View Full Version : VSX7000, IP, Black screen
abakri
01-08-2007, 07:55 AM
Helo everybody
Im tryin to make an IP call from a VSX7000, the connection is established but only partially, instead of the far side i see a black screen and hear no audio, however the other side sees and hears us well.
Im behind a PIX firewall, with ports open, can u please suggest a solution ?
I have a copy of the PIX configuration, if it can help any of you help us solve this issue, please say so, and i will provide it.
Thanks all in advance
Ashraf
Slimey
01-09-2007, 09:22 PM
post it here or at http://pastebin.ca then link us to it. dont forget to remove things like passwords, externaly accessable ip addresses you do not want shown, etc.
Slimey
01-10-2007, 12:02 AM
also take a look at this from polycom
Cisco PIX “fixup protocol h323 h225 1720” on only:
H.323 video endpoints will have connection and video incompatibilities.
Cisco currently does not support AES or H.239 in the “fixup protocol h323
h225 1720”
Cisco PIX “fixup protocol h323 h225 1720” on with following ports open:
Polycom V500 and VSX systems will work properly; however, with Cisco PIX
setup in this manner you will be required to disable AES to connect endpoints
through the Firewall. Also, H.239 will not work properly in this configuration.
Cisco currently does not support AES or H.239 in the “fixup protocol h323
h225 1720”
In an H.323 multipoint conference using a VSX system MCU located behind a
Cisco PIX 6.3.4 and 7.0.1 firewall among systems with H.239 enabled, the V500
and VSX systems outside of the firewall may not receive video when other
sites connect. To avoid this, disable H.239 on all sites.
V500 and VSX systems are unable to control the far end camera when it is
located behind a Cisco PIX 6.3.4 and 7.0.1 firewall.
Configure Conduits or Access List Assignments for the following ports:
TCP 1720
TCP 3230 - 3235
TCP 3603
TCP 389
UDP 3230-3253
UDP 1718-1719
Cisco PIX “fixup protocol h323 h225 1720” off with following ports open:
Polycom V500 and VSX systems and all features will work properly.
1. To turn off the “fixup protocol h323 h225 1720” feature, use the following
command:
no fixup protocol h323 h225 1720
2. Configure Conduits or Access List Assignments for the following ports:
For outbound interface
TCP 1720
TCP 3230 - 3235
TCP 3603
TCP 389
UDP 3230-3253
UDP 1718-1719
For inside interface, open all IP per video device.
Use the following command to configure conduits or access points:
conduit permit tcp host 255.255.255.255 eq port any
Where 255.255.255.255 is the external IP address of the SME Appliance.
If an endpoint receives inbound video calls from outside the LAN, use the
following command to create a static connection for each internal endpoint:
static (inside,outside) xxx.xxx.xxx.xxx iii.iii.iii.iii netmask
vBulletin® v3.7.2, Copyright ©2000-2008, Jelsoft Enterprises Ltd.