<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Video Calls through FWSM ring but cannot answer in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/video-calls-through-fwsm-ring-but-cannot-answer/m-p/1648346#M596842</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would strongly recommend opening a TAC case so a Cisco engineer can investigate the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Dec 2010 10:52:34 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-12-29T10:52:34Z</dc:date>
    <item>
      <title>Video Calls through FWSM ring but cannot answer</title>
      <link>https://community.cisco.com/t5/network-security/video-calls-through-fwsm-ring-but-cannot-answer/m-p/1648345#M596829</link>
      <description>&lt;P&gt;Running FWSM Firewall Version 3.1(4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that calls originating from the outside of the firewall to the inside will ring but you cannot answer. The internal video conference server is a Polycom HDX 7000. There are ANY/ANY rules to/from this server and the default application inspection policy is set for h323/ras/h225 as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ils&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp error&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I don't think this is relevant, but we also have some custom inspection policies as follows:&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;class-map class_sqlnet4&lt;/DIV&gt;&lt;DIV&gt; match port tcp eq 1433&lt;/DIV&gt;&lt;DIV&gt;class-map class_sqlnet5&lt;/DIV&gt;&lt;DIV&gt; match port tcp range sqlnet 1541&lt;/DIV&gt;&lt;DIV&gt;class-map class_sqlnet6&lt;/DIV&gt;&lt;DIV&gt; match port tcp eq 3306&lt;/DIV&gt;&lt;DIV&gt;class-map class_sqlnet7&lt;/DIV&gt;&lt;DIV&gt; match port tcp eq 5090&lt;/DIV&gt;&lt;DIV&gt;class-map class_sqlnet8&lt;/DIV&gt;&lt;DIV&gt; match port tcp eq 1742&lt;/DIV&gt;&lt;DIV&gt;class-map class_h323_h2253&lt;/DIV&gt;&lt;DIV&gt; match port tcp eq 11720&lt;/DIV&gt;&lt;DIV&gt;class-map class_h323_h2252&lt;/DIV&gt;&lt;DIV&gt; match port tcp eq 2263&lt;/DIV&gt;&lt;DIV&gt;class-map class_sqlnet&lt;/DIV&gt;&lt;DIV&gt; match port tcp eq 1025&lt;/DIV&gt;&lt;DIV&gt;class-map class_sip_tcp&lt;/DIV&gt;&lt;DIV&gt; match port tcp eq sip&lt;/DIV&gt;&lt;DIV&gt;class-map class_h323_h225&lt;/DIV&gt;&lt;DIV&gt; match port tcp eq 1300&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;class class_h323_h225&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect h323 h225&lt;/DIV&gt;&lt;DIV&gt; class class_h323_h2252&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect h323 h225&lt;/DIV&gt;&lt;DIV&gt; class class_h323_h2253&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect h323 h225&lt;/DIV&gt;&lt;DIV&gt; class class_sip_tcp&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect sip&lt;/DIV&gt;&lt;DIV&gt; class class_sqlnet&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect sqlnet&lt;/DIV&gt;&lt;DIV&gt; class class_sqlnet4&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect sqlnet&lt;/DIV&gt;&lt;DIV&gt; class class_sqlnet5&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect sqlnet&lt;/DIV&gt;&lt;DIV&gt; class class_sqlnet6&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect sqlnet&lt;/DIV&gt;&lt;DIV&gt; class class_sqlnet7&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect sqlnet&lt;/DIV&gt;&lt;DIV&gt; class class_sqlnet8&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect sqlnet&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I have been making test calls from a software client on my laptop to this video conf server. Calls that do not traverse the firewall complete as expected, but calls through the firewall ring but will not answer. The error message on the video conf server is:&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;&lt;SPAN&gt;Your call cannot be completed because the far system is not compatible with the H.323 communication standards used by this system.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;The error message on the client is:&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;P class="MsoNormal"&gt;The far end system is capable of receiving the call but rejected it for some unknown reason.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;And finally I have wireshark captures for both good (internal) and bad (external to internal) calls which I've uploaded... (I'm attaching several bad captures)&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;I've worked with Polycom support, but all they can really say is to verify the appropriate ports and ip inspection is configured, which I believe is good.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Thanks in advance for you help, this is becoming quite an issue here as more and more video apps are being rolled out... &lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Chris&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:27:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/video-calls-through-fwsm-ring-but-cannot-answer/m-p/1648345#M596829</guid>
      <dc:creator>royalle01</dc:creator>
      <dc:date>2019-03-11T19:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Video Calls through FWSM ring but cannot answer</title>
      <link>https://community.cisco.com/t5/network-security/video-calls-through-fwsm-ring-but-cannot-answer/m-p/1648346#M596842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would strongly recommend opening a TAC case so a Cisco engineer can investigate the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Dec 2010 10:52:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/video-calls-through-fwsm-ring-but-cannot-answer/m-p/1648346#M596842</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-12-29T10:52:34Z</dc:date>
    </item>
    <item>
      <title>Video Calls through FWSM ring but cannot answer</title>
      <link>https://community.cisco.com/t5/network-security/video-calls-through-fwsm-ring-but-cannot-answer/m-p/1648347#M596848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi, did you ever get an answer to this?&amp;nbsp; I am having a similar problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Christal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Jun 2011 12:34:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/video-calls-through-fwsm-ring-but-cannot-answer/m-p/1648347#M596848</guid>
      <dc:creator>CJRealmuto</dc:creator>
      <dc:date>2011-06-12T12:34:33Z</dc:date>
    </item>
  </channel>
</rss>

