Wi-Fi Calling operational issues in routers when blocking IPSec

Hello Peplink Team & Peplink Community,
We have found an issue with Wi-Fi Calling settings when using the Content Filtering in the Balance Routers (tested on a Balance One & a Balance 580, will check soon on a MAX router). Our client needs to block the Security / Tunnelling protocol of IPSec; the issue is that Wi-Fi Calling requires this protocol. We have attempted to put into the exemptions of the Content Filtering using, the Web Blocking, the URL necessary of pub.3gppnetwork.org though without success in allowing Wi-Fi Calling to work.

This is a significant problem for our clients as they have setups in areas where there is no mobile/cellular coverage and are dependant on Wi-Fi calling for business operations.

These are URLs to resources we have referenced in our attempts to get this working
https://forums.whirlpool.net.au/archive/2638260

We have found the issues with both Firmware 7.1.2GA and 8.0.0RC4, we may have missed something in making this work and would be grateful for input from both Peplink & the Peplink Community for a solution.
Appreciate your assistance,
Marcus :slight_smile:

2 Likes

@mldowling

IPSEC application blocking & the Web Blocking work differently. The Exempted Domain from Web Blocking will not exempt the IPSEC blocking.

Possible to arrange for us to check on the WI-FI calling application that you have ? We need to check under which conditions that the application is block in-order to work on the improvement. Would you please open a ticket on this and ATTN the ticket to me ?

1 Like

Hello @sitloongs,
Ticket number 9040680
Happy to Help,
Marcus :slight_smile:

Hello @sitloongs,
It looks like to make Wi-Fi Calling work the content filtering needs to also have a new option of “Exempted Domains from Application Blocking”.

The ticket has been updated with some tests results using FW 8.0.1 RC4.

A question to the community, has anyone else worked out a way around getting Wi-Fi Calling to work while blocking IPsec (customer want to block all VPN traffic except Wi-Fi calling)?

Happy to Help,
Marcus :slight_smile:

@mldowling

Engineering team is looking at this. I have your ticket with me now.

1 Like

Are you able to share the solution on this ?

I am also having the same requirement.

Thanks.

@mldowling Instead of application blocking could you use firewall rules to block ports 500 and 4500 for any destination and above that rule allow it for pub.3gppnetwork.org?