Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

I2050 Softphone and VPN over PIX

Status
Not open for further replies.

Rambocious

IS-IT--Management
Apr 8, 2004
17
US
I have a Pix 520 firewall that we are running our Cisco VPN clients through. When on the internal network I can us the IP softphone with no problems. While on the VPN I can not get to the Softphone acces or even access the BCM start page. I can not even ping the BCM from the VPN but I can ping every server and workstation on the network.

Any ideas?
 
Probably need to allow the ports that the bcm uses for access, throught the pix, i dont remember the ports but will look them up unless someone here beats me to it :)
 
Signaling between the IP telephones and the Business Communications Manager uses Business Communications Manager port 7000. However, voice packets are exchanged using the default RTP ports 28000 through 28255 at the Business Communications Manager, and ports 51000 through 51200 at the IP telephones. If these ports are blocked by the firewall or NAT, you will experience one-way or no-way speech paths.

Marshall
 
You probably need to build a static route in the BCM to account for the VPN.
 
Login/Admin uses Windows DCOM and I haven't seen too many firewalls that allow that to pass without some moderate intervention.
 
Can you confirm the BCM is using the same gateway address as all the other machines.

Marshall
 
If the BCM is not configured to use a default gateway and assuming that your VPN server is your default gateway for all other clients on the network.
You must select Net Link Mgr in the BCM Unified Manager and click on the permanent wan connection tab.
To assign your default gateway enter the address in the Next Hop on Primary Link field.

If your VPN server is not also your default router:
You must build static routes on the BCM to re-route outgoing packets to remote subnets via the IP address of your VPN server.
 
Aragon

You hit it....Our BCM is not used in any way for networking so the default gateway was not set. The BCM is on the same subnet as myself so I would have never noticed the problem because I could always get to the Unified Manager.

thanks to all for the helpful tips.

See Ya,
Al
 
hey Marshal,

That is funny...the problem was that in the LAN section there is no place for a gateway so I had no clue.....

Again thanks for the help!!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top