<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: h323 and NAT issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299538#M311735</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Olivier,&lt;BR /&gt;first i suggest you to group pots you're using in acl in a service group to make your configuration simplest and easiest tor ead.&lt;BR /&gt;in most case the issue you're encountering it's port related, so be sure that ports you're permitting on your acl are the same your vdc is using for audio and video traffic. As i know H323 calls uses tcp 1720 port to estabilish connection then a random range of tcp/udp ports for audio and video. In your VDC system you can restrict this random range of ports so it uses always those ports for audio and video traffic.&lt;BR /&gt;then i suggest you to try configuring a 1:1 exclusive nat for the vdc system and restrict access from outside just with the acl. Also disable all h323 inspection.&lt;BR /&gt;&lt;BR /&gt;hope this helps.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Oct 2013 10:19:33 GMT</pubDate>
    <dc:creator>alessandro.s</dc:creator>
    <dc:date>2013-10-02T10:19:33Z</dc:date>
    <item>
      <title>h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299533#M311729</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a router 1812 Version 12.4(15)T16, RELEASE SOFTWARE (fc2). Router is doing NAT.&lt;/P&gt;&lt;P&gt;I have a lifesize videoconference system. Calls with h323 are dropped after 30 seconds.&lt;/P&gt;&lt;P&gt;I have ip inspect rule :&lt;/P&gt;&lt;P&gt;[...]&lt;/P&gt;&lt;P&gt; - ip inspect name SDM_LOW h323&lt;/P&gt;&lt;P&gt; - ip inspect name SDM_LOW h323callsigalt&lt;/P&gt;&lt;P&gt;[...]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; ip address xxx.xxx.xxx.xxx 255.255.255.248&lt;/P&gt;&lt;P&gt; ip access-group 102 in&lt;/P&gt;&lt;P&gt; ip verify unicast reverse-path&lt;/P&gt;&lt;P&gt; ip nbar protocol-discovery&lt;/P&gt;&lt;P&gt; ip flow ingress&lt;/P&gt;&lt;P&gt; ip flow egress&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip inspect SDM_LOW out&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; full-duplex&lt;/P&gt;&lt;P&gt; crypto map SDM_CMAP_1&lt;/P&gt;&lt;P&gt; service-policy input sdmappfwp2p_SDM_LOW&lt;/P&gt;&lt;P&gt; service-policy output sdmappfwp2p_SDM_LOW&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I start a communication, I have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh ip inspect sessions&lt;/P&gt;&lt;P&gt; Session 85AE7150 (50.59.87.241:60118)=&amp;gt;(192.168.200.200:60016) h323-RTP-audio SIS_OPEN&lt;/P&gt;&lt;P&gt; Session 85AE12C0 (50.59.87.241:60119)=&amp;gt;(192.168.200.200:60017) h323-RTCP-audio SIS_OPEN&lt;/P&gt;&lt;P&gt; Session 85AE39B0 (192.168.200.200:60001)=&amp;gt;(50.59.87.241:62830) h245-media-control SIS_OPEN&lt;/P&gt;&lt;P&gt; Session 841F7CEC (192.168.200.200:60005)=&amp;gt;(50.59.87.241:1720) h323 SIS_OPEN&lt;/P&gt;&lt;P&gt; Session 85AE20A8 (50.59.87.241:60120)=&amp;gt;(192.168.200.200:60018) h323-RTP-video SIS_OPENING&lt;/P&gt;&lt;P&gt; Session 85ADE0B0 (50.59.87.241:60121)=&amp;gt;(192.168.200.200:60019) h323-RTCP-video SIS_OPENING&lt;/P&gt;&lt;P&gt; Session 85AE4D28 (50.59.87.241:60122)=&amp;gt;(192.168.200.200:60020) h323-RTP-data SIS_OPENING&lt;/P&gt;&lt;P&gt; Session 85ADCD38 (50.59.87.241:60123)=&amp;gt;(192.168.200.200:60021) h323-RTCP-data SIS_OPENING&lt;/P&gt;&lt;P&gt; Pre-gen session 85ADA648&amp;nbsp; 192.168.200.200[1024:65535]=&amp;gt;50.59.87.241[60119:60119] h323-RTCP-audio&lt;/P&gt;&lt;P&gt; Pre-gen session 85AD92D0&amp;nbsp; 192.168.200.200[1024:65535]=&amp;gt;50.59.87.241[60121:60121] h323-RTCP-video&lt;/P&gt;&lt;P&gt; Pre-gen session 85ADB6F8&amp;nbsp; 192.168.200.200[1024:65535]=&amp;gt;50.59.87.241[60123:60123] h323-RTCP-data&lt;/P&gt;&lt;P&gt; Pre-gen session 85AD9008&amp;nbsp; 192.168.200.200[1024:65535]=&amp;gt;50.59.87.241[60118:60118] h323-RTP-audio&lt;/P&gt;&lt;P&gt; Pre-gen session 85AE5848&amp;nbsp; 192.168.200.200[1024:65535]=&amp;gt;50.59.87.241[60119:60119] h323-RTCP-audio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where 192.168.200.200 is local IP and 50.59.87.241 the server I try to reach.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea of what is going on ? Why calls are dropped after 30 seconds ?&lt;/P&gt;&lt;P&gt;Something with NAT ?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 01:05:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299533#M311729</guid>
      <dc:creator>olivier1977</dc:creator>
      <dc:date>2019-03-13T01:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299534#M311730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Oliver,&lt;BR /&gt;try to disable h323 inspections, some videoconference systems does not work properly with inspection enabled and nat&lt;BR /&gt;&lt;BR /&gt;hope this helps.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Oct 2013 14:35:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299534#M311730</guid>
      <dc:creator>alessandro.s</dc:creator>
      <dc:date>2013-10-01T14:35:34Z</dc:date>
    </item>
    <item>
      <title>h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299535#M311731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alessandro.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I turned of h323.&lt;/P&gt;&lt;P&gt;Still the same. Communications shut down after 30 sec &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Oct 2013 15:11:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299535#M311731</guid>
      <dc:creator>olivier1977</dc:creator>
      <dc:date>2013-10-01T15:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299536#M311732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Oliver,&lt;BR /&gt;you turned off all h323 inspections ?&lt;BR /&gt;can you post complete configurtion of your router?&lt;BR /&gt;&lt;BR /&gt;regards&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Oct 2013 15:17:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299536#M311732</guid>
      <dc:creator>alessandro.s</dc:creator>
      <dc:date>2013-10-01T15:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299537#M311733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alessandro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;configuration below :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect tcp reassembly queue length 200&lt;/P&gt;&lt;P&gt;ip inspect tcp reassembly timeout 10&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW appfw SDM_LOW&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW dns&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW https&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW icmp&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW imap&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW pop3&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW rcmd&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW sqlnet&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW tcp&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW udp&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW http&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW h323&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW h323callsigalt&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW skinny&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW sip-tls&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW sip&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW esmtp max-data 50000000&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW cuseeme&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW ftp&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW netshow&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW realaudio&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW rtsp&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW streamworks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WAN_INTERFACE = xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; ip address WAN_INTERFACE.226 255.255.255.248&lt;/P&gt;&lt;P&gt; ip access-group 102 in&lt;/P&gt;&lt;P&gt; ip verify unicast reverse-path&lt;/P&gt;&lt;P&gt; ip nbar protocol-discovery&lt;/P&gt;&lt;P&gt; ip flow ingress&lt;/P&gt;&lt;P&gt; ip flow egress&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip inspect SDM_LOW out&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; full-duplex&lt;/P&gt;&lt;P&gt; crypto map SDM_CMAP_1&lt;/P&gt;&lt;P&gt; service-policy input sdmappfwp2p_SDM_LOW&lt;/P&gt;&lt;P&gt; service-policy output sdmappfwp2p_SDM_LOW&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inbound ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 102 remark SDM_ACL Category=3&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq www log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 443 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 558 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 1023 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 1024 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 1503 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 1718 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 1719 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 1720 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 4001 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 11720 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 17518 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 60000 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 60001 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 60002 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 60003 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 60004 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 60005 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60000 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 1023 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 1024 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 1718 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 1719 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 1720 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 5060 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 17518 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60001 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60002 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60003 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60004 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60005 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60006 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60007 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60008 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60009 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60010 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60011 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60012 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60013 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60014 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60015 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60016 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60017 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60018 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60019 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60020 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60021 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60022 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60023 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60024 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 60025 log&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.228 eq 3389 log&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.228 eq 3389 log&lt;/P&gt;&lt;P&gt;[ Some ipsec rubles]&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.230 eq 22&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.230 eq www&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.227 eq smtp&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any host WAN_INTERFACE.227 eq 80&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.227 eq www&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.227 eq ftp&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.226 eq 1723&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any host WAN_INTERFACE.226 eq 47&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60000 WAN_INTERFACE.228 60000 route-map SDM_RMAP_32 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 80 WAN_INTERFACE.228 80 route-map SDM_RMAP_15 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 443 WAN_INTERFACE.228 443 route-map SDM_RMAP_7 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 558 WAN_INTERFACE.228 558 route-map SDM_RMAP_47 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 1023 WAN_INTERFACE.228 1023 route-map SDM_RMAP_77 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 1023 WAN_INTERFACE.228 1023 route-map SDM_RMAP_78 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 1024 WAN_INTERFACE.228 1024 route-map SDM_RMAP_73 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 1024 WAN_INTERFACE.228 1024 route-map SDM_RMAP_74 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 1503 WAN_INTERFACE.228 1503 route-map SDM_RMAP_75 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 1718 WAN_INTERFACE.228 1718 route-map SDM_RMAP_86 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 1718 WAN_INTERFACE.228 1718 route-map SDM_RMAP_87 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 1719 WAN_INTERFACE.228 1719 route-map SDM_RMAP_42 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 1719 WAN_INTERFACE.228 1719 route-map SDM_RMAP_43 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 1720 WAN_INTERFACE.228 1720 route-map SDM_RMAP_28 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 1720 WAN_INTERFACE.228 1720 route-map SDM_RMAP_44 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 4001 WAN_INTERFACE.228 4001 route-map SDM_RMAP_72 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 5060 WAN_INTERFACE.228 5060 route-map SDM_RMAP_29 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 11720 WAN_INTERFACE.228 11720 route-map SDM_RMAP_71 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 17518 WAN_INTERFACE.228 17518 route-map SDM_RMAP_45 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 17518 WAN_INTERFACE.228 17518 route-map SDM_RMAP_46 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 60000 WAN_INTERFACE.228 60000 route-map SDM_RMAP_30 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 60001 WAN_INTERFACE.228 60001 route-map SDM_RMAP_31 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60001 WAN_INTERFACE.228 60001 route-map SDM_RMAP_33 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 60002 WAN_INTERFACE.228 60002 route-map SDM_RMAP_66 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60002 WAN_INTERFACE.228 60002 route-map SDM_RMAP_34 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 60003 WAN_INTERFACE.228 60003 route-map SDM_RMAP_67 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60003 WAN_INTERFACE.228 60003 route-map SDM_RMAP_35 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 60004 WAN_INTERFACE.228 60004 route-map SDM_RMAP_68 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60004 WAN_INTERFACE.228 60004 route-map SDM_RMAP_36 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp LAN_INTERFACE 60005 WAN_INTERFACE.228 60005 route-map SDM_RMAP_69 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60005 WAN_INTERFACE.228 60005 route-map SDM_RMAP_37 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60006 WAN_INTERFACE.228 60006 route-map SDM_RMAP_38 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60007 WAN_INTERFACE.228 60007 route-map SDM_RMAP_39 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60008 WAN_INTERFACE.228 60008 route-map SDM_RMAP_48 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60009 WAN_INTERFACE.228 60009 route-map SDM_RMAP_49 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60010 WAN_INTERFACE.228 60010 route-map SDM_RMAP_50 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60011 WAN_INTERFACE.228 60011 route-map SDM_RMAP_51 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60012 WAN_INTERFACE.228 60012 route-map SDM_RMAP_52 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60013 WAN_INTERFACE.228 60013 route-map SDM_RMAP_53 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60014 WAN_INTERFACE.228 60014 route-map SDM_RMAP_54 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60015 WAN_INTERFACE.228 60015 route-map SDM_RMAP_55 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60016 WAN_INTERFACE.228 60016 route-map SDM_RMAP_56 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60017 WAN_INTERFACE.228 60017 route-map SDM_RMAP_57 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60018 WAN_INTERFACE.228 60018 route-map SDM_RMAP_58 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60019 WAN_INTERFACE.228 60019 route-map SDM_RMAP_59 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60020 WAN_INTERFACE.228 60020 route-map SDM_RMAP_60 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60021 WAN_INTERFACE.228 60021 route-map SDM_RMAP_61 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60022 WAN_INTERFACE.228 60022 route-map SDM_RMAP_62 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60023 WAN_INTERFACE.228 60023 route-map SDM_RMAP_63 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60024 WAN_INTERFACE.228 60024 route-map SDM_RMAP_64 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp LAN_INTERFACE 60025 WAN_INTERFACE.228 60025 route-map SDM_RMAP_65 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static LAN_INTERFACE WAN_INTERFACE.228 route-map SDM_RMAP_76&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All SMD_RMAP are like this one below &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map SDM_RMAP_32 permit 1&lt;/P&gt;&lt;P&gt; match ip address 141&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 141 remark SDM_ACL Category=2&lt;/P&gt;&lt;P&gt;access-list 141 deny&amp;nbsp;&amp;nbsp; ip host LAN_INTERFACE 10.0.5.0 0.0.0.31&lt;/P&gt;&lt;P&gt;access-list 141 deny&amp;nbsp;&amp;nbsp; ip host LAN_INTERFACE 10.0.5.40 0.0.0.1&lt;/P&gt;&lt;P&gt;access-list 141 permit udp host LAN_INTERFACE eq 60000 any&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 08:29:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299537#M311733</guid>
      <dc:creator>olivier1977</dc:creator>
      <dc:date>2013-10-02T08:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299538#M311735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Olivier,&lt;BR /&gt;first i suggest you to group pots you're using in acl in a service group to make your configuration simplest and easiest tor ead.&lt;BR /&gt;in most case the issue you're encountering it's port related, so be sure that ports you're permitting on your acl are the same your vdc is using for audio and video traffic. As i know H323 calls uses tcp 1720 port to estabilish connection then a random range of tcp/udp ports for audio and video. In your VDC system you can restrict this random range of ports so it uses always those ports for audio and video traffic.&lt;BR /&gt;then i suggest you to try configuring a 1:1 exclusive nat for the vdc system and restrict access from outside just with the acl. Also disable all h323 inspection.&lt;BR /&gt;&lt;BR /&gt;hope this helps.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 10:19:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299538#M311735</guid>
      <dc:creator>alessandro.s</dc:creator>
      <dc:date>2013-10-02T10:19:33Z</dc:date>
    </item>
    <item>
      <title>h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299539#M311737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alessandro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I turned off h323&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW appfw SDM_LOW&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW http&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW dns&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW https&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW icmp&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW imap&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW pop3&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW rcmd&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW sqlnet&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW tcp&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW udp&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW esmtp max-data 50000000&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW cuseeme&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW ftp&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW netshow&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW realaudio&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW rtsp&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW streamworks&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW sip-tls&lt;/P&gt;&lt;P&gt;ip inspect name SDM_LOW sip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I removed PAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RTRSJM#sh run | i ip nat inside source&lt;/P&gt;&lt;P&gt;ip nat inside source route-map SDM_RMAP_1 interface FastEthernet0 overload&lt;/P&gt;&lt;P&gt;ip nat inside source route-map SDM_RMAP_3 interface FastEthernet0 overload&lt;/P&gt;&lt;P&gt;ip nat inside source route-map SDM_RMAP_79 interface FastEthernet0 overload&lt;/P&gt;&lt;P&gt;ip nat inside source route-map SDM_RMAP_80 interface FastEthernet0 overload&lt;/P&gt;&lt;P&gt;ip nat inside source route-map SDM_RMAP_81 interface FastEthernet0 overload&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip nat inside source static 192.168.200.200 WAN_INTERFACE.228 route-map SDM_RMAP_76&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 10.0.1.49 47 WAN_INTERFACE.226 47 route-map SDM_RMAP_83 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 10.0.1.49 1723 WAN_INTERFACE.226 1723 route-map SDM_RMAP_82 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 10.0.1.59 21 WAN_INTERFACE.227 21 route-map SDM_RMAP_14 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 10.0.1.42 25 WAN_INTERFACE.227 25 route-map SDM_RMAP_13 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 10.0.1.59 80 WAN_INTERFACE.227 80 route-map SDM_RMAP_5 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp 10.0.1.59 80 WAN_INTERFACE.227 80 route-map SDM_RMAP_9 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 10.0.1.42 110 WAN_INTERFACE.227 110 route-map SDM_RMAP_12 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 10.0.1.45 3389 WAN_INTERFACE.227 3389 route-map SDM_RMAP_11 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp 10.0.1.45 3389 WAN_INTERFACE.227 3389 route-map SDM_RMAP_8 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp 10.0.1.134 21 WAN_INTERFACE.229 21 route-map SDM_RMAP_26 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 10.0.1.134 80 WAN_INTERFACE.229 80 route-map SDM_RMAP_21 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp 10.0.1.134 80 WAN_INTERFACE.229 80 route-map SDM_RMAP_22 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 10.0.1.134 443 WAN_INTERFACE.229 443 route-map SDM_RMAP_23 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static udp 10.0.1.134 443 WAN_INTERFACE.229 443 route-map SDM_RMAP_24 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 10.0.1.139 22 WAN_INTERFACE.230 22 route-map SDM_RMAP_85 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 10.0.1.139 80 WAN_INTERFACE.230 80 route-map SDM_RMAP_84 extendable&lt;/P&gt;&lt;P&gt;RTRSJM#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route-map SDM_RMAP_76 permit 1&lt;/P&gt;&lt;P&gt; match ip address 188&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 188 remark SDM_ACL Category=2&lt;/P&gt;&lt;P&gt;access-list 188 deny&amp;nbsp;&amp;nbsp; ip host 192.168.200.200 10.0.5.0 0.0.0.31&lt;/P&gt;&lt;P&gt;access-list 188 deny&amp;nbsp;&amp;nbsp; ip host 192.168.200.200 10.0.5.40 0.0.0.1&lt;/P&gt;&lt;P&gt;access-list 188 permit ip host 192.168.200.200 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I also have dynamic NAT for subnet 192.168.200.0 /24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source route-map SDM_RMAP_79 interface FastEthernet0 overload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route-map SDM_RMAP_79 permit 1&lt;/P&gt;&lt;P&gt; match ip address 193&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still have the issue. Most of the time call ends after 30 sec, but now sometimes call ends after 5 or 6 minutes.&lt;/P&gt;&lt;P&gt;I wonder if i should have put the VDC in a separate VLAN and having only static NAT no dynamic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx for your help.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 10:24:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299539#M311737</guid>
      <dc:creator>olivier1977</dc:creator>
      <dc:date>2013-10-03T10:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299540#M311739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Oliver,&lt;BR /&gt;what about access-lists? did you checked ports used by VDC for audio and video calls? I see that you have access-list 102 applied on your outside interface, is any access-list applied on inside interface?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 10:39:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299540#M311739</guid>
      <dc:creator>alessandro.s</dc:creator>
      <dc:date>2013-10-03T10:39:45Z</dc:date>
    </item>
    <item>
      <title>h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299541#M311742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alessandro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find below router's and VDC's configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RTRSJM#sh ip int brie&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK? Method Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Protocol&lt;/P&gt;&lt;P&gt;FastEthernet0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WAN_INTERFACE.226&amp;nbsp;&amp;nbsp;&amp;nbsp; YES NVRAM&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;/P&gt;&lt;P&gt;Vlan1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.254&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES NVRAM&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;/P&gt;&lt;P&gt;Vlan2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.0.254&amp;nbsp;&amp;nbsp; YES NVRAM&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;/P&gt;&lt;P&gt;Vlan5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.71.1&amp;nbsp;&amp;nbsp;&amp;nbsp; YES NVRAM&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;/P&gt;&lt;P&gt;Vlan192&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.200.1&amp;nbsp;&amp;nbsp; YES NVRAM&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;/P&gt;&lt;P&gt;RTRSJM#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RTRSJM#sh ip int fa0&lt;/P&gt;&lt;P&gt;FastEthernet0 is up, line protocol is up&lt;/P&gt;&lt;P&gt;&amp;nbsp; Internet address is WAN_INTERFACE.226/29&lt;/P&gt;&lt;P&gt;&amp;nbsp; Broadcast address is 255.255.255.255&lt;/P&gt;&lt;P&gt;&amp;nbsp; Address determined by non-volatile memory&lt;/P&gt;&lt;P&gt;&amp;nbsp; MTU is 1500 bytes&lt;/P&gt;&lt;P&gt;&amp;nbsp; Helper address is not set&lt;/P&gt;&lt;P&gt;&amp;nbsp; Directed broadcast forwarding is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; Outgoing access list is not set&lt;/P&gt;&lt;P&gt;&amp;nbsp; Inbound&amp;nbsp; access list is &lt;STRONG&gt;102&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RTRSJM#sh ip int vl192&lt;/P&gt;&lt;P&gt;Vlan192 is up, line protocol is up&lt;/P&gt;&lt;P&gt;&amp;nbsp; Internet address is 192.168.200.1/24&lt;/P&gt;&lt;P&gt;&amp;nbsp; Broadcast address is 255.255.255.255&lt;/P&gt;&lt;P&gt;&amp;nbsp; Address determined by non-volatile memory&lt;/P&gt;&lt;P&gt;&amp;nbsp; MTU is 1500 bytes&lt;/P&gt;&lt;P&gt;&amp;nbsp; Helper address is not set&lt;/P&gt;&lt;P&gt;&amp;nbsp; Directed broadcast forwarding is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; Outgoing access list is &lt;STRONG&gt;not set&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Inbound&amp;nbsp; access list is &lt;STRONG&gt;not set&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ACL in inbound WAN interface and fot NAT.&lt;/P&gt;&lt;P&gt;ACL 102 in the one hereabove.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does it matter if i have static and dynamic NAT for the same adress ?&lt;/P&gt;&lt;P&gt;Dynamic for the subnet and static for the VDC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source route-map SDM_RMAP_79 interface FastEthernet0 overload&lt;/P&gt;&lt;P&gt;ip nat inside source static 192.168.200.200 WAN_INTERFACE.228 route-map SDM_RMAP_76&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VDC configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Network • Reserved Ports&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UDP Lowest Value:&amp;nbsp;&amp;nbsp;&amp;nbsp; 60000&lt;/P&gt;&lt;P&gt;UDP Highest Value:&amp;nbsp;&amp;nbsp;&amp;nbsp; 60023&lt;/P&gt;&lt;P&gt;TCP Lowest Value:&amp;nbsp;&amp;nbsp;&amp;nbsp; 60000&lt;/P&gt;&lt;P&gt;TCP Highest Value:&amp;nbsp;&amp;nbsp;&amp;nbsp; 60005&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Network • NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Static NAT:&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;/P&gt;&lt;P&gt;NAT Public IP Address:&amp;nbsp;&amp;nbsp;&amp;nbsp; WAN_INTERFACE.228&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; thx for your help&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 12:08:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299541#M311742</guid>
      <dc:creator>olivier1977</dc:creator>
      <dc:date>2013-10-03T12:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299542#M311745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Olivier,&lt;BR /&gt;i think it does not matter if you use both static and dynamic nat, i often use this configuration with polycom VDC systems and they works great!&lt;BR /&gt;I noticed you are using an old IOS so i suggest you to upgrade to a15 IOS version then retry.&lt;BR /&gt;If you can, post some acl logs captured during a video call.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 14:20:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299542#M311745</guid>
      <dc:creator>alessandro.s</dc:creator>
      <dc:date>2013-10-03T14:20:46Z</dc:date>
    </item>
    <item>
      <title>h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299543#M311749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Qlessqndrom&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunatly I'm not able to dl c181x-advipservicesk9-mz.124-15.T17.bin.&lt;/P&gt;&lt;P&gt;I don't have a service contract &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 14:37:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299543#M311749</guid>
      <dc:creator>olivier1977</dc:creator>
      <dc:date>2013-10-03T14:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299544#M311750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Olivier,&lt;BR /&gt;according to lifesize admin guide&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.lifesize.com/~/media/Documents/Product%20Documentation/Video%20Systems/Guides%20and%20Reference/Video%20User%20Administrator%20Guide%2048%20EN.ashx" target="_blank"&gt;http://www.lifesize.com/~/media/Documents/Product%20Documentation/Video%20Systems/Guides%20and%20Reference/Video%20User%20Administrator%20Guide%2048%20EN.ashx&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;at page 41 try to enable static nat on your VDC appliance using public ip address you intend to use as outside address.&lt;BR /&gt;&lt;BR /&gt;regards&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 14:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299544#M311750</guid>
      <dc:creator>alessandro.s</dc:creator>
      <dc:date>2013-10-03T14:59:55Z</dc:date>
    </item>
    <item>
      <title>h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299545#M311753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it's already done&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Network • NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Static NAT:&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;/P&gt;&lt;P&gt;NAT Public IP Address:&amp;nbsp;&amp;nbsp;&amp;nbsp; 86.xxx.xxx.228&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 16:25:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299545#M311753</guid>
      <dc:creator>olivier1977</dc:creator>
      <dc:date>2013-10-03T16:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299546#M311756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;have you ever tried to disable this NAT rule on VDC appliance and make a videocall?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;regards&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 16:41:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299546#M311756</guid>
      <dc:creator>alessandro.s</dc:creator>
      <dc:date>2013-10-03T16:41:38Z</dc:date>
    </item>
    <item>
      <title>h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299547#M311759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I disabled NAT on the VDC. I'm not able to make calls anymore.&lt;/P&gt;&lt;P&gt;So I enabled NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway we ordered a new ADSL line dedicated to the visioconf.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Oct 2013 12:20:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299547#M311759</guid>
      <dc:creator>olivier1977</dc:creator>
      <dc:date>2013-10-14T12:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: h323 and NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299548#M311761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oliver,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did the additional line solve the problem?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 01:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h323-and-nat-issue/m-p/2299548#M311761</guid>
      <dc:creator>Ivaylo Georgiev</dc:creator>
      <dc:date>2014-01-27T01:18:27Z</dc:date>
    </item>
  </channel>
</rss>

