Avatar of psdalb
psdalb
 asked on

Cisco ASDM Outbound rule for video conferencing

Hello,

We are having a demo of a video conferencing tomorrow (also a cisco product).  The test is failing.  The instructions are saying to open up for outbound connections ports tcp - 2776, 1720, 2777 and UDP ports 1719, 2776, 2777.

I have opened these up on the ASDM (Access rules) for incoming rules (attached), but it still fails.  I can not see where to change outbound rules on the ASDM  (6.2 for asa).

I have extremely limited experience with command line rules.

Attached is the failure of the test as well.

I turned of the firewall on my pc as well as our web filter to eliminate that from the equation.
firewallSnapshot.JPG
video-failure.txt
Software FirewallsHardware Firewalls

Avatar of undefined
Last Comment
psdalb

8/22/2022 - Mon
pclinuxguru

Well the outside rules your showing are generally Outside -> Inside.

If your trying to open stuff for going inside to outside it would be listed in the Inside section.
pclinuxguru

You could also utilize the packet Traces under Tools. Just fill in the blanks with the info and it will generally tell you what is blocking it if the ASA is blocking it.
ASKER CERTIFIED SOLUTION
psdalb

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
pclinuxguru

You can simply create your permit rules first and at the end do a deny all rule.

The implicit rule is only there because there are no rules. Once you add a rule it removes it.

Rules in ASDM go from top down so if something doesn't match the last rule which is deny everything would take affect.
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
psdalb

ASKER
Expert helped dianose the problem.  This led me to contact Cisco for the ultimate solution.