Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

UDP traffic one with PIX VPN with a client side firewall

Status
Not open for further replies.

gregws

Programmer
Nov 27, 2002
5
US


We are experiencing one way UPD (re. SIP) traffic with a VPN client. The traffic coming from the PIX firewall is not reaching the client IF there is a client side firewall in the way. Outbound (from the VPN client works fine). It is confusing because one would think that encapsulation would allow the traffic to pass through. If we bypass the client side firewall everything works great. If has failed with three different (e.g. Linksys) firewalls.

Thanks.

 
HI.

The SIP protocol is sensitive to NAT and PAT, and requires some manipulation.
The problems at the client side can be for 2 reasons:
1) The client side firewall performs NAT or PAT, and does not translate the SIP traffic properly.
2) The client side firewall does not inspect SIP packets and does not open the required ports for return traffic for that reason.
But the problem could also be at the pix side (or both).

Please provide more details, and another explanation. I don't know if I understood your scenario.
What is the pix OS version?
The latest (ver 6.2x) fixes some bugs with SIP handling at the pix.

At the pix, you can get more info using syslog messages and debug commands, for example:

debug sip
terminal monitor

Read the SIP related RFC documents, it will help you.
And take a look here about the pix fixup command:

Bye
Yizhar Hurwitz
 
Ping works fine. If there is no client side firewall the application works beautifully. It does seem that the firewall is stopping inbound UDP or SIP traffic. I confuses me because, I would have guessed that the encapsulation of the VPN would 'hide' the packet type.

Greg
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top