<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi David,Let me share with in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/airplay-not-working-with-an-asa-in-the-middle/m-p/2489309#M268153</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;Hi David,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;Let me share with you my findings. Apple TV requires more than 5353 port opened. Please see the following link and include in your ASA those additional ports/range. I mean, 7000, 7100, 5000 (udp/tcp), etc etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;&lt;A href="http://community.arubanetworks.com/t5/Unified-Wired-Wireless-Access/apple-macbook-airplay-appletv-firewall-port-findings/td-p/55048"&gt;&lt;U&gt;&lt;FONT color="#0000ff"&gt;http://community.arubanetworks.com/t5/Unified-Wired-Wireless-Access/apple-macbook-airplay-appletv-firewall-port-findings/td-p/55048&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;After opening those ports, the service is working BUT with significant LATENCY/SLOWNESS which we are trying to solve. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;We took some packets captures on the ASA ingress/egress interfaces for both contexts (see pictures attached)&amp;nbsp;and I could see many retransmissions and duplicated ACK so I tried something else that worked&amp;nbsp;(see Apple TV Works attached file) BUT this is not the final solution we need so we are still working on this issue in order to check if there is something wrong with our routing/switching process in the 6500 LAN SW.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;I created static routes in the ASA contexts to communicate the IPAD to the APPLE TV (ports already opened in the ASA as indicated before) without traversing the Wireless 6500&amp;nbsp;SW (test performed on VLAN A and VLAN B) and it worked fine. However as I said, this is not the solution we want because the Wireless 6500 SW must manage inter-ASA-contexts traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;In addition to that I attached another picture/diagram that shows when Apple TV service fails-latency (traffic crossing the Wireless 6500 SW for communication between ASA contexts).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;Important to say that I am NOT using MULTICAST or BROADCAST ENABLED in the WLC. I am based on mDNS as indicated in the Cisco Guide/Instructions for version 7.5 and above.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Apr 2014 16:21:37 GMT</pubDate>
    <dc:creator>ajc</dc:creator>
    <dc:date>2014-04-15T16:21:37Z</dc:date>
    <item>
      <title>airplay not working with an ASA in the middle</title>
      <link>https://community.cisco.com/t5/network-security/airplay-not-working-with-an-asa-in-the-middle/m-p/2489307#M268150</link>
      <description>&lt;P style="font-size: 14px;"&gt;Hi All&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;This is my case: In the lab I could configure mDNS on my 5508 with the global multicast and igmp snooping disabled. Only I needed was Global mDNS multicast enabled (based on Cisco Guide) and it worked fine under the following scenarios:&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;All the services connected wireless&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;IPAD on subnet A and Apple TV on subnet B, no Firewall in the middle. Peer to Peer Blocking in the WLC was any DROP or DISABLED and it worked fine.&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;BUT, when I moved into production environment, the only way that it works is by having both Apple Devices in the same subnet with the Peer to Peer bloking DISABLED. I have a firewall ASA in the middle so I do not know what should I check in the firewall to allow Airplay to work.&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;However, there is something really weird. in the IPAD, I can see the AIRPLAY icon at the bottom of the screen, when I click on it, I can see MIRRORING button and I moved it to the right to activated it BUT nothing happens on the AppleTV connected to an screen. I mean, looks like the request for MIRRORING from the IPAD to the Apple TV device is not reaching the last one. A few seconds after activating MIRRORING in the IPAD looks like the request is dropped since that the mirroring is not active.&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;Is there any particular multicast configuration required in the ASA including ports (like 5353 udp)?&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;I have an open case with TAC but any ideas are welcomed.&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;By the way, I am running v 7.6 in the WLC in order to implement mDNS (traffic between ssid's subnet managed by the WLC - Bonjour Gateway is not neccesary)&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;thanks&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;Abraham&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:58:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/airplay-not-working-with-an-asa-in-the-middle/m-p/2489307#M268150</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2019-03-12T03:58:46Z</dc:date>
    </item>
    <item>
      <title>Did you ever get to the</title>
      <link>https://community.cisco.com/t5/network-security/airplay-not-working-with-an-asa-in-the-middle/m-p/2489308#M268152</link>
      <description>&lt;P&gt;Did you ever get to the bottom of this problem? I'm having the same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2014 03:37:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/airplay-not-working-with-an-asa-in-the-middle/m-p/2489308#M268152</guid>
      <dc:creator>David Taylor</dc:creator>
      <dc:date>2014-04-15T03:37:10Z</dc:date>
    </item>
    <item>
      <title>Hi David,Let me share with</title>
      <link>https://community.cisco.com/t5/network-security/airplay-not-working-with-an-asa-in-the-middle/m-p/2489309#M268153</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;Hi David,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;Let me share with you my findings. Apple TV requires more than 5353 port opened. Please see the following link and include in your ASA those additional ports/range. I mean, 7000, 7100, 5000 (udp/tcp), etc etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;&lt;A href="http://community.arubanetworks.com/t5/Unified-Wired-Wireless-Access/apple-macbook-airplay-appletv-firewall-port-findings/td-p/55048"&gt;&lt;U&gt;&lt;FONT color="#0000ff"&gt;http://community.arubanetworks.com/t5/Unified-Wired-Wireless-Access/apple-macbook-airplay-appletv-firewall-port-findings/td-p/55048&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;After opening those ports, the service is working BUT with significant LATENCY/SLOWNESS which we are trying to solve. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;We took some packets captures on the ASA ingress/egress interfaces for both contexts (see pictures attached)&amp;nbsp;and I could see many retransmissions and duplicated ACK so I tried something else that worked&amp;nbsp;(see Apple TV Works attached file) BUT this is not the final solution we need so we are still working on this issue in order to check if there is something wrong with our routing/switching process in the 6500 LAN SW.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;I created static routes in the ASA contexts to communicate the IPAD to the APPLE TV (ports already opened in the ASA as indicated before) without traversing the Wireless 6500&amp;nbsp;SW (test performed on VLAN A and VLAN B) and it worked fine. However as I said, this is not the solution we want because the Wireless 6500 SW must manage inter-ASA-contexts traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;In addition to that I attached another picture/diagram that shows when Apple TV service fails-latency (traffic crossing the Wireless 6500 SW for communication between ASA contexts).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;Important to say that I am NOT using MULTICAST or BROADCAST ENABLED in the WLC. I am based on mDNS as indicated in the Cisco Guide/Instructions for version 7.5 and above.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2014 16:21:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/airplay-not-working-with-an-asa-in-the-middle/m-p/2489309#M268153</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2014-04-15T16:21:37Z</dc:date>
    </item>
    <item>
      <title>Hi David,Apparently we solved</title>
      <link>https://community.cisco.com/t5/network-security/airplay-not-working-with-an-asa-in-the-middle/m-p/2489310#M268155</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;Hi David,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;Apparently we solved the issue. IP REDIRECT is enabled by default in the VLAN that is shared by the ASA and the LAN SW as you can see in the pictures I attached to this post. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;Because of this command, the LAN SW would be dropping the packets causing retransmission and dup ack on the IPAD/Apple TV which causes latency/slowness. The LAN SW based on this command sends continuous ICMP Redirect to the ASA &lt;SPAN style="color: black; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;telling to this device to no longer forward the traffic to the 6500, but in stead to its L2 adjacent ASA context.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;&lt;SPAN style="color: black; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-CA; mso-fareast-language: EN-CA; mso-bidi-language: AR-SA;"&gt;This link provides information about this: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/Baseline_Security/securebasebook/sec_chap4.html"&gt;&lt;U&gt;http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/Baseline_Security/securebasebook/sec_chap4.html&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 00:08:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/airplay-not-working-with-an-asa-in-the-middle/m-p/2489310#M268155</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2014-04-16T00:08:24Z</dc:date>
    </item>
  </channel>
</rss>

