?
Solved

Lifesize room220 behind ASA5505

Posted on 2010-11-10
6
Medium Priority
?
2,440 Views
Last Modified: 2012-05-10
We are having issues making or receiving video calls on our new Lifesize Room 220, behind an ASA. it is in our DMZ, with a static NAT translation for a public IP.

The following ports are open to it:  tcp 1720, tcp 60000-64999  udp 60000-64999 and I have the proper outside ACL applied.

The issue: We have a block of 13 public IPs from Comcast. If I connect directly to the comcast modem with a laptop, pull a public IP, I can access the Lifesize device no problem via its publc IP. It hits the outside interface of the ASA and routes accordingly. . However, anyone outside of our public IP block can NOT access it.  I have never seen this issue before.

We thought it was a routing issue with our cable internet provider, but its not.  Because if I plug the lifesize directly into the cable modem, it grabs a public IP via DHCP, and works like a charm

 I was told by our vendor that these devices had issues behind Cisco devices. Anyone have any experience with this? We have several other publicly accessible devices in this DMZ that don't have any issues.

Thanks
0
Comment
Question by:orus
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
6 Comments
 
LVL 10

Accepted Solution

by:
cstosgale earned 2000 total points
ID: 34106930
If you can connect to it from outside your ASA your config is unlikely to be the problem. I would make sure this is not a routing issue. Is the ASA the default route for the network the lifesize is on, and is the ASAs default route via that link?

Also, turn of h.323 inspection on the ASA, and make sure you have specified the public IP of the lifesize unit in it's config. I think there is some nat translation stuff to turn on on the lifesize as well.
0
 

Author Comment

by:orus
ID: 34106963
the ASA's default route, is the gateway given to us by Comcast

route outside 0.0.0.0  0.0.0.0  75.xxx.xx.190

-the public ip of the lifesize is on the same network as the gateway specified above (.190)
-h.323 inspection was already off

The tech tried using nat in the device then tried it disabled. Neither worked. I'm not sure how much experience he had, but we tried everything on our end
0
 
LVL 10

Expert Comment

by:cstosgale
ID: 34107393
Definitely should be enabled on the life-size, and the public ip must be specified.  This definitely should work, I have done it a number of times. I would do a packet capture on the asa (this can be done from the wizards menu in asdm).  This will show you what is missing.

Also make sure you are on version 8 or later on the asa.
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 

Author Comment

by:orus
ID: 34107529
I did do a capture. I captured any traffic hitting the public ip of the lifesize.  The only traffic which hits the asa is traffic initiated from our own public ip block, as specified above during my test

0
 

Author Comment

by:orus
ID: 34107546
We are at 8.04.   I just dont get it
Ive let tons of stuff into the dmz before in other  networks

Maybe the tech didnt do nat right
0
 

Author Closing Comment

by:orus
ID: 34107952
Let me know if u have any other ideas
0

Featured Post

Get your Conversational Ransomware Defense e‑book

This e-book gives you an insight into the ransomware threat and reviews the fundamentals of top-notch ransomware preparedness and recovery. To help you protect yourself and your organization. The initial infection may be inevitable, so the best protection is to be fully prepared.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question