
Not applicable
Created on 07-22-2005 09:49 AM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Problems with Video Conferencing
Problem
We get connection, a call is established, but no audio or video passes. Same result with call initiated by either end. I' ve tried setting up what is in the Fortigate Tech Note " H.323 Support" Direct Call Scenario 3: NAT/Route mode, NAT enabled and virtual IP required
Pieces and parts
FG 400 FW 2.80, build456
Polycom iPower 9800
Current Firewall Policies
Int > Ext:
Source – Internal-iPower, Destination – External-All, Always, H323, Accept, NAT Dynamic Pool
Ext > Int:
Source – External-All, Destination – Internal-iPower(Virtual IP), Always, H323, Accept, No NAT
What am I missing, or doing wrong? Do I need to create a custom “Video Conferencing†service or a group that includes more ports?
Also how does H.264 differ from H.323, with regards to the firewall?
Thanks
In the dark
Mark
15 REPLIES 15

Not applicable
Created on 08-10-2005 06:18 AM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Mark,
Sorry for the late response! I have been struggling with setting up the same situation as you.
I had some success with 2.8MR6 but no luck with any other builds.
What I have tried to pry out of Fortinet is:
1.) What build should I use?
2.) Are there known problems with Tanberg or Polycom units?
3.) How can I troubleshoot / Diagnose the problem?
If I hear anything I' ll post back here.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Staylor,
Thanks. I finally found the blurb about H.323 not being completely supported in the MR10 release notes. Why would anyone want to read them?
I and considering back revving to MR6, but have a couple questions.
If I do back-rev, will my saved (full system) settings from MR10 reload into MR6?
Is there any important functionality I will lose? Currently I have SPAM filtering disabled, but I am using AV.
One other thing to pry out of Fortinet:
4.) Will H.323 be properly fixed in any forthcoming versions, and if so, when?
Thanks again.
Mark


Not applicable
Created on 08-10-2005 10:39 AM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When you drop back to a prior MR it will default your firewall. I backed up both all configs and just the system config. So far I have only had luck restoring just the system config, not all at once in the large file. Be careful dropping down an MR.
Hopefully next week I can find some time and get some answers to our questions from our vendor, fortinet or a fortinet (employee) engineer I know.
-Scott
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FG 400 FW 2.80, build456 Polycom iPower 9800It should work as long as you are not using the FastStart feature (added after MR10) or multiple Gatekeepers. Please open a support ticket if you have not already.
Fortinet Technical Support
Fortinet Technical Support

Not applicable
Created on 08-10-2005 06:41 PM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hum, I have two tandberg units and a polycom unit. I' ll have to run some more tests tomorrow and then maybe open a ticket.
Thanks!
-Scott

Not applicable
Created on 08-26-2005 05:56 AM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This really worries me. MR10 claims to fix the H.323 issues. At least the one of not passing H.323. By what you' re saying, it' s not resolved. Have you done any follow up tests?

Not applicable
Created on 08-29-2005 06:49 AM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did get to do some follow up tests. I blow out the VIP' s, rules and everything. I then recreated everything again and still could not get the units to pass traffic. It looks like my end and the other end setup the sessions and negotiate the transfer rate but then never pass any audio or video. After about 20 seconds of looking at a blank screen the Tandburg units say communication error and drop back to the main menu.
I opened a ticket Friday Aug 26th in the early AM for this problem. I am still waiting to hear anything back. If I do not hear back by 14:00 today I will forward the ticket number to a Fortinet engineer in my area and see if he has any information / solutions.
Management is getting frustrated with this issue and they also were not happy when the rates went up July 1st. We will be evaluating other vendors if this problem can not be resolved in a timely manor.
I' ll be sure to keep the forum updated on my progress. (Still optimistic?)
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did not use H323 protocol with the fortigate unit. But reading your post about this issue is interesting and i am curious to know would happen if this traffic was encapsulated in an ipsec tunnel.

Not applicable
Created on 08-31-2005 04:34 AM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sorry to say, I' m not sure about how it would work with an IPSEC tunnel. I' ll be happy if I can get a straight IP connection to the internet reliably. After the MR10 upgrade, I tested with mixed results. I don' t know wether to blame the other end or the firewall at this point. Some clarification on the release notes would be nice at this point. I am still waiting for that from the fortinet engineer. When I get the word that it at least SHOULD work, I' ll test a bit more.
Seems like I can pass traffic from a few Polycom test sites. But the one I have lots of trouble with is the one at stereo.polycom.com.
yet lobby.austin.polycom.com seems to fly every time. If anyone has the time to test, try this and let me know if you get similar results. The stereo one does connect but only sometimes. I usually get what looks like a connect with no audio/video.
Polycom issue or a Fortinet one?????[>:]
