05-16-2013 12:18 AM - edited 03-18-2019 01:07 AM
I have given new Public IP to my Firewall(VCS Expressway), It shows me H323 and SIP status Active in traversal Zone, as well as it shows Active in VCS Control. but unable to connect to public IP. It will get disconnected automatically and shows unreachable destination in Expressway Logs.
I have restarted my whole system 2 times after making changes in Expressway
Please Suggest me the solution
05-16-2013 12:39 AM
Ensure "Calls to unkown IP addresses" is set to "Indirect" on the VCS-C and "Direct" on the VCS-E.
Also make sure there's no alg/helper or h.323 inspection happening on your firewall.
Test with known good destinations such as public test sites; try 71.14.2.157 and/or 71.14.2.158
If you can connect to those, then your end is fine and the problem is most likely with the other site, if you can't connect to those, then the problem is most likely at your end.
/jens
05-19-2013 11:08 PM
Yes, I have already set it to same as you said.
1. previously we use Public IP which is in use for our office network. so it were get peer with our office network gateway
e.g 10.10.10.3 - Express way IP, I had putted it in peer1 address of traversal zone of VCS control it shows,
peer1 H.323: Active: 10.10.10.1:18869
SIP: Active: 10.10.10.1:38400 , in traversal zone of VCS Expressway
2. when we change Public IP which is different from our network, i.e 20.20.20.6 in traversal zone of VCS Control as well as made changes in IP setting of VCS Expressway.
In this case I am able to recieve incoming calls on public network with this (20.20.20.6) IP, but can not dial it on public network it automatically get disconnected. after putting new Public IP in my VCS Expressway it shows,
peer1 H.323: Active: 10.10.10.1:18869
SIP: Active: 10.10.10.1:38400 , in traversal zone of VCS Expressway, but it should shows
peer1 H.323: Active: 20.20.20.1:18869
SIP: Active: 20.20.20.1:38400........(20.20.20.1 : which is gateway of new public IP 20.20.20.6)
05-19-2013 11:20 PM
what version of VCSC and VCSE are you using?
are you using dual port of VCSE?
have you enabled Assent?
are all the required ports on FW between VCSC and VCSE opened?
enable Diagnostic logging on VCS and see what messages you get as result of failure?
05-19-2013 11:34 PM
1. Soft version of VCSC and VCSE : X 7.1
2. I am using single port Of VCSE
3. I have already enabled Assent of traversal zone in VCSE
4. All ports are open which is required for VCSC and VCSE
05-19-2013 11:43 PM
ok. so are you using NAT'ed address on VCSE?
05-19-2013 11:44 PM
no.
05-19-2013 11:45 PM
ok what failure message do you see in network log of VCSC/VCSE? (enable DEBUG mode)
05-20-2013 12:23 AM
It shows unreachable destination
05-20-2013 12:27 AM
need more than that. like. error code 480 unreachable destination, 10.1.2.3 reject connection/ time out received.
etc. etc.
the whole error, otherwise open TAC case to be looked at it.
regards, Ahmad
05-20-2013 12:42 AM
while dial to external Public IP:::::
1. tvcs: Event="
" Service="
" Src-ip="
" Src-port="
" Src-alias-type="
" Src-alias="
" Src-alias-type="
" Src-alias="
" Dst-ip="
" Call-serial-number="
aead802c-bd6e-11e2-b247-0010f32379c6
" Tag="
1e9e5c12-bd6f-11e2-9df7-0010f32378e2
" Protocol="
" Response-code="
" Level="
" UTCTime="
"
2.
tvcs: Event="
" Service="
" Src-ip="
" Src-port="
" Src-alias-type="
" Src-alias="
" Src-alias-type="
" Src-alias="
" Dst-ip="
" Call-serial-number="
5e9343e6-bd6f-11e2-9738-0010f32379c6
" Tag="
ce85d678-bd6f-11e2-949f-0010f32378e2
" Protocol="
" Response-code="
" Level="
" UTCTime="
"
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide