01-24-2019 05:14 AM - edited 02-21-2020 08:41 AM
Hello All,
One of our folks pointed out an issue that I had never noticed (or paid much attention to) before. When opening the Whats App application on an iPhone, there is a delay of 30-45 seconds before the app finishes connecting on our network. We've verified this with 7 iPhones in different areas, however, it does not happen with Android devices. I'm not sure if this started when we migrated to our ASA w/ FTD last year. However, we do have an access rule configured to allow Whats App traffic. The delay does not occur if these iPhone users switch to cellular, or, when connecting over home WiFi networks. I'm curious if anyone else has seen this behavior behind their FTD firewall?
Thanks
Solved! Go to Solution.
01-24-2019 06:12 AM
WhatsApp messenger uses the following ports: 5223, 5228, 4244, 5242, 443, 80 and 5222. Whats App messenger uses the following ports: 5223, 5228, 4244, 5242, 443, 80 and 5222. Ports used in WhatsApp: 80, 443, 4244, 5222, 5223, 5228 and 5242. TCP Ports: 80, 443, 4244, 5222, 5223, 5228, 5242, 50318, 59234
01-24-2019 05:35 AM
However, we do have an access rule configured to allow Whats App traffic
instead of allow rule, use trust rule and see if that make a difference.
01-24-2019 06:08 AM
Thanks for the suggestion Sheraz. I may try that to see if it fixes it also, however, I did notice that when opening Whats App, it was attempting to connect to Jabber port tcp-5222, which was being blocked. I allowed that and Whats App on all devices connect instantly now.
01-24-2019 06:12 AM
WhatsApp messenger uses the following ports: 5223, 5228, 4244, 5242, 443, 80 and 5222. Whats App messenger uses the following ports: 5223, 5228, 4244, 5242, 443, 80 and 5222. Ports used in WhatsApp: 80, 443, 4244, 5222, 5223, 5228 and 5242. TCP Ports: 80, 443, 4244, 5222, 5223, 5228, 5242, 50318, 59234
01-24-2019 06:49 AM
I was thinking what else you can do is. create a object port group and put whatsapp port in that group and create a rule for
for example
ACP Example
inside zone-inside outside zone-outside 192.168.1.0 8.8.8.8 port-source any destination-port whatsapp-custom-ports
than put allow rule so in this you will keep the traffic inspection.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide