<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CBAC with NAT and H.323 problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852468#M456302</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Thorr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In fact I think this should be working, is there a way you can post your config (with some changes due to security purposes)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Jan 2012 18:08:44 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-01-24T18:08:44Z</dc:date>
    <item>
      <title>CBAC with NAT and H.323 problem</title>
      <link>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852465#M456295</link>
      <description>&lt;P&gt; Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is Cisco 1921 router at the edge of the network performing NAT service with software (C1900-UNIVERSALK9-M), Version 15.0(1)M5, RELEASE SOFTWARE (fc2). Router is successfully performing NAT on IP packets, but IP address inside the payload (H.323 messages) remains unchanged (private). Because of that users on the inside network cannot establish video conferencing with remote users. VC is established normally among local users (because IP address both in IP header and in H.323 messages remains the same). How I can make NAT to change both address (in IP header and in H.323 messages) ? CBAC hasn't resolved my problem as well. I've done these things on router just to test CBAC:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -Created extended access-list with permit ip any any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -Applied it both to inside and outside interfaces of router&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -Created ip inspect rule: &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip inspect name TEST h323&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip inspect name TEST h323-annexe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip inspect name TEST h323-nxg&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; {Last two lines I've added just to use all possible inspection with H.323}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -Applied inspection rule to inside interface in incoming direction. No success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -Applied inspection rule to outside interface in outgoing direction. No success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how I can use NAT in conjunction with CBAC (or which another solution I can use) to NAT address both in IP header and inside H.323 message to make video conferencing succeed? Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852465#M456295</guid>
      <dc:creator>Thorsten997</dc:creator>
      <dc:date>2019-03-11T22:18:18Z</dc:date>
    </item>
    <item>
      <title>CBAC with NAT and H.323 problem</title>
      <link>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852466#M456297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="color: #000000; font-family: Arial, Helvetica, sans-serif; text-indent: -28px; background-color: #ffffff;" width="19" /&gt;&lt;/P&gt;&lt;P&gt;CBAC restrictions regarding H.323:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;H.323 V2 and RTSP protocol inspection supports only the following multimedia client-server applications: Cisco IP/TV, RealNetworks RealAudio G2 Player, Apple QuickTime 4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using one of those clients?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 06:59:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852466#M456297</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-24T06:59:39Z</dc:date>
    </item>
    <item>
      <title>CBAC with NAT and H.323 problem</title>
      <link>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852467#M456299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately we are using Polycom devices. Are there any other ways to make that work?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 07:10:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852467#M456299</guid>
      <dc:creator>Thorsten997</dc:creator>
      <dc:date>2012-01-24T07:10:55Z</dc:date>
    </item>
    <item>
      <title>CBAC with NAT and H.323 problem</title>
      <link>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852468#M456302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Thorr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In fact I think this should be working, is there a way you can post your config (with some changes due to security purposes)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 18:08:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852468#M456302</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-24T18:08:44Z</dc:date>
    </item>
    <item>
      <title>CBAC with NAT and H.323 problem</title>
      <link>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852469#M456303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are the configs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show access-lists&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Extended IP access list 101&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 permit ip any any (1964 matches)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show ip inspect all&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;Inspection Rule Configuration&lt;/P&gt;&lt;P&gt; Inspection name TEST&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; h323 alert is on audit-trail is off timeout 3600&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; h323-annexe alert is on audit-trail is off timeout 30&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; h323-nxg alert is on audit-trail is off timeout 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show running-config&lt;/STRONG&gt; {some fragment}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&amp;nbsp; {connects to provider}&lt;/P&gt;&lt;P&gt; ip address x.x.x.x x.x.x.x &lt;/P&gt;&lt;P&gt; ip access-group 101 in&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1 {connects to inside network} &lt;/P&gt;&lt;P&gt; description connect to ASA outside&lt;/P&gt;&lt;P&gt; ip address Y.Y.Y.Y Y.Y.Y.Y&lt;/P&gt;&lt;P&gt; ip access-group 101 in&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip inspect TEST in&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; standby delay minimum 20 reload 20&lt;/P&gt;&lt;P&gt; standby 10 ip Z.Z.Z.Z&lt;/P&gt;&lt;P&gt; standby 10 priority 110&lt;/P&gt;&lt;P&gt; standby 10 preempt delay minimum 20 reload 20 sync 10&lt;/P&gt;&lt;P&gt; standby 10 name Redundancy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; {NATing Polycom's local IP to global one:}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source static A.A.A.A V.V.V.V redundancy Redundancy mapping-id 1&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;ip nat inside source static B.B.B.B W.W.W.W redundancy Redundancy mapping-id 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. &lt;/P&gt;&lt;P&gt;There is Cisco ASA 5510 between router and internal switch. All ports (both in and out) are opened on ASA for Polycom devices.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2012 11:27:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852469#M456303</guid>
      <dc:creator>Thorsten997</dc:creator>
      <dc:date>2012-01-25T11:27:19Z</dc:date>
    </item>
    <item>
      <title>CBAC with NAT and H.323 problem</title>
      <link>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852470#M456305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Thorr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you doing inspection on the ASA for h323 and h323 ras??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2012 17:14:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852470#M456305</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-25T17:14:11Z</dc:date>
    </item>
    <item>
      <title>CBAC with NAT and H.323 problem</title>
      <link>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852471#M456307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, I've turned off both h323 and h323 ras inspection on ASA. (The same result is achieved with inspection turned on on the ASA)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 05:49:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852471#M456307</guid>
      <dc:creator>Thorsten997</dc:creator>
      <dc:date>2012-01-26T05:49:12Z</dc:date>
    </item>
    <item>
      <title>CBAC with NAT and H.323 problem</title>
      <link>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852472#M456309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Thorr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA??? Isn't his a router running CBAC?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 17:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852472#M456309</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-26T17:10:28Z</dc:date>
    </item>
    <item>
      <title>CBAC with NAT and H.323 problem</title>
      <link>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852473#M456311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, ASA is between router and local network switch. As I'm doing NAT on border router I need addresses inside H.323 messages to be NATed too, so that's why I'm trying to use CBAC. (Some people states that CBAC in conjunction with NAT can translate addresses both in IP header and in H.323 messages)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Feb 2012 17:25:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852473#M456311</guid>
      <dc:creator>Thorsten997</dc:creator>
      <dc:date>2012-02-01T17:25:06Z</dc:date>
    </item>
    <item>
      <title>CBAC with NAT and H.323 problem</title>
      <link>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852474#M456313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Thor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is correct, the embedded ip address should be translated, all you need is the H323 inspection&lt;/P&gt;&lt;P&gt;ip inspect xxxx h323&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;ip inspect xxxx h323callsigalt &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Feb 2012 17:35:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-with-nat-and-h-323-problem/m-p/1852474#M456313</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-01T17:35:54Z</dc:date>
    </item>
  </channel>
</rss>

