07-15-2012 10:16 AM - edited 03-11-2019 04:31 PM
Hello,
I recently put in production a new firewall 5515X , but we had some issue related to the WoIP and the Video Calls. Our solution for Video its similar to the voip it use UDP to send the images and voice, we notice that at the begining the video calls between 2 offices (VPN site to site) cut for moments or it didnt show the image and sound,
In the case of VoIP (we use a sip provider ) we could not make outbounds calls and received calls.
After some troubleshooting we decide on disable the inspection for the SIP and ICMP after that the Voip works but the video calls didnt work anymore, we enable again the parameters for the SIP and ICMP and the video calls work and the voip no for a while.
What other test can i do in order to find the root of this? the inspection can delay or drop the packets for this 2 services?
07-15-2012 11:09 AM
Hello Luis,
Do you have enabled the h323 inspection?
Do you have any content filter in your network?
Does it work when you do a videocall to a device on the internet ( not on the L2L vpn)
That being said I would recommend you to first add the inspections ( SIP,H323 ras and h225) and afterwards do a clear local-host ( with this we will clear al the connections previously established by the ASA so future ones will have the new inspection parameters)
If it does not work then we will need to do captures on both interfaces while the inspections are applied( If is going through the VPN tunnel then just on the inside interface)
Cap capin interface inside circular-buffer tracer match ip host x.x.x.x (local unit host) y.y.y.y (remote device)
If the other VPN endpoint it's an ASA then do the capture on their side as well.
Regards,
Julio
CSC is a free support community, please take your time to rate all of the engineer's answers.
07-15-2012 11:29 AM
Hello,
thank you for your reply about your questions.
- Yes, i had enable the h323 inspection
- there is not content filter in our current network.
-It doesnt work when we tried to call a device on internet. I made the clear conn protocol udp & tcp after i disable the inspection for icmp, sip, and my voip calls work, but the video calls stop to work.i enable the inspections again and it work again the video and with luck the voip calls.
This video solution its special because it needs to chante the udp timeout to at least 30 minutes.
Regards,
07-15-2012 11:44 AM
Hello,
Its clear local-host not clear conn!
So when you try to connect to a remote end on the internet, do captures on both interfaces inside/outside
Julio
CSC is a free support community, please take your time to rate all of the engineer's answers.
07-16-2012 12:03 PM
Hello,
We tested today again our internet connection but is still giving us problems, to upload to the VPN or internet is not working , we didnt see any drop or packet loss but we disable some inspect features in order to increase our internet speed and vpn speed.
Regards,
07-16-2012 12:06 PM
Im seeing this in the firewall
}
PERFMON STATS: Current Average
Xlates 16/s 1/s
Connections 44/s 13/s
TCP Conns 30/s 6/s
UDP Conns 7/s 4/s
URL Access 0/s 0/s
URL Server Req 0/s 0/s
TCP Fixup 1742/s 0/s
TCP Intercept Established Conns 0/s 0/s
TCP Intercept Attempts 0/s 0/s
TCP Embryonic Conns Timeout 0/s 0/s
HTTP Fixup 0/s 0/s
FTP Fixup 0/s 0/s
AAA Authen 0/s 0/s
AAA Author 0/s 0/s
AAA Account 0/s 0/s
VALID CONNS RATE in TCP INTERCEPT: Current Average
N/A 1037.50%
07-16-2012 12:20 PM
Hello Luis,
You will need to gather the captures with the inspections enabled.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide