Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Problems with Video Conferencing

Problem We get connection, a call is established, but no audio or video passes. Same result with call initiated by either end. I' ve tried setting up what is in the Fortigate Tech Note " H.323 Support" Direct Call Scenario 3: NAT/Route mode, NAT enabled and virtual IP required Pieces and parts FG 400 FW 2.80, build456 Polycom iPower 9800 Current Firewall Policies Int > Ext: Source – Internal-iPower, Destination – External-All, Always, H323, Accept, NAT Dynamic Pool Ext > Int: Source – External-All, Destination – Internal-iPower(Virtual IP), Always, H323, Accept, No NAT What am I missing, or doing wrong? Do I need to create a custom “Video Conferencing” service or a group that includes more ports? Also how does H.264 differ from H.323, with regards to the firewall? Thanks In the dark Mark
15 REPLIES 15
Not applicable

Hi Mark, Sorry for the late response! I have been struggling with setting up the same situation as you. I had some success with 2.8MR6 but no luck with any other builds. What I have tried to pry out of Fortinet is: 1.) What build should I use? 2.) Are there known problems with Tanberg or Polycom units? 3.) How can I troubleshoot / Diagnose the problem? If I hear anything I' ll post back here.
Not applicable

Staylor, Thanks. I finally found the blurb about H.323 not being completely supported in the MR10 release notes. Why would anyone want to read them? I and considering back revving to MR6, but have a couple questions. If I do back-rev, will my saved (full system) settings from MR10 reload into MR6? Is there any important functionality I will lose? Currently I have SPAM filtering disabled, but I am using AV. One other thing to pry out of Fortinet: 4.) Will H.323 be properly fixed in any forthcoming versions, and if so, when? Thanks again. Mark
Not applicable

When you drop back to a prior MR it will default your firewall. I backed up both all configs and just the system config. So far I have only had luck restoring just the system config, not all at once in the large file. Be careful dropping down an MR. Hopefully next week I can find some time and get some answers to our questions from our vendor, fortinet or a fortinet (employee) engineer I know. -Scott
skyhigh
New Contributor

FG 400 FW 2.80, build456 Polycom iPower 9800
It should work as long as you are not using the FastStart feature (added after MR10) or multiple Gatekeepers. Please open a support ticket if you have not already.
Fortinet Technical Support
Fortinet Technical Support
Not applicable

Hum, I have two tandberg units and a polycom unit. I' ll have to run some more tests tomorrow and then maybe open a ticket. Thanks! -Scott
Not applicable

This really worries me. MR10 claims to fix the H.323 issues. At least the one of not passing H.323. By what you' re saying, it' s not resolved. Have you done any follow up tests?
Not applicable

I did get to do some follow up tests. I blow out the VIP' s, rules and everything. I then recreated everything again and still could not get the units to pass traffic. It looks like my end and the other end setup the sessions and negotiate the transfer rate but then never pass any audio or video. After about 20 seconds of looking at a blank screen the Tandburg units say communication error and drop back to the main menu. I opened a ticket Friday Aug 26th in the early AM for this problem. I am still waiting to hear anything back. If I do not hear back by 14:00 today I will forward the ticket number to a Fortinet engineer in my area and see if he has any information / solutions. Management is getting frustrated with this issue and they also were not happy when the rates went up July 1st. We will be evaluating other vendors if this problem can not be resolved in a timely manor. I' ll be sure to keep the forum updated on my progress. (Still optimistic?)
Not applicable

I did not use H323 protocol with the fortigate unit. But reading your post about this issue is interesting and i am curious to know would happen if this traffic was encapsulated in an ipsec tunnel.
Not applicable

Sorry to say, I' m not sure about how it would work with an IPSEC tunnel. I' ll be happy if I can get a straight IP connection to the internet reliably. After the MR10 upgrade, I tested with mixed results. I don' t know wether to blame the other end or the firewall at this point. Some clarification on the release notes would be nice at this point. I am still waiting for that from the fortinet engineer. When I get the word that it at least SHOULD work, I' ll test a bit more. Seems like I can pass traffic from a few Polycom test sites. But the one I have lots of trouble with is the one at stereo.polycom.com. yet lobby.austin.polycom.com seems to fly every time. If anyone has the time to test, try this and let me know if you get similar results. The stereo one does connect but only sometimes. I usually get what looks like a connect with no audio/video. Polycom issue or a Fortinet one?????[>:]
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors