• ×
    Information
    Windows update impacting certain printer icons and names. Microsoft is working on a solution.
    Click here to learn more
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Windows update impacting certain printer icons and names. Microsoft is working on a solution.
    Click here to learn more
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
The HP Community is where owners of HP products, like you, volunteer to help each other find solutions.
HP Recommended

Hello! Is it possible to setup multipoint conference with both LAN and WAN(throught NAT) subscribers on VSX 7000?

 

We have few VSX 6000 stations in our LAN with private addresses, and one external station with public ip address.

When we configure VSX 7000 to work with NAT, it works with external station, but not with locals(black screen, no sound)

 

We need to set up VSX 7000 to make both internal and external calls, without reconfiguring it + make multipoint conferences.

 

Is it possible?

 

1 ACCEPTED SOLUTION

Accepted Solutions
HP Recommended

Wheb you have the 'NAT is h323' box unchecked (required to get through a non-h323 firewall) the VSX presents 2 IP addresses to the network. (the internal and external) The external IP address 'confuses' the other internal system and the call does not connect.

Making a call through the firewall works because the VSX is 'telling' the firewall what its NAT route is so farend traffic can find its way back.

 

Checking the box will allow internal calls because there is only 1 IP address to deal with.

 

With your current firewall config you will have to make that check box change for every call.

 

You did not specify which firewall you have but 'pete' is correct (next reply) the VBP will work well for you and is not very expensive.

 

View solution in original post

8 REPLIES 8
HP Recommended

It should be if you have set it up correctly. 

Does the VSX 7000 station in the lan with privat addresses?

Does the locals see it? 

 

For a multipoint guide for the  VSX 7000

http://extension.oregonstate.edu/internal/computing/sites/default/files/PolyCom_VSX_7000_Multipoint_... 

HP Recommended

Being able to call behind the firewall and through the firewall depends on the firewall itself. It depends on how the firewall does NAT.

 

Here’s how I explain the function:

 

If the NAT is 323 compatible is checked, In the HDX firewall settings, the HDX is putting the ‘real’ (internal) IP address at both layer 3 and layer 7 of the packet.

 

If it is unchecked, the unit puts the ‘real’ IP address in L3 and the WAN (external) IP in L7 of the packet.

 

'NAT is compatible' is extremely close, in real-world function, to having no NAT settings at all. When it is checked, the unit is depending on the firewall to intercept the packets & do the L3 NAT (change internal IP to external IP/vice-versa), as well as open the payload of the packet, determine if there is anything ‘to do’ (such as determine if it is an H245 packet and alter the IP address/port numbers contained therein) & do whatever is necessary.

When not checked, the codec has the simple thought process of: “the firewall here is dumb, so I have to put the WAN IP in the payload part so this call will work”

 

The layer 3 part of the packet, regardless of the NAT settings, is the same as it would not work otherwise.

 

So to get 'best of both worlds' the 'NAT is H323 compatible' needs to be checked. The rest depends on the firewall.

HP Recommended

2 Kendo: thnx, we have no problems working throught nat. I have uncheched  'NAT is H323 compatible' and said "no ip nat service h323" on cisco router.

 

the problem is when I configure polycom VSX 7000 to work throught nat I cannot connect to endstations on LAN(blank screen, no sound on our side, like here: http://support.polycom.com/global/documents/support/setup_maintenance/products/video/vsx_series_admi... on p.12-12)

 

we would like to talk with LAN and WAN endstations without reconfiguring VSX 7000 and make multipoint with both of them. I need to know for shure is it possible or not.

 



 

 

HP Recommended

We have no problems connecting in LAN when NAT is off.

HP Recommended

For this situation, I think I'd recommend a Polycom VBP E Series & put all your end points inside & let the VBP deal with external traffic sat side by side with the Cisco FW.

http://www.polycom.co.uk/products/telepresence_video/security_remote_access/index.html

Pete

HP Recommended

Wheb you have the 'NAT is h323' box unchecked (required to get through a non-h323 firewall) the VSX presents 2 IP addresses to the network. (the internal and external) The external IP address 'confuses' the other internal system and the call does not connect.

Making a call through the firewall works because the VSX is 'telling' the firewall what its NAT route is so farend traffic can find its way back.

 

Checking the box will allow internal calls because there is only 1 IP address to deal with.

 

With your current firewall config you will have to make that check box change for every call.

 

You did not specify which firewall you have but 'pete' is correct (next reply) the VBP will work well for you and is not very expensive.

 

HP Recommended

Hmm! Nice PDF Kendo.  That'll cut many of my tech support calls short (or sell loads of VBP(E)s:)LOL

HP Recommended

Sorry for long silence.

kendo, thank you for explanation! now I need the nat device to work as "h323 compatible"

the device is Cisco 7206VXR-G2,

ios is C7200P-ADVENTERPRISEK9-M, Version 15.0(1)M7.

 

as far as I understood by default cisco routers have h323 compatible nat, but because of ios bugs they dont work as expected, at least with polycoms.(http://otrs.xperteam.nl/otrs/public.pl?Action=PublicFAQZoom;ItemID=3)

 

so external calls dont work with default nat config, the only command I now to impact the nat h323 behavior is "no ip nat service h225" to make it h323 incompatible.

 

should I dig in the way of "voice service voip"?

I found this and will try when here will be no users.

 

2 petet: thnx, I hope we wont need to buy new devices, looking for other solution.

 

 

 


† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.