Educause Security Discussion mailing list archives

Re: iChat and the PIX


From: Joe Marshall <JMarshall () FREDERICK EDU>
Date: Tue, 14 Dec 2004 11:23:52 -0500

We followed Apple's document on getting iChat to work through a firewall
with NAT.  Granted, we do not have a PIX, but the ports are all
explained in the link below.  There are a lot more than just port
5060...

http://docs.info.apple.com/article.html?artnum=93208




Joe Marshall
Director of Network Services & IT Security
Frederick Community College
7932 Opossumtown Pike
Frederick, Maryland 21702
301.624.2824 phone
301.624.2898 fax


sauvignec () WINTHROP EDU 12/14/04 11:08AM >>>
If your campus is using a Cisco PIX, can you please read this and see
if
you have any advice? Our problem has been escalated by a parent to our

President's office...

We have a problem with a student not being able to use iChat from our
campus network. We have run numerous tests from public and private IP's

through our Cisco PIX and we have run numerous tests from other
networks
that don't go through the PIX and it seems we have narrowed down a
problem that our NAT and PAT users cannot use iChat through our PIX if

talking to another user off campus that also has a private IP address.


We have tried "fixup protocol sip 5060" on and off and still no
success.

Does anybody have any experience getting iChat to work correctly
through
a PIX?

Thanks in advance,

================================
Craig M. Sauvigne
System Administrator
Winthrop University
Rock Hill, SC 29733
sauvignec () winthrop edu

**********
Participation and subscription information for this EDUCAUSE Discussion
Group discussion list can be found at http://www.educause.edu/groups/ .



**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/groups/.

Current thread: