Question

Polycom and Watchguard Firebox 500

Asked by: bfurst

My company recently purchased a Video Conferencing solution from Polycom, the VSX 7000 camera. After getting it all connected and configured, I made a video conference call to the Polycom help desk to test it out.

The connection was successful, and the person at the help desk could see me, but I couldn't see them. I was told this was a port forwarding problem and that I would need to change some settings on our firewall, a Watchguard Firebox 500. I was given the necessary ports needed to open it up and went through and manually added a custom service that allowed forwarding to the proper internal address and tried to make the call again. Still no video from the help desk.

I then tried to enable 1-to-1 NAT by purchasing a second static IP and enabling the Any service to allow ALL traffic to be forwarded to and from the internal address. When I did that, I couldn't even connect the call to the helpdesk. I also tried enabling the NAT/Firewall transversal option on the VSX 7000, but still nothing. I've tried it in every conceivable configuration I could think of, but the best I can manage is the one-way link with my firebox log spitting out errors on protocol unknown ?.

After talking with the Polycom rep for a little while, he made me check that the Firebox was compatible with the H323 protocol, which the manual said it was-in dynamic NAT mode only. He suggested I call watchguard, which I did, only to find out that my predescessor had allowed our license with watchguard support to expire! This would cost us a little over $700 to renew for a year, including the penalty fee for not renewing during our original license. Since we're a nonprofit organization in a rather tight financial spot at the moment (we got the polycom setup to cut down on travel costs with our HQ), this isn't my best option.

I voiced my concerns to the technical support member at Watchguard that even if I renewed the subscription to their support service, is there any guarantee that our firebox would be compatible with the polycom system? He said he couldn't guarantee it, but he knows that it should work as they have instructions for it (but can't send me them or give me hints since I'm out of contract).

We will probably renew our subscription when things become more financially stable as the firebox itself is close to three times the cost, but we really need to get this up and going as soon as possible and I'd really like to know that it can be done with our current setup before we move forward.

So I'd like to ask if anyone has any ideas on how to make this work, or has any experience with these systems, I would GREATLY appreciate any help you could give. I'm assigning this 500 points, as we are quite desperate now. Thanks!

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2006-09-01 at 02:54:52ID21975131
Tags

watchguard

,

polycom

,

firebox

Topic

Conferencing Software

Participating Experts
5
Points
500
Comments
16

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Changing Admin password on a Watchguard Firebox
    How do I change the Admin login and update passwords on a Watchguard Firebox.
  2. Port Forwarding on a WatchGuard Firebox
    I've been informed that I need to forward port 3389 to one of my private IPs to get Microsoft's Remote Desktop software to function. I'm running a WatchGuard Firebox System 5.0, and the manual isn't giving me much information as to how to do it. Anyone else have one of thes...
  3. Cisco VPN Client to Watchguard firebox 700
    Hello. Is it possible to use a Cisco VPN Client to connect to a Watchguard firebox 700? Regards Daniel
  4. Migration of WatchGuard Firebox x1000 to WatchGuard …
    It seems like no specify document I can find regarding migration of WFS 7.3 to WSM 8.3. I have a WatchGuard Firebox x1000 and a software is running WFS 7.3 version, with VPN and DHCP. We have bought a new WatchGuard Firebox x1650 with new software called WSM 8.3. My Compan...
  5. Watchguard Firebox & Websense
    We are moving from a Cisco Pix to a Watchguard X550e. I would like to utilize Websense instead of the onboard Webblocker that comes with the Firebox. Does anyone know how to configure the proxy to to do this?
  6. Routing with Watchguard Fireboxes
    I have a set of static IP addresses asigned to me by my ISP. Normally I would use my static IP's directly and simply assign them to the public interfaces on whichever device I was configuring. In this scenario however, the ISP has provided 1 true / real static IP and the re...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: charan_jeetsinghPosted on 2006-09-02 at 08:51:42ID: 17442610

first of all... though in my org also watchguard is put up majorly but i am not very happy with it... nowhere in frnt of cisco/checkpoint.  now coming to ur problem.....

1) hav u configured log server for it?
2) if yes can u see any specific packet drops/connection refused in log from the ip of ur test partner.....
3) if no there is an option: Hostwatch, put a filter for ur ip and his ip and see concurrent connections in real time.... see if any packet drops are there on any specific port!!

in the mean time i will see if there is any concrete solution available for it!

 

by: bfurstPosted on 2006-09-05 at 13:00:40ID: 17458555

Hey there, thanks for the advice.

I put the filters on and it shows that port 0 is being denied.

 

by: StonewallJacobyPosted on 2006-09-05 at 14:10:14ID: 17459095

Have you added the H.323 proxy and given it appropriate rules?  Also, I can tell you that watchguard's 1-to-1 NAT is NOT the same thing as watchguard dynamic NAT.  If you are not careful with 1-to-1, you can conflict with the existing "default" dynamic NAT rules that the watchguard box implements.  

Try killing your 1-to-1 rules, get back to your configuration that was partially successful, and add the H323 proxy with appropriate inbound and outbound traffic rules (heck, try allowing ANY to ANY to see if it works).

 

by: hstilesPosted on 2006-09-06 at 07:56:47ID: 17463620

Could you clarify the following:

1) The exact model of the Firebox
2) The version of Watchguard software you are running

However, I'll assume you are using v 7.x of the Watchguard Firebox System.

Try the following

1) Add the additional IP address to the external interface of the firebox
2)Click on setup, NAT and click on 1-1 NAT Tab and enable.  Add an entry with following settings -
interface - external
no.of hosts to NAT - 1
NAT base - 2nd IP address from ISP
Real base - internal IP of videoconferencing PC/device
Under Dynamic NAT exceptions add an exception from internal address to external

3) create incoming and outgoing rules for the H323 proxy.  Your incoming rules do not need to use a NAT rule.  Simply use the internal address of your videoconferencing host/device.

 

by: bfurstPosted on 2006-09-06 at 22:32:55ID: 17468379

Hey there, thanks for the additional comments, guys.

I have an X500, running version 7.30-B2938.

I did everything you two said, and its still showing no audio/video incoming, but my video/audio is showing up on their screen. On the Polycom, it has an option for NAT transversal, or setting it to show the outside IP address as its own. I'll try playing around with that, but I don't know if that would be beneficial in this situation or not. Regardless, I'll keep trying and any more help would be GREATLY appreciated!

 

by: bfurstPosted on 2006-09-06 at 22:40:44ID: 17468393

Additionally, when I view the connection through the hostwatch, these are the connections I get:

Source:            Destination:     Port:   Connection:      Details
192.168.5.222  12.31.173.174  2852    Dynamic NAT    to <MyPublicIPHere>:32778
192.168.5.222  12.31.173.174       0    Denied              rsvp Thu Sept 7 05:35:44

I hadn't noticed that before, but it seems as though the internal address is STILL trying to use Dynamic NAT even though I told it not to. Is this normal? The log spits out this repeatedly, until I disconnect:

09/07/06 01:35  firewalld[127]:  log out eth1 160 rsvp 24 30 192.168.5.222 12.31.173.174 unknown ? (ip options)

 

by: bfurstPosted on 2006-09-06 at 23:17:50ID: 17468488

Is there a way to edit these things, 'cause I hate to keep adding more comments...

Anyway, I added 192.168.5.222 to external as a rule in addition to 192.168.5.222 to <MyPublicIPHere>, and that actually caused me to be unable to even connect to the Polycom help desk. It just kept dialing, and nothing showed up on Hostwatch. I assume this means that it is trying to use 1-to-1 NAT, but is failing for some reason. I tried it with and without NAT transversal and still no luck.

 

by: StonewallJacobyPosted on 2006-09-09 at 14:33:22ID: 17487266

OK, I've spent a little time reviewing the documentation on the Polycom7000 and the watchguard.  The digging I have done on this subject doesn't look promising.  All searching on the Watchguard site leads me to the same Watchguard support page about H.323, and it says that incoming calls are not supported with incoming static-NAT.  Incoming static NAT is how Watchguard boxes handle incoming traffic (incoming connections).  
From Watchguard:

"Allowing this service inbound

In order to allow external clients to connect to H.323 systems behind the Firebox, an H.323 service icon must be added to the Policy Manager with appropriate incoming and outgoing rules. Note that this service does not work properly with incoming static-NAT, which means that if your clients are to accept incoming H.323 connections, they must have public IP addresses. This does not affect clients creating outgoing connections with private IP addresses. There are other video applications like CUseeMe that do work properly with an incoming static-NAT rule.

Allowing this service outbound

In order to allow your internal users to connect to other H.323 endpoints on the Internet, simply add an H.323 service icon to your Policy Manager configuration with the desired outgoing properties. This service works fine from clients with internal private or public IP addresses. The Firebox is able to follow the dynamic negotiation required for H.323 and route private IP address requests appropriately."


There may be a brute force (though extremely insecure) way to handle this.  You say you now have 2 public IP addresses.  Assign one of them to the watchguard's external interface, and the other to the polycom.  Buy a small 4 port or 8 port network switch.  Go to the wiring closet and find the ethernet interface that is your internet connection (WAN side).  Plug the internet WAN ethernet link into the switch.  PLug a patch cable from this small switch to the wathguard external interface.  Find the exact network drop that goes to the polycom, disconnect it from your production network switch, and plug it into the small network switch.  This places your polycom unit directly on the INternet, without firewall interference (or protection) of any kind.  If it doesn't work now, something else is wrong.

This should be seen as a temporary and last-ditch measure.  You may wish to explore the security features of the polycom (which don't look very robust).  It probably means that anyone who hits your IP address will be able to connect, whether you want them to or not.  This does NOT expose your production network, just the polycom unit.  Try it and let me know what happens.

 

by: bfurstPosted on 2006-09-10 at 15:50:40ID: 17490894

Thanks again for the reply StonewallJacoby.

I went ahead and set all the public info on the Polycom and bypassed the firewall. First try I was connected fully and able to see into Polycom's office! So it does in fact work, it's just proof that the firewall is causing problems. I honestly don't know what else to try, and I think you're correct in assuming that this probably isn't going to work without bypassing the firewall altogether-something we'd definately like to avoid.

According to the wording in that first article you quoted about inbound H.323 connections, do you think it would work to assign the Polycom the public IP address, leave it behind the firewall, remove the alias from the external port and do a manual route instead?

 

by: StonewallJacobyPosted on 2006-09-10 at 17:03:32ID: 17491068

Here's the problem: Even if you could do that, you would still be effectively bypassing the firewall by routing traffic from that public IP to the polycom.  ANyway, I don't think the watchguard box will tolerate having IP's from the same subnet on two different interfaces (in your case, trusted and external).  



Are you trying to host videoconferences?  Are you trying to videoconference with just one other location?  If it is just one other location, then consider setting up a VPN tunnel between your partner and yourselves:
http://www.h323forum.org/papers/polycom/DeployingSecureIPVideoNetworks.pdf#search=%22polycom%20video%20conferencing%20authentication%22


Maybe you should investigate polycom's videoconferencing gear related to hosting, authentication and security, etc.  See the third article on this page:
http://bcisdvcs.wordpress.com/tag/rus-grant/


hmmmm...I just found this....
"A common problem with VC through NAT is that the H.323 payload itself makes a reference to the inside IP address of the VC system. In other words, the system that you are making a call to on the other side of the firewall will try to send the return streams to an unroutable IP address.

There are a few ways of overcoming this. Both Polycom and Tandberg (and others) for example allow you to configure your system so that it uses the outside NAT'ed address rather than its private address in the payload."

I remember something from your polycom setup where you can tell the polycom unit the outside (public IP) address it will use.  This must be for the reason stated above.  (That part of the polycom setup is on pages 3-16 and 3-17 of the downloadable polycom manual "Administrator's Guide for the VSX Series Version 8.5").  Try configuring the H.323 proxy on the watchguard with incoming and outgoing rules allowing traffic to and from the NAT (inside) IP of the polycom to / from "Any".  Configure the polycom "NAT Configuration - Manual" and "NAT Public WAN Address - your public IP".

If that don't work, I don't think it's gonna.



 

by: hstilesPosted on 2006-09-11 at 02:28:08ID: 17492776

As a compromise, try setting up an ANY rule for the Polycom but still using the 1-1 NAT exceptions procedure I described earlier.  It may well be that the Firebox, in acting as H323 proxy is indeed causing problems with outbound traffic.

 

by: bfurstPosted on 2006-09-11 at 10:41:35ID: 17496407

Thanks for the replies you two.

StonewallJacoby:
I tried using the NAT transversal thing, which allows me to set the polycom to report the public IP as its personal IP and it continues to be be a one way conversation.

hstiles:
I tried setting the Any rule and trying it, and it still gave me the one way viewing, so then I enabled the 1-to-1 Nat without changing anything and it wouldn't let me connect at all. But in enabling the 1-to-1 NAT, I did have to enable the Exceptions to Dynamic Routing or it would ignore the 1-to-1.

 

by: hstilesPosted on 2006-09-12 at 00:49:51ID: 17500517

We use an application that sends a simple outbound wakeup packet to an external host.  This packet needs to come from the actual NAT base IP not the external IP of the Firebox.

Therefore I would assume that this configuration is similar to what the Polycom requires.  Using the H323 proxy may complicate matters because the Firebox may be masquerading as the Polycom device.

I would therefore hope that an ANY rule, in conjunction with 1-1 NAT and a dynamic NAT exception would solve the problem.

If not, I can't think of what else you can try.

 

by: bfurstPosted on 2006-09-19 at 10:22:09ID: 17553788

Yeah, I tried your last suggestion hstiles, but dynamic takes precedence over 1-1 and then just gives me the original problems. We decided the only solution was to switch it before it hits the firebox, then run a dedicated line to the conference room. Thanks all for your help anyway.

 

by: rbarwigPosted on 2009-06-12 at 06:20:43ID: 24611908

I too ran into this same problem witrh an X1000 and X1250e, my solution was simple, remove one of the public IPs from the alias table, install a 5 port switch in front of the firebox, then connect a residential Netgear router to the switch, setup the Netgrear with the removed public IP and a different subnet for the LAN interface, connect that to my LAN, and set the VC system to this other subnet, works great!  Costa few dollars more but no issues since I did this.  This also protects your VC system from sitting directly on the internet.

 

by: NBDHSupportPosted on 2010-01-29 at 07:20:55ID: 26438047

The accepted solution of setting up the H.323 proxy worked for me.  I used a combination of the H.323 proxy along with inbound/outbound packet filter rules for additional ports required.  Without the H.323 proxy only inbound worked.  Could not initiate a call.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...