Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

iSight und PIX515 with

Status
Not open for further replies.

lsicforum

IS-IT--Management
May 20, 2003
5
0
0
DE
Hello,

I am trying to connect two firewire cameras iSight at Apple G4s. One Apple computer is in Germany behind the Firewall second is in Amerika. The connection works if I use the germany's computer outside the firewall. So the problem is in the pix. I red on the Apple site, that follow ports have to be open:

UDP 5060
UDP range 16384-16403

I opened these ports on inside and outside interfaces, but connection fails. The computer in Amerika can see that my computer in Germany online is, but i can't see the Amerika's computer online.

The PIX (ver. 6.1(3)) conf (fragment):

access-list fromoutside permit udp any host 2xx.xxx.xxx.196 eq 5060
access-list fromoutside permit udp any host 2xx.xxx.xxx.196 range 16384 16403

access-list frominside permit udp any any eq 5060
acess-list fromside permit udp any any range 16384 16403

global (outside) 1 2xx.xxx.xxx.196

access-group fromoutside in interface outside
access-group frominside in interface inside

Why doesn't it work?

Can help me anyone?

Thank you in Advance!
 
HI.

You will probably also need a "static" command to map an unused registered public ip address to the internal machine.

You can consider upgrading your pix device to latest version, because some of the fixes relate to SIP and other multimedia protocols support.
Contact your Cisco dealer for that.



Yizhar Hurwitz
 
Hi yizhar,

"You will probably also need a "static" command to map an unused registered public ip address to the internal machine"

Why? As you have understood we use NAT. I think it is enough for the connection. Of cause i can try what you meane. But what is if we could have just one registered public ip address?

I think it has to work with NAT. Or?

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top