| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| I am seeing the following blocked traffic when trying vdeo conferencing between two site. Both are behind Checkpoint NGX HFA_02 running on Nokia IP 350's with IPSO 4.0. Any ideas what I can configure to allow this traffic? Number: 1376589 Date: 13Mar2006 Time: 13:45:48 Product: VPN-1 Pro/Express Interface: eth2c0 Origin: nbfw1 (142.166.5.58) Type: Log Action: Drop Protocol: tcp Service: H323_any (1720) Source: Saskatoon_Video (10.192.109.234) Destination: NB_Video (10.88.132.242) Source Port: Napster_directory_5555 (5555) Information: H.323 reason: Malformed H.225 message |
| |||
| Due to numerous other small errors on that particular Nokia box, I am replacing it with a SPLAT platform this weekend and then rebuilding the Nokia from scratch. If the problem persists I'll look at the hot fix, although the video is not being blocked by an identical Nokia gateway at the other end. |
| |||
| After numerous suggestions from Nokia, Checkpoint and users goups, I was not able to determine why the H323 packets were being dropped by only one of our firewalls. But, I was able to by-pass the problem by enabling wire mode on the VPN connection between the two sites internal ports. Video conferencing is now working. |
![]() |
| Thread Tools | |
| Display Modes | |
| |