Skip to main content
Contributor III
July 22, 2005
Question

Problems with Video Conferencing

  • July 22, 2005
  • 15 replies
  • 8797 views
Problem We get connection, a call is established, but no audio or video passes. Same result with call initiated by either end. I' ve tried setting up what is in the Fortigate Tech Note " H.323 Support" Direct Call Scenario 3: NAT/Route mode, NAT enabled and virtual IP required Pieces and parts FG 400 FW 2.80, build456 Polycom iPower 9800 Current Firewall Policies Int > Ext: Source – Internal-iPower, Destination – External-All, Always, H323, Accept, NAT Dynamic Pool Ext > Int: Source – External-All, Destination – Internal-iPower(Virtual IP), Always, H323, Accept, No NAT What am I missing, or doing wrong? Do I need to create a custom “Video Conferencing” service or a group that includes more ports? Also how does H.264 differ from H.323, with regards to the firewall? Thanks In the dark Mark

    15 replies

    Contributor III
    August 10, 2005
    Hi Mark, Sorry for the late response! I have been struggling with setting up the same situation as you. I had some success with 2.8MR6 but no luck with any other builds. What I have tried to pry out of Fortinet is: 1.) What build should I use? 2.) Are there known problems with Tanberg or Polycom units? 3.) How can I troubleshoot / Diagnose the problem? If I hear anything I' ll post back here.
    Contributor III
    August 10, 2005
    Staylor, Thanks. I finally found the blurb about H.323 not being completely supported in the MR10 release notes. Why would anyone want to read them? I and considering back revving to MR6, but have a couple questions. If I do back-rev, will my saved (full system) settings from MR10 reload into MR6? Is there any important functionality I will lose? Currently I have SPAM filtering disabled, but I am using AV. One other thing to pry out of Fortinet: 4.) Will H.323 be properly fixed in any forthcoming versions, and if so, when? Thanks again. Mark
    Contributor III
    August 10, 2005
    When you drop back to a prior MR it will default your firewall. I backed up both all configs and just the system config. So far I have only had luck restoring just the system config, not all at once in the large file. Be careful dropping down an MR. Hopefully next week I can find some time and get some answers to our questions from our vendor, fortinet or a fortinet (employee) engineer I know. -Scott
    skyhigh
    New Member
    August 10, 2005
    FG 400 FW 2.80, build456 Polycom iPower 9800
    It should work as long as you are not using the FastStart feature (added after MR10) or multiple Gatekeepers. Please open a support ticket if you have not already.
    Contributor III
    August 11, 2005
    Hum, I have two tandberg units and a polycom unit. I' ll have to run some more tests tomorrow and then maybe open a ticket. Thanks! -Scott
    Contributor III
    August 26, 2005
    This really worries me. MR10 claims to fix the H.323 issues. At least the one of not passing H.323. By what you' re saying, it' s not resolved. Have you done any follow up tests?
    Contributor III
    August 29, 2005
    I did get to do some follow up tests. I blow out the VIP' s, rules and everything. I then recreated everything again and still could not get the units to pass traffic. It looks like my end and the other end setup the sessions and negotiate the transfer rate but then never pass any audio or video. After about 20 seconds of looking at a blank screen the Tandburg units say communication error and drop back to the main menu. I opened a ticket Friday Aug 26th in the early AM for this problem. I am still waiting to hear anything back. If I do not hear back by 14:00 today I will forward the ticket number to a Fortinet engineer in my area and see if he has any information / solutions. Management is getting frustrated with this issue and they also were not happy when the rates went up July 1st. We will be evaluating other vendors if this problem can not be resolved in a timely manor. I' ll be sure to keep the forum updated on my progress. (Still optimistic?)
    Contributor III
    August 31, 2005
    I did not use H323 protocol with the fortigate unit. But reading your post about this issue is interesting and i am curious to know would happen if this traffic was encapsulated in an ipsec tunnel.
    Contributor III
    August 31, 2005
    Sorry to say, I' m not sure about how it would work with an IPSEC tunnel. I' ll be happy if I can get a straight IP connection to the internet reliably. After the MR10 upgrade, I tested with mixed results. I don' t know wether to blame the other end or the firewall at this point. Some clarification on the release notes would be nice at this point. I am still waiting for that from the fortinet engineer. When I get the word that it at least SHOULD work, I' ll test a bit more. Seems like I can pass traffic from a few Polycom test sites. But the one I have lots of trouble with is the one at stereo.polycom.com. yet lobby.austin.polycom.com seems to fly every time. If anyone has the time to test, try this and let me know if you get similar results. The stereo one does connect but only sometimes. I usually get what looks like a connect with no audio/video. Polycom issue or a Fortinet one?????[>:]
    BigE
    New Member
    August 31, 2005
    I have been trying to run a video conf through IPSec and have not had very good results. Fortigate 200 2.8 mr8 and Fortigate 100a mr7 on each side of the link. Actually, the 200 crashes when the 100a side picks up the con call.
    BigE
    New Member
    August 31, 2005
    The 200 is crashing when connecting to any other camera. It looks like the CPU gets cranked up too high and the 200 stops sending or recieving any traffic. It may be too busy so I am going to look through my rules.
    Contributor III
    September 1, 2005
    OK. I have to say, I' m an idiot! I set the priority to high on the Policy allowing H.323 traffic. I didn' t specify an amount or any values. Therefore, H.323 was allocated no bandwidth. All testing after correcting that worked fine. What a day!
    BigE
    New Member
    September 3, 2005
    Upgraded to MR10 and now videoconferencing works. There are H.323 issues in MR7, 8, and 9 but they are fixed in 10.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!