<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Polycom HdX8000 behind ASA Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118811#M393623</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have also record one more log Please have a look at the attached..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 29 Dec 2012 20:30:25 GMT</pubDate>
    <dc:creator>samirshaikh52</dc:creator>
    <dc:date>2012-12-29T20:30:25Z</dc:date>
    <item>
      <title>Polycom HdX8000 behind ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118807#M393617</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am encountering some problems setting up my new polycom hdx 8000 behind ASA 5540&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have opened reuired ports through the firewall ( incoming and outgoing). I have enabled inspection h323 on ASA and enabled the option NAT is 323 compatible on Polycom.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3230-3243 tcp&lt;/P&gt;&lt;P&gt;h323 tcp&lt;/P&gt;&lt;P&gt;h323 udp&lt;/P&gt;&lt;P&gt;3230-3285 udp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the problem.&lt;/P&gt;&lt;P&gt;I get connected to the call but I cannot&amp;nbsp; the remote site cannot see and hear me.&lt;/P&gt;&lt;P&gt;But I can see and hear them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please can someone help me in this very important matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:41:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118807#M393617</guid>
      <dc:creator>samirshaikh52</dc:creator>
      <dc:date>2019-03-12T00:41:57Z</dc:date>
    </item>
    <item>
      <title>Polycom HdX8000 behind ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118808#M393619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't probably give you an exact answer to your problem but I remember some customer once having probems with Polycom devices through Cisco firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding one thing recommended is to avoid using the inspect/fixup commands on the PIX/ASA firewall. I think I've also read on a Cisco document that there has been some problems between Cisco firewalls and Polycom devices in general but cant find that document right now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; no inspect h323 h225&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; no inspect h323 ras&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or something similiar depending on your firewall software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could try the above perhaps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried to monitor the logs through ASDM to see if there is anything that is getting blocked while you try to form the connections?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Dec 2012 15:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118808#M393619</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-29T15:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Polycom HdX8000 behind ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118809#M393621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Thanks for your quick response.&lt;/P&gt;&lt;P&gt;Yes I have trid before disabling h323 inspection and then disabling NAT is h323 compatible on Polycom&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;In my ASDM logs I have seen any dropped or denied connection. Please see the attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Dec 2012 15:53:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118809#M393621</guid>
      <dc:creator>samirshaikh52</dc:creator>
      <dc:date>2012-12-29T15:53:36Z</dc:date>
    </item>
    <item>
      <title>Polycom HdX8000 behind ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118810#M393622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only special thing about that output is that the ICMP is getting block from "inside" to "outside"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also since its ICMP Type 3 Code 3 it would seem that the "inside" device is sending some "Port Unreachable" to the host on the "outside".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the "inside" Polycom device not accepting some connection and why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess its probably related to some UDP connection not getting through to the Polycom device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Personally I am not really familiar with video conferencing or its firewall related things. I have only been lately trying to troubleshoot some situations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would perhaps also try to take some packet captures on the ASA itself and go through them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Dec 2012 16:08:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118810#M393622</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-29T16:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Polycom HdX8000 behind ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118811#M393623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have also record one more log Please have a look at the attached..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Dec 2012 20:30:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118811#M393623</guid>
      <dc:creator>samirshaikh52</dc:creator>
      <dc:date>2012-12-29T20:30:25Z</dc:date>
    </item>
    <item>
      <title>Polycom HdX8000 behind ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118812#M393624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The single log message included in that file seems to be indicating that traffic from the Polycom device is being blocked from leaving from your network to the remote device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you try and open everything for the Polycom device so no access-list is blocking its connections?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems you have an ACL named &lt;STRONG&gt;"inside_access_in"&lt;/STRONG&gt; attached to the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; interface which is blocking some connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you perhaps for testing purposes open all traffic from the Polycom device to the destination IP address? (if the one in the logs is the only one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list inside_access_in line 1 permit ip host &lt;POLYCOM local="" ip="" address=""&gt; host &lt;REMOTE device="" ip="" address=""&gt;&lt;/REMOTE&gt;&lt;/POLYCOM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The source and destination port look a bit wierd (high port as destination) but maybe you could give the above a go and see if it helps.&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Dec 2012 21:19:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118812#M393624</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-29T21:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: Polycom HdX8000 behind ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118813#M393625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have also tried by opening all the ports ( incoming and outgoing) but it was the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something weird &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt; Really !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Samir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Dec 2012 22:33:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118813#M393625</guid>
      <dc:creator>samirshaikh52</dc:creator>
      <dc:date>2012-12-29T22:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Polycom HdX8000 behind ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118814#M393626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have found a very interesting thing &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assigned public ip address to the LAN interface of my laptop and placed a call to polycom. It was successfully Both way I can see and hear&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when I assigned dhcp private ip to the laptop and placed a call. Then polycom is not able to send audio and video.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Polycom see a private ip address while recieving a call&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is mean by that Can anyone pleas help me. ?&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Dec 2012 15:55:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118814#M393626</guid>
      <dc:creator>samirshaikh52</dc:creator>
      <dc:date>2012-12-30T15:55:22Z</dc:date>
    </item>
    <item>
      <title>Polycom HdX8000 behind ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118815#M393627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to set up a static NAT to a dedicated public IP for all ports.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Dec 2012 19:23:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118815#M393627</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2012-12-31T19:23:52Z</dc:date>
    </item>
    <item>
      <title>Polycom HdX8000 behind ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118816#M393628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt; I have already a static NAT for a fixed public IP allowing all ports. ( outgoing)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Dec 2012 19:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/polycom-hdx8000-behind-asa-firewall/m-p/2118816#M393628</guid>
      <dc:creator>samirshaikh52</dc:creator>
      <dc:date>2012-12-31T19:40:40Z</dc:date>
    </item>
  </channel>
</rss>

