]>
Content-Length: 0


---
Transmitting (no NAT) to 84.163.79.98:5060:
SIP/2.0 401 Unauthorized
Via: SIP/2.0/UDP 84.163.79.98;branch=z9hG4bKc58fad09f;received=84.163.79.98
From: 1012345 <sip:[email protected]>;tag=4dcff1acaf3ceef
To: 1012345 <sip:[email protected]>;tag=as240e5138
Call-ID: [email protected]
CSeq: 922552752 REGISTER
User-Agent: Asterisk PBX
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY
Contact: <sip:[email protected]>
WWW-Authenticate: Digest realm="asterisk", nonce="123c9219"
Content-Length: 0


---
Scheduling destruction of call '[email protected]' in 15000 ms
Destroying call '[email protected]'
Destroying call '[email protected]'

Der Adapter versucht, sich als 71 und 72 am Asterisk zu registrieren. Und das ist alles was davon im SIP-Debug zu sehen ist.
 
Ich würde mal ein Ethereal auf das Netz setzen, um den gesamten SIP-Dialog in einem lesbareren Paketformat zu sehen. Vielleicht unterschlägt hier jemand ein paar Pakete ;-)

Generell ist 401 an dieser Stelle wohl ok, da keine korrekte Authentisierung erfolgte. Auf die Antwort 401 mit WWW-Authenticate Header und nonce sollte nun ein REGISTER mit korrekt verschlüsselter Antwort "nonce + response" folgen.

Vielleicht kommt das auch, aber der Asterisk sieht das Paket nicht mehr... Wie gesagt, ein Ethereal würde weiterhelfen...

Und nun erst mal gute Nacht! ;-)
--gandalf.
 
So wie es aussieht ignoriert dein Endgerät die Antworten von Asterisk, weil der Contact-Header nicht korrekt übernommen wurde.
 
Kostenlos!

Statistik des Forums

Themen
248,887
Beiträge
2,303,970
Mitglieder
378,564
Neuestes Mitglied
warumdas