I am using a PIX 506E to connect to a Concentrator 3005. I have used both Easy VPN (Network extension mode) and SITE-SITE VPN configs. I'm able to telnet, ping, ftp, web, file transfer with no problem.
I cannot establish a connection from one video conferencing unit attached to the PIX LAN to the other video conferencing unit attached to the Concentrator LAN. I'm certain routing and reachability is not an issue.
The manufactuer indicates the following are needed ports for the units to establish a connection:
-------------------
1719 H323/RAS UDP
1720 H323/Q931 *TCP
2326-2373 (2837)** H323/RTP UDP
5555-55xx (5587)** H323/H.245/Q.931 TCP
The first outgoing call uses 5555 for outgoing Q.931 and 5556 for H.245, next uses 5557 for
Q.931 and 5558 for H.245, etc. Each incoming H.323 call uses the next available port for
H.245. Disconnecting a site in a call will not free up available 55XX ports until the whole
conference is down.
--------------
Do I need to add FIXUP PROTOCOL and/or access-lists to my outside interface on the PIX?
My understanding of a VPN tunnel w/tunnel everything is that the tunnel is wide open? That is to say there are no restrictions on what traffic (IP and/or ports) may traverse the link?
I've looked all over Cisco site/Google and even hit the books with no success!