<html><head></head><body><div class="ydpe722751ayahoo-style-wrap" style="font-family: Helvetica Neue, Helvetica, Arial, sans-serif; font-size: 13px;"><div></div>
<div dir="ltr" data-setdir="false">Hi Razvan,</div><div dir="ltr" data-setdir="false"><br></div><div dir="ltr" data-setdir="false">Thanks for reply. </div><div dir="ltr" data-setdir="false">But let me describe the scenario better:</div><div dir="ltr" data-setdir="false">Clients must have TLS connection and we have an OpenSIPS cluster on the front of Asterisk servers. So in this case, if client's connection with one SIP proxy node goes down, it should be re-establish with other node in cluster? or as all cluster nodes are using shared DB and they talk to each other via BIN, client connection remains? thanks.</div><div dir="ltr" data-setdir="false"><br></div><div dir="ltr" data-setdir="false">Regards.</div><div dir="ltr" data-setdir="false"><br></div><div dir="ltr" data-setdir="false"><br></div><div><br></div>
</div><div id="ydpbc85b436yahoo_quoted_0428132246" class="ydpbc85b436yahoo_quoted">
<div style="font-family:'Helvetica Neue', Helvetica, Arial, sans-serif;font-size:13px;color:#26282a;">
<div>
On Monday, January 4, 2021, 01:04:34 AM PST, Răzvan Crainea <razvan@opensips.org> wrote:
</div>
<div><br></div>
<div><br></div>
<div><div dir="ltr">Hi, Yavari!<br clear="none"><br clear="none">Happy new year!<br clear="none">No, this is not possible - OpenSIPS is only able to route packages based <br clear="none">on SIP packets - if you create an end-to-end connection between the <br clear="none">client and media servers, OpenSIPS will not be able to decrypt the <br clear="none">packages to know where to send what. OpenSIPS (and the entire SIP stack, <br clear="none">by specifications) is not connection oriented, so packets can't be <br clear="none">routed based on a previously established connection, only by SIP headers.<br clear="none"><br clear="none">Best regards,<br clear="none"><br clear="none">Răzvan Crainea<br clear="none">OpenSIPS Core Developer<br clear="none"><a shape="rect" href="http://www.opensips-solutions.com" rel="nofollow" target="_blank">http://www.opensips-solutions.com</a><br clear="none"><div class="ydpbc85b436yqt0295362242" id="ydpbc85b436yqtfd43591"><br clear="none">On 12/31/20 2:57 AM, H Yavari via Users wrote:<br clear="none">> Hi to all,<br clear="none">> <br clear="none">> Happy holidays.<br clear="none">> <br clear="none">> In a distributed scenario, is it possible to have a TLS transparent with <br clear="none">> Opensips?<br clear="none">> I mean clients make TLS connection with the nodes behind the proxy <br clear="none">> server/load balancer and next time they can connect to the other nodes <br clear="none">> but TLS connection is end to end between client and media server (AS/FS <br clear="none">> etc.).<br clear="none">> Please advise.<br clear="none">> <br clear="none">> Regards,<br clear="none">> HYavari</div><br clear="none">> <br clear="none">> <br clear="none">> <br clear="none">> <br clear="none">> _______________________________________________<br clear="none">> Users mailing list<br clear="none">> <a shape="rect" href="mailto:Users@lists.opensips.org" rel="nofollow" target="_blank">Users@lists.opensips.org</a><br clear="none">> <a shape="rect" href="http://lists.opensips.org/cgi-bin/mailman/listinfo/users" rel="nofollow" target="_blank">http://lists.opensips.org/cgi-bin/mailman/listinfo/users</a><br clear="none">> <br clear="none"><br clear="none">_______________________________________________<br clear="none">Users mailing list<br clear="none"><a shape="rect" href="mailto:Users@lists.opensips.org" rel="nofollow" target="_blank">Users@lists.opensips.org</a><br clear="none"><a shape="rect" href="http://lists.opensips.org/cgi-bin/mailman/listinfo/users" rel="nofollow" target="_blank">http://lists.opensips.org/cgi-bin/mailman/listinfo/users</a><div class="ydpbc85b436yqt0295362242" id="ydpbc85b436yqtfd37814"><br clear="none"></div></div></div>
</div>
</div></body></html>