cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
957
Views
0
Helpful
7
Replies

One way video between Movi(external) to Movi(Internal by VPN)

startryst
Level 1
Level 1

Hi, Experts

Movi(external) means Movi registered to VCS Expressway

Movi(Internal by VPN) means the Movi registered to VCS Control under VPN connection.

1. Movi(external) call Movi(external) successful: bi-directional audio/video

2. Movi(Internal by VPN call Movi(Internal by VPN) successful: bi-diretional audio/video

3. Movi(external) call Movi(Internal by VPN): Movi(external) couldn't receive audio/video, but Movi(Internal by VPN) can received the audio/video from MOvi(external), and when call established, the Turn relays shown 18.

4. VCS Expressway deployed in public routable IP addres without any firewall in front of it.

7 Replies 7

sekuzmin
Level 1
Level 1

Hi,

I'd recommend read throught following document and double-check Traversal zone configuration and search rules on VCSC and VCSE - Step 8 and 9. Make sure, as well, that all necessary ports are opened on firewall, between VCSC and VCSE - "Appendix 3 – Firewall and NAT configuration"

http://www.cisco.com/en/US/docs/telepresence/infrastructure/vcs/config_guide/Cisco_VCS_Basic_Configuration_Control_with_Expressway_Deployment_Guide_X7-2.pdf

Hi, Sergey

I've checked again for the zone and search rule configuration according to that document, all configuration are correct, and btw, except traversalzone, there isn't any ports need to be configured between VCSC and VCSE, as all connections are initialed from VCSC which is the inside of the FW, and this is fully allowed from the firewall perspetive.

but anyway, thanks for your advice here.

Tomonori Taniguchi
Cisco Employee
Cisco Employee

What type of VPN connection are you running on Jabber Video client PC that registered on VCS-C, split tunnel?

What happen if you disable ICE feature on Jabber Video client (disable ICE on provisioning template).

Hi, Tomonori

Anyconnect Secure Mobility Client, and yet, it's running in split tunnel mode. Is it becuase of the split tunnel?

After checking for the split tunnel, I found the setting of that is correct, and the key thing is the VCS Expressway's public IP address didn't in the split tunnel, which means, the traffic heading to TURN is out of the VPN tunnel....even the Movi client is connected to VCS Control by VPN...

Tried, disabling ICE didn't helps on this...

I suggest to take a diagnostic log on VCS and verify which address that Jabber Video negotiated for media traffic.

And also capture sniffer log on both sides (Jabber Video client) to verify RTP destination IP address.