cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
428
Views
0
Helpful
3
Replies

ip communicator over vpn

dzuodar
Level 1
Level 1

hi!

we're facing a problem with ip communicator when the user tries to call from remote location over vpn towards another user also on a remote location with vpn.

the followin situations do work:

ip communicator office <-> ip communicator office

ip communicator remote vpn <-> ip communicator office

only ip communicator remote vpn <-> ip communicator remote vpn doesn't work...

the issue will probably be caused by certain TCP/UDP ports that are not allowed directly between remote clients, call set-up is ok, phone is ringing, but from the moment the called party goes off-hook the call fails or (int the best situation), you can not hear the other side...

anybody with some good input? i have already been searching for which ports should definitely be allowed but i cannot find anything...

thanks and best regards,

Dimitri

3 Replies 3

csacontract
Level 1
Level 1

Are you using a PIX firewall to terminate the VPNs?

PIXes don't support VPN Hairpinning. When you are setting up the call, you are talking to the Call Manager server. But the moment the call is established, the RTP stream tries to go directly between endpoints. This is where the VPN Hairpinning will fail.

I don't know if PIX IOS 7.0 allows for VPN hairpinning yet as it only came out a few days ago. Not sure if IOS VPN endpoints support VPN Hairpin, but I have vague recollections that VPN Concentrators do.

Maybe a question best directed in the security forums if this turns out to be your issue.

Lukeyson

Hi Lukeyson!

thanks already for this information! for your reference: we terminate our vpn on concentrator 3005. i will check out about VPN hairpinning and afterwards post a question on the security forum. will let you know if this did the trick!

cheers,

Dimitri

We are having an issue with IP Communicator over VPN...our issue is : Everything works fine when directly connected to the network, but over VPN..we hear nothing when calling Cisco IVRs. The press options work (press 1, 2, 3) but you can not hear the IVR greeting prompt. It's as if the stream audio is getting blocked. We would like to know what ports as well. Anyone know??