Educause Security Discussion mailing list archives

Re: Palo Alto Firewall and Sorenson VP 200 (Video Phones)


From: Peter Setlak <psetlak () COLGATE EDU>
Date: Fri, 17 May 2013 15:28:04 -0400

Harry,

We use PA 5050's on our edge. We do not use Sorenson video phones. However,
we did experience an issue with Jumbo Frames with a device on our network.
Are the video phones wired? Are they on 1Gb or 100Mb ports? Try 100Mb and
see if that fixes the issue. There are also settings on the FW to allow
jumbo frames (which we did not adjust as we're hesitant to change the
entire edge for one device). Otherwise, are the video phones using GRE or
another IP protocol? I often get stuck when I'm trying work with IP (not
tcp or udp) protocols. The PA sees these as applications, not ports (or
services). ICMP is also an application in PA's world... If the vid phones
rely on pings to keepalive, hat may be the culprit. Hope this helps.

- Peter


On Fri, May 17, 2013 at 2:57 PM, Harry Zahlis <
harry.zahlis () fresnocitycollege edu> wrote:

 Our District just purchased and implemented a new Palo Alto Networks
firewall.  We have run across an issue which has stumped a lot of people.*
***

** **

Our deaf faculty and students use a device provided by Sorenson (Sorenson
ntouch VP-200) for telecommunication.  At first we opened the specific
ports required by the Sorenson devices but we could not place phone calls.
We opened all ports, TCP and UDP in both directions (any-any) and we still
cannot get the devices to work properly.  Each of the devices has a static
address on the inside and outside.****

** **

My questions is does anyone have a Palo Alto Networks firewall and utilize
Sorenson video phone devices on your campus?  I would really be interested
to know how you got these suckers to work.****

** **

Thanks in advance for any assistance.****

** **

Harry****

** **

Harry Zahlis****

Network Coordinator****

Fresno City College****




-- 
Thank you,

Peter J. Setlak
Managing Director, Networks, Systems & Operations
Network Security Analyst, GSEC, GLEG
Colgate University
---
psetlak () colgate edu
(315) 228-7151
Case-Geyer 180H (NSO Suite)
skype: petersetlak

Think *Green!* Please consider the environment before printing this email.

*Engage with Colgate University:
*
News blog <http://blogs.colgate.edu/>,
Twitter<https://twitter.com/#%21/colgateuniv>
, Facebook <https://www.facebook.com/colgateuniversity>,
Google+<https://plus.google.com/u/0/b/113333907606560373469/>
, Delicious <http://www.delicious.com/colgatenewsmakers>,
YouTube<http://www.youtube.com/cuatchannel13>
, Flickr <http://www.flickr.com/photos/colgateuniversity/>,
Pinterest<http://pinterest.com/colgateuniv/>
, LinkedIn <http://www.linkedin.com/company/colgate-university/>

Current thread: