[26710] in resnet

home help back first fref pref prev next nref lref last post

Re: Firewall drops video conferencing packets

daemon@ATHENA.MIT.EDU (Mike King)
Tue Sep 6 12:35:52 2011

MIME-Version: 1.0
Content-Type: multipart/alternative; boundary=000e0cd47e72a6da2504ac483cd8
Message-ID:  <CANtPpk4h9i8BZNp=UJ0OdurX1w-cFpgSXKcpCkrgQZ=Wh=L=PQ@mail.gmail.com>
Date:         Tue, 6 Sep 2011 12:22:41 -0400
Reply-To: Resnet Forum <RESNET-L@listserv.nd.edu>
From: Mike King <me@mpking.com>
To: RESNET-L@listserv.nd.edu
In-Reply-To:  <CAF03826CDC19848A698E99DC608B54702D0634E@vEXMB1.clarion.local>

--000e0cd47e72a6da2504ac483cd8
Content-Type: text/plain; charset=ISO-8859-1

IWelcome to the world of application aware Firewalls.

I'm betting you are running into an Inspection error.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a008085283d.shtml

I would do the following:

policy-map global_policy
 class inspection_default
no inspect h323 h225
no inspect h323 ras


I have cisco IP phones, and I ALWAYS have to remove the skinny from my
ASA's, because they often do not support the correct version of the skinny
protocol.  (At the time I hit the issue, The phones were on Version 19 of
SCCP, but the ASA only understood Version 15)

This may not be your issue, but I wouldn't be surprised if it is.

Mike


On Tue, Sep 6, 2011 at 10:04 AM, Christopher Hickernell <
chickernell@clarion.edu> wrote:

>  Has anyone else experienced a problem with video conferencing traffic
> crossing the firewall?  We have various models of Polycom units (HDX 8000
> HD, HDX 9004, VS4000) that have trouble when they have to cross our Cisco
> ASA to connect to another unit.  A connection is always established, but
> sometimes video and audio do not work, sometimes content cannot be sent,
> etc.****
>
> ** **
>
> Monitoring the firewall logs I observed this error:****
>
> ** **
>
> Deny IP from Montgomery-416.itv.clarion.edu to Still-111, IP options:
> "Router Alert"****
>
> ** **
>
> * *
>
> *Christopher* Hickernell, CCNA, MCSE****
>
> *Network Support Specialist, ResNet Manager*
>
> Clarion University of Pennsylvania**
>
> Center for Computing Services**
>
> G-13 Still Hall, Clarion, PA 16214****
>
> chickernell@clarion.edu | 814.393.2218****
>
> ** **
>
> ** **
>  ___________________________________________________ You are subscribed to
> the ResNet-L mailing list.
>
> To subscribe, unsubscribe or search the archives, go to
> http://LISTSERV.ND.EDU/archives/resnet-l.html___________________________________________________
>

___________________________________________________
You are subscribed to the ResNet-L mailing list.

To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________

--000e0cd47e72a6da2504ac483cd8
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

IWelcome to the world of application aware Firewalls.<div><br></div><div>I&=
#39;m betting you=A0are running into an Inspection error.</div><div><br></d=
iv><div><a href=3D"http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/pr=
oducts_tech_note09186a008085283d.shtml">http://www.cisco.com/en/US/products=
/hw/vpndevc/ps2030/products_tech_note09186a008085283d.shtml</a></div>
<div><br></div><div>I would do the following:</div><div><span class=3D"Appl=
e-style-span" style=3D"font-family: arial, helvetica, sans-serif; font-size=
: 12px; "><pre style=3D"font-size: 15px; ">policy-map global_policy
 class inspection_default
no inspect h323 h225=20
no inspect h323 ras </pre></span></div><div><div><br>I have cisco IP phones=
, and I ALWAYS have to remove the skinny from my ASA&#39;s, because they of=
ten do not support the correct version of the skinny protocol. =A0(At the t=
ime I hit the issue, The phones were on Version 19 of SCCP, but the ASA onl=
y understood Version 15)</div>
<div><br></div><div>This may not be your issue, but I wouldn&#39;t be surpr=
ised if it is.</div><div><br></div><div>Mike</div><div><br></div><div><br><=
div class=3D"gmail_quote">On Tue, Sep 6, 2011 at 10:04 AM, Christopher Hick=
ernell <span dir=3D"ltr">&lt;<a href=3D"mailto:chickernell@clarion.edu">chi=
ckernell@clarion.edu</a>&gt;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex;">





<div lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div>
<p class=3D"MsoNormal">Has anyone else experienced a problem with video con=
ferencing traffic crossing the firewall?=A0 We have various models of Polyc=
om units (HDX 8000 HD, HDX 9004, VS4000) that have trouble when they have t=
o cross our Cisco ASA to connect to
 another unit.=A0 A connection is always established, but sometimes video a=
nd audio do not work, sometimes content cannot be sent, etc.<u></u><u></u><=
/p>
<p class=3D"MsoNormal"><u></u>=A0<u></u></p>
<p class=3D"MsoNormal">Monitoring the firewall logs I observed this error:<=
u></u><u></u></p>
<p class=3D"MsoNormal"><u></u>=A0<u></u></p>
<p class=3D"MsoNormal">Deny IP from <a href=3D"http://Montgomery-416.itv.cl=
arion.edu" target=3D"_blank">Montgomery-416.itv.clarion.edu</a> to Still-11=
1, IP options: &quot;Router Alert&quot;<u></u><u></u></p>
<p class=3D"MsoNormal"><u></u>=A0<u></u></p>
<p class=3D"MsoNormal"><b><u></u>=A0<u></u></b></p>
<p class=3D"MsoNormal"><b>Christopher</b> Hickernell, CCNA, MCSE<u></u><u><=
/u></p>
<p class=3D"MsoNormal"><i>Network Support Specialist, ResNet Manager<u></u>=
<u></u></i></p>
<p class=3D"MsoNormal">Clarion University of Pennsylvania<i><u></u><u></u><=
/i></p>
<p class=3D"MsoNormal">Center for Computing Services<i><u></u><u></u></i></=
p>
<p class=3D"MsoNormal">G-13 Still Hall, Clarion, PA 16214<u></u><u></u></p>
<p class=3D"MsoNormal"><a href=3D"mailto:chickernell@clarion.edu" target=3D=
"_blank">chickernell@clarion.edu</a> | <a href=3D"tel:814.393.2218" value=
=3D"+18143932218" target=3D"_blank">814.393.2218</a><u></u><u></u></p>
<p class=3D"MsoNormal"><u></u>=A0<u></u></p>
<p class=3D"MsoNormal"><u></u>=A0<u></u></p>
</div>
</div>

___________________________________________________
You are subscribed to the ResNet-L mailing list.
<p>
To subscribe, unsubscribe or search the archives,
go to <a href=3D"http://LISTSERV.ND.EDU/archives/resnet-l.html" target=3D"_=
blank">http://LISTSERV.ND.EDU/archives/resnet-l.html</a>
___________________________________________________
</p></blockquote></div><br></div></div>
___________________________________________________
You are subscribed to the ResNet-L mailing list.
<p>
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________

--000e0cd47e72a6da2504ac483cd8--

home help back first fref pref prev next nref lref last post