Cisco Firewall :: PIX 525 - Unable To Do Polycom Video Conferencing
Jul 20, 2011
I have this problem with the Polycom Video Conferencing (HDX 7000) While we can initiate a video call to other locations, we can not receive a video call from other locations. Whenever there is a incoming call, the polycom is ringing fine. but once we answer the call, the call will be disconnected. Our access rules are listed below, 203.125.99.99 is our public IP for example.
We have just acquired a cisco profile 42 video conferencing equipment and am required to open ports for SIP and H232, any pointers on hw that can be acquired i have a cisco ASA 5510, Some one told me to open port 16384 but i need pointers on how to do it becuase I already set an access list to any.
the config
Internet -> ASA 5510 -> Switch -> Profile 42 and other devices
The problem is that calls originating from the outside of the firewall to the inside will ring but you cannot answer. The internal video conference server is a Polycom HDX 7000. There are ANY/ANY rules to/from this server and the default application inspection policy is set for h323/ras/h225 as follows:
I'm trying to put together the best scenario for a large business to set up videoconferencing between users within the states and overseas. From my understanding, the company would have to set up a MCU to manage multiple audiovisual sessions. Then implement an SIP software such as Asterisk, with a registrar server to maintain a database with information about the network addresses of each user on the domain.The diagram in my head is something like this:
i want to establish a video conferencing system based using desktop computers so that at a time about 7-8 users are in a video conference simultaneosly. i have the media connectivity already established i.e on OFC. will i have to make a server.
We have a Cisco 1841 router at Branch end and a Cisco 2821 router at the HO connected by a 2MB Leased line. There is a Video Conferencing device setup in the branch office . We want to reserve 1MB bandwidth for the video conferencing and leave the remaining BW for Data . The traffic between the locations is passed through the tunnel using the static routes .
Site A Cisco 2911 -- 2 T1 WIC. One going to Site B 1841 another going to Site C 1841.I am looking for a way to setup a Polycom QOS, judging by several forum posts about this, would it be better to create an access list with the Polycom IPs to limit the bandwidth to 512Kbps? Or if not, a link for Polycom QOS configs? What is happening is when noone else is using the connection except for the video conference, after about an hour with the T1 not being 100 % utilized, the 2911 GE0/0 interface will start developing input queue errors. What I usually have to do is reboot the router at night and that alleviates the problem since regular data traffic will not cause this problem.
Current configuration : 3529 bytes version 15.0 service timestamps debug datetime msec service timestamps log datetime msec localtime show-timezone year service password-encryption [Code] .....
I have only seen this problem with several video conferences from one location. Currently there is only one T1 connection from our HQ to remote location. When two conference calls are set to use 256Kbps connection to come back to the main HQ, after an hour or so the T1 connection would drop. What I mean about drop is that the route on the 2911 will disappear. I have to wait about 10 minutes for the connection to come back up or I have to reboot the router for the connection to appear again. There are no interface drops on the serial connections or ethernet connections.
HQ - 2911 Remote - 1821 2911 running config: Current configuration : 3529 bytes ! version 15.0 service timestamps debug datetime msec
I am encountering some problems setting up my new polycom hdx 8000 behind ASA 5540?I have opened reuired ports through the firewall ( incoming and outgoing). I have enabled inspection h323 on ASA and enabled the option NAT is 323 compatible on Polycom.
3230-3243 tcp h323 tcp h323 udp 3230-3285 udp
Here is the problem.I get connected to the call but I cannot the remote site cannot see and hear me.But I can see and hear them.
We are trying to get a video conference system (POLYCOM) up running. Thrue a Cisco 1812 router with Firewall feature set.
I Have heard in the past that there should be issues with Polycom and Cisco, but have actually never seen it.I can establish a video call from inside the 1812 to outside.
But when I try from outside to the public ip adress there is nattet to, then it reach the video system and die straight after, so there is never any video session set up.
I have tried to remove everything regarding firewall feature and passing true, so the only thing the 1812 should do is NAT. And still the same.
I can not see anything in the log on the router from the ACL's where I permittet everything, other then it connect on the port TCP 1720, as it should. This is the software I'm running on the router:
When I search Google, it look like there is a lot issues with Cisco and Polycom, but I have not found any concret solution. Other then I should use a ADSL line with a public IP address. As we probably is going to do.
Config nat(inside) 1.0.0.0.0.0.0.0.0 match ip inside andy inside any dynamic translaion to pool 1 (matching global) translate_hits=45236,untranslate_hits=0
I cannot access my polycom unit on 172.20.16.8 via 10.20.60.8 below is my results of show run Result of the command: "show run"
I am trying to set up a Cisco ASA 5510 running 8.2 to allow a connection to a Polycom camera that sits behind it. What I want to do is forward multiple ports to allow a connection from an outside office. The polycom camera uses the following ports:
1720 tcp 3230-3235 tcp 3230-3253 udp
I got these port numbers from the Polycom web site. So what I did was create a service object as follows:
object-group service All-Polycom-ports service-object tcp range 3230 3235 service-object tcp eq h323 service-object udp range 3230 3253 My question is how can I use this service object in a static (inside,outside)
command so that I don't have to create multiple commands for the port forwarding. Is this even possible or do I have to sit down and write out around 30 seperate commands to do this. I've been searching the web and it seems a lot of people want to do this but so far I haven't found an answer.
My camera saves video as .avi files, but when I open them in Media Player, all I get is sound. The camera works fine, as I can view live video, but the saved files show nothing, just have sound.
I recently bought 3 DCS-920 to monitor my home while at the office. However I can't seem to get the damned things to stream video using the dyndns service. I linked my router to the dyndns account and host service. I portforward the ports my cameras are assigned. Up to this point its all good, I can access the cameras and their settings pages while outside. However both the Java and ActiveX options for video streaming do not work. Even within the network, using their raw IPs to view the cameras the videos stream works.But putting in the hostname and port they are assigned brings up the camera page, but no video.I can only assume the ports the video and audio run on are seperate, as when I put one camera's IP in the DMZ host on my router, it works with the DNS. Unforunately I can only do that with 1, and I'd rather not do that at all.
I am current trying to configure the network settings on a standalone DVR.I have been doing trial and error all day long to get a 'SUCCESS' on a 'check' while entering the DDNS SVC information.After figuring out that the IP Configuration & Allocation of the Network in the router was messed up, I finally got the DDNS SVC to give me a 'SUCCESS' reading. Thus, enabling me to remotely access the digital video recorder via a Internet Browser.Here's the catch ;I am only able to access the DVR from the PC that has the configuration of the network. (example 10.0.0.1)and the settings on the DVR have been set to :IP : 10.0.0.5ubnet Mask :255.255.255.0Gateway : 10.0.0.1DNS : 10.0.0.1Port of device is set to 20410.So entering http://10.0.0.5:20410 directs me to the webclient that enables me to remotely access the device
i play with my brandnew 942L Camera and everything works fine. The only thing i cannot get to work is to play recorded videos from the playlist on my mobile phone.I use myDLink Lite and the video-settings in the 942L for profile 4 (mobile devices) is set to MPEG4, 320x240, 5 BPS, CBR Quality, 384kb/s, "3gpp".
Setup my DCS-930L for DDNS (Dynamic Domain Name Server) so I can access the DCS-930L via the Internet (couldn't access the camera half the the time while on vacation using mydlink) and can now access the camera using my laptop, Android Thrive, and Motorola Droid 3 via the URL I've created but can only see the video when using the laptop.
I have the DCS-930L set to Java but when I log into the camera with the Thrive or Droid 3 (both Android devices) I don't get video. I can make changes to the camera settings and everything else you can do when logged into the camera but just can't see the video. If I change the 'View Mode' in the video setup to 'Image', I will get a picture on all three devices (Thrive, Droid 3, and laptop).What do I need on the Droid 3 & Thrive so I can see the video when I log into the DCS-930L with an Android device?
Setup my DCS-930L for DDNS (Dynamic Domain Name Server) so I can access the DCS-930L via the Internet (couldn't access the camera half the the time while on vacation using mydlink) and can now access the camera using my laptop, Android Thrive, and Motorola Droid 3 via the URL I've created but can only see the video when using the laptop.
I have the DCS-930L set to Java but when I log into the camera with the Thrive or Droid 3 (both Android devices) I don't get video. I can make changes to the camera settings and everything else you can do when logged into the camera but just can't see the video. If I change the 'View Mode' in the video setup to 'Image', I will get a picture on all three devices (Thrive, Droid 3, and laptop).
What do I need on the Droid 3 & Thrive so I can see the video when I log into the DCS-930L with an Android device?
i've some trouble configuring a TDM switch PRI-to-PRI from Telco to an RMX 1500. After a lot of hours spent on configuration now i can receive and make call from the RMX, but only two channels. When I try to make a third call I get "Cause i = 0x82AC - Requested circuit/channel not available" This is the HW configuration: Cisco 2811 (IOS Version 12.4(25c)) with 2 VWIC2-2MFT-T1/E1, 16-PVDM2 and 64-PVDM2 on the first VWIC i've two Telco PRI (each with 15 bi-directional channel), on the second VWIC i've connected with E1 cross-cable the RMX 1500 with 6 timeslots configured, This router already doing VoIP translation from the Telco PRI to an Asterisk PBX (fax and DID).
I have a setup using an ASA 5510 8.2(2). In the DMZ (192.168.12.x) there is a server, switch and multiple cameras for surveillance of the site. In the Inside (140.152.25.x) are the pcs that can run the client software to view the video feed, or it can pull from the server in the DMZ.
On the server in the DMZ, you can see the feed, along with any pc you connect to that network. On any machine on the Inside, or through VPN, you cannot either with the client software or pulling from the surveillance server.
I am watching the connection through ASDM and don’t see any particular port being blocked, but I do see TCP connections being terminated by inspection. So far I’ve taken out inspections for http and rstp. I don’t really see anything else that would drop video. I've attached the error I keep seeing.
policy-map global_policy class inspection_default inspect dns preset_dns_map
There are two Polycom devices behind ASA (Terminal HDX7000 and MCU RMX1000), ASA is connected to Cisco 1900 router which is connected to ISP.
Polycom devices are NATed (unique global address per device) on router and h323 inspection is done on ASA. The issue is that when trying to connect from outside to conference on MCU I don't receive any video (but MCU shows me like a connected participant). The same is true when MCU try to call outside terminals, they are shown as connected participants, but there is just a black screen. On ASA all ports are opened (both in and out) and there are no ACLs on router. And what means NAT configuration on Polycom devices, why it is needed when NATing is done on router (such configuration option I've seen also on Tandberg and another vendor's devices)?
I am using ASA 5510 and I have a specific problem with Http Connection to receive a video Flow ( RSTP protocol ) in the LAN. Some Pc users (192.168.1.133,in the log) with ASA Lan Interface as gateway can ping the Camera but don't receveive the video flow.Some Pc users (192.168.1.116,in the log) using another gateway can ping and receive the video flow. I used Whireshark to capture traffic between camera and Pc using the 2 gateway. I joined Logs with this message.It seems to be a problem of TCP segments on the ASA, I try to changed some TCP options but it's still the same:- Disable Force Maximum Segment Size- Enable Force TCP Connection to Linger in TIME_WAIT State for at Least 15 Second.
I have a customer with a Cisco ASA 5510 firewall, an inside network containing a Genetec video recording server, and cameras installed on broadband modems throughout the area (each with a public IP). They've recently purchased Axis Q6034-E cameras that use H.264 to stream back to the video recording server. The camera has a view mode where you can watch it through H.264 or Motion JPEG. The view with M-JPEG works, but when I switch to H.264 the video stream is denied. We have allowed RTSP, RTP, and HTTP (it's setup with only http, not 443)traffic from the camera address on the cable company public network but are still being denied the video stream. The recording software requires that the feed come from the H.264 feed, so the motion jpeg does not fix the underlying issue of being able to record.
We know it's the firewall because if we install the camera on the inside network, the video feed in H.264 works to the recorder.
How to enable something special on the firewall to allow traffic through from the device?
I just installed a refurb'd 3560 48 port POE switch and configured all ports on VLAN100. All Polycom IP 430 phones (with power adapter and without power adapter) constantly reboot every couple minutes. Any Cisco 7960 phone does not constantly reboot and works correctly. When I plug a small unmanaged switch into a 3560 port and then plug the Polycom phone into the unmanaged switch powering the phone with a power adapter, the phone works correctly. So it seems that the 3560 is causing the Polycom to reboot.
I would like to know if there an specific configuration in order to apply QoS configuration in Switches 3750X for Polycoms Phones.I was reviewing the information from Cisco but mostly of them apply only for cisco phones, and just some or basic for non cisco phones.
Trying to set-up a priority queue for Voice and Video traffic, below is the current ASA config. The WAN link is 6mb, trying to limit the Internet traffic to 4mb and save 2mb for the PQ, config belowTraffic just isn't hitting the PQ
priority-queue outside queue-limit 512 tx-ring-limit 200 ! class-map Video description Video match dscp af31
my client wants to make videoconference call thorugh Microsoft Office Communicator, this should be operating between host from one site to another one, but we already configured some rules in the firewalls, and making some test I see that the videoconference use dynamic ports (1024 to 65535) and if we let to operate the videoconference we should remove all the rules in the firewall and that's not the point.
I'm trying to configure LLDP-MED between a Cat45010+E Sup7 (IOS 15.1) and Polycom CX600 Lync phones. I have created and applied the correct network policy for the interfaces.
From these sites, I need to send all the correct TLVs or the phones won't respond: {URL}.
When a scour the config of the switch, I can't find any related configuration commands relating to the specific LLDP-MED TLV components which are enabled/disabled. Where are they hiding? I would like to confirm which TLVs are being sent by my switch and if they are matched to the phone. I can always use the DHCP method, put this is not preferred.
I am able to ping from Switch to firewall inside ip and user desktop ip but unable to ping from user desktop to FW Inside ip.. config is below for both switch and FW Cisco ASA5510....
TechCore-SW#ping 172.22.15.10 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 172.22.15.10, timeout is 2 seconds:
I have some problem with the ASA 5510 ver 7.0(6). My manager wants to keep this as backup. tried lots of things but still users not able to access internet nor can i ping anywhere.For example when i ping 4.2.2.2 i dont get any reply.The runing config is below for ur ref :