Hello everyone,

I have onsite a CIX 670 system with a few 16 port IP Cards. Our remote site connected via Site To Site VPN has about 20 IP phones (IP5022) connected. We had some speed issues on the remote end earlier today and it turns out within a matter of just a few minutes several of the Toshiba IP phones connected to there perspective IP cards here at the main site and transferred a bunch of data. Around 10 phones transferring 6 gigs in just a few minutes. Pulling logs from the firewall I see the most significant data traffic was over TCP port 2944 which looks to be part of the telephony system as mentioned here. https://wiki.wireshark.org/H248/MEGACO . Anyone have any idea what could be causing this ? Perhaps some type of firmware upgrade trying to be pushed by the system? I doubt its phone(talk) traffic since I usually see that on upper UDP ports. I changed all the codecs for those phones in emanager from G711 to G729A in hopes that it helps. Which I doubt since again the phone traffic should be UDP not TCP. Anyway I was hoping maybe some otehrs have had similar issues and could give me some info on what to do troubleshoot or correct it. There are no Vlans or QOS in place to prioritize any of the traffic so that could also cause problems.

Thank you in advance for any help.