<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Presence not working correctly with SIP inspection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508970#M579519</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Federico, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if you got an answer to this already in any other way. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all SIP inspection like any other inspection is used to open up dynamically connection and pre-create xlates and a little bit of voo-doo when NAT is involved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When using VPN connections by default should be permitted and usually we don't do NAT - so you should not normally need sip inspection for VPN flows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That being said I agree that it looks like a problem with interoperability, I'm not aware of any problem with this - nor do I have access to check right now if this is known or not. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if someone already looked into this, if not I'll have a check tomorrow. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 28 Nov 2010 23:01:45 GMT</pubDate>
    <dc:creator>Marcin Latosiewicz</dc:creator>
    <dc:date>2010-11-28T23:01:45Z</dc:date>
    <item>
      <title>Presence not working correctly with SIP inspection</title>
      <link>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508969#M579518</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to bring up a problem that I'm having...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Clients connecting via IPsec VPN and using Personal Communicator.&lt;/P&gt;&lt;P&gt;CUCP 7/ASA 8.2&lt;/P&gt;&lt;P&gt;Clients can connect via VPN, log in to the Personal Communicator and make calls (the chat is not working because all collegues appear offline).&lt;/P&gt;&lt;P&gt;If disabling SIP inspection in the ASA, then the chat works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem is we need SIP inspection enabled.&lt;/P&gt;&lt;P&gt;The Presence server resides behind the ASA and it works fine locally.&lt;/P&gt;&lt;P&gt;Problem is only via VPN due to SIP inspection, how to fix it?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you all!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:14:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508969#M579518</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2019-03-11T19:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: Presence not working correctly with SIP inspection</title>
      <link>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508970#M579519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Federico, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if you got an answer to this already in any other way. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all SIP inspection like any other inspection is used to open up dynamically connection and pre-create xlates and a little bit of voo-doo when NAT is involved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When using VPN connections by default should be permitted and usually we don't do NAT - so you should not normally need sip inspection for VPN flows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That being said I agree that it looks like a problem with interoperability, I'm not aware of any problem with this - nor do I have access to check right now if this is known or not. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if someone already looked into this, if not I'll have a check tomorrow. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Nov 2010 23:01:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508970#M579519</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-11-28T23:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: Presence not working correctly with SIP inspection</title>
      <link>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508971#M579520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marcin,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;There's no NAT for the presence server through the tunnel, but the client will requiere static NAT for public access later on... so SIP inspection will be needed eventually.&lt;/P&gt;&lt;P&gt;Right now... I turned off SIP inspection and the chat works fine through VPN.&lt;/P&gt;&lt;P&gt;If I enable SIP inspection the chat won't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I would like here is to be able to allow the chat to work with SIP inspection enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm still having the problem so I would definitely appreciate your help with this one &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Nov 2010 23:07:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508971#M579520</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-11-28T23:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: Presence not working correctly with SIP inspection</title>
      <link>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508972#M579521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure thing Federico, I'll dig in tomorrow &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Nov 2010 23:22:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508972#M579521</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-11-28T23:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Presence not working correctly with SIP inspection</title>
      <link>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508973#M579522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No spectacular finding on my side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One would be this:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtc62281"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtc62281&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also remember having something similar to this in the past. But I'd need to dig into presence protocol, I believe CUCM had two possible options for presence (transport? not sure what CUCM phrasing on this was), can you check that for me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Nov 2010 10:36:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508973#M579522</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-11-29T10:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Presence not working correctly with SIP inspection</title>
      <link>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508974#M579523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marcin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All I know at this moment is that with SIP inspection enabled the chat won't work... so what I'll do is run some tests and check what messages do I get to see if we can identify the problem.&lt;/P&gt;&lt;P&gt;I will post the findinds and what you're asking too... thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Nov 2010 15:52:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508974#M579523</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-11-29T15:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: Presence not working correctly with SIP inspection</title>
      <link>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508975#M579524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TAC would typically request, ingress and egress captures + syslogs to get started (SIP debugs too ;-))&lt;/P&gt;&lt;P&gt;If you can get that I'll have a look.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Nov 2010 15:56:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508975#M579524</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-11-29T15:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: Presence not working correctly with SIP inspection</title>
      <link>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508976#M579525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marcin, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm including the logs and debug SIP for a connection from a VPN user dporras.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The behavior is the same... with SIP inspection enabled the chat won't work for personal communicator.&lt;/P&gt;&lt;P&gt;I don't see SIP drops in ''sh service-policy'... I'm not sure if I should see packet drops... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can take a look at the attachment I'll appreciate it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Nov 2010 16:41:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508976#M579525</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-11-30T16:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: Presence not working correctly with SIP inspection</title>
      <link>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508977#M579526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I remembered there was something exchanged via different connection then SIP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Nov 30 2010 10:32:29: %ASA-6-302013: Built inbound TCP connection 1357720 for SHDSL:172.16.13.11/53599 (172.16.13.11/53599) to inside:172.16.10.249/443 (172.16.10.249/443) (dporras)&lt;BR /&gt;Nov 30 2010 10:32:30: %ASA-6-302014: Teardown TCP connection 1357720 for SHDSL:172.16.13.11/53599 to inside:172.16.10.249/443 duration 0:00:00 bytes 2889 TCP FINs (dporras)&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding what SIP inspection might be up to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I see for example:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;SIP::Found Event header field with presence package&lt;BR /&gt;Created SIP session for SHDSL:172.16.13.11/53607 to inside:172.16.10.249/5060, 18 total&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; From: sip:dporras@fusionetcorp.local (30);tag=c917b560 (8)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; To: sip:dporras@fusionetcorp.local (30)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Call-ID: 5a16f7020c59da0aNDdlOGM5MjAyMGRmZmFmZmIzYjA0MWQ2OTQ4OWQxNjM. (60)&lt;BR /&gt;Created SIP Transaction for SHDSL:172.16.13.11/53607 to inside:172.16.10.249/5060&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Call-ID: 5a16f7020c59da0aNDdlOGM5MjAyMGRmZmFmZmIzYjA0MWQ2OTQ4OWQxNjM. (60)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CSeq: 1 PUBLISH&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Branch: z9hG4bK-d87543-3c4409660751743c-1--d87543-&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; SIP::Payload not modified&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;SIP::Found valid SIP URI: sip:dporras@172.16.13.11:50021&lt;BR /&gt;SIP::Found Contact sip:dporras@172.16.13.11:50021&lt;BR /&gt;SIP::Found Content-length 0&lt;BR /&gt;SIP::Found Event header field with presence package&lt;BR /&gt;Created SIP Transaction for SHDSL:172.16.13.11/53607 to inside:172.16.10.249/5060&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Call-ID: 5a16f7020c59da0aNDdlOGM5MjAyMGRmZmFmZmIzYjA0MWQ2OTQ4OWQxNjM. (60)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CSeq: 2 PUBLISH&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Branch: z9hG4bK-d87543-80599b0c83043903-1--d87543-&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; SIP::Payload not modified&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see any obvious notion of ASA doing something wrong I don't think the packets are being dropped I suspect they are somehow mangled so the manager doesn't recognize them correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think we'd need more in depth investigation. Traffic capture before and after firewall, with and without SIP inspection + debugs would be a good place to start - but it's not something to be dragged in forum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you open a TAC case? We'll have a look at this one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Nov 2010 22:41:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508977#M579526</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-11-30T22:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: Presence not working correctly with SIP inspection</title>
      <link>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508978#M579527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marcin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was a bug in the ASA code.&lt;/P&gt;&lt;P&gt;Originally I mentioned version 8.2, but the ASA was running 8.0(4) my mistake &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I upgraded the ASA to 8.2(2) and now the chat function works perfectly for Personal Communicator through the VPN (with SIP inspection enabled).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 17:22:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/presence-not-working-correctly-with-sip-inspection/m-p/1508978#M579527</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-02T17:22:40Z</dc:date>
    </item>
  </channel>
</rss>

