PIX 525 and H.323 handling

Discussion in 'Cisco' started by pfisterfarm, Mar 4, 2008.

  1. pfisterfarm

    pfisterfarm Guest

    Does the PIX 525 have H.323 aware NAT? I've got a videoconferencing
    app behind the PIX that I'd like to provide outside access to a
    vendor.

    The last thing that was changed to get it to work was to fix the NAT
    transversal setting in the videoconferencing software. It was set to
    the local IP address of the machine, rather than the global address.
    Shouldn't the PIX have translated this anyway? I would have expected
    that the PIX would be H.323 aware and do this by default. I'm not sure
    I can tell by the documentation online.
     
    pfisterfarm, Mar 4, 2008
    #1
    1. Advertisements

  2. pfisterfarm

    pmachete Guest

    Which version are you running?
     
    pmachete, Mar 4, 2008
    #2
    1. Advertisements

  3. pfisterfarm

    pfisterfarm Guest

    It's 7.2(2).

    --Steve
     
    pfisterfarm, Mar 4, 2008
    #3
  4. pfisterfarm

    pmachete Guest

    Try to disable fixup:

    policy-map global_policy
    class inspection_default
    no inspect h323 h225
    no inspect h323 ras

    Depends on the videoconf device but some of them support the nat
    traversal by setting the inside and outside address.
    Therefore, the pix/asa fixup should be disabled.

    Just a guess ...

    Regards,
    Pedro
     
    pmachete, Mar 5, 2008
    #4
  5. pfisterfarm

    pfisterfarm Guest

    So this will allow me to leave the NAT transversal option off on the
    videoconferencing software?
     
    pfisterfarm, Mar 6, 2008
    #5
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.