<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN with Polycom RPAD (Real Presence) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-with-polycom-rpad-real-presence/m-p/2519#M1875</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is your end device Call server/PBX is NAT aware..? Is there a predict session available&amp;nbsp; from the signaling session...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest you to enable packet capture for ingress and egress on the PAN firewall just to see, the Layer-7 Payload and how it modified by PAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find below few related discussions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/21721"&gt;nat&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/23792"&gt;Polycom Real Presence issue&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Jan 2014 01:06:30 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-01-23T01:06:30Z</dc:date>
    <item>
      <title>PAN with Polycom RPAD (Real Presence)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-with-polycom-rpad-real-presence/m-p/2518#M1874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok. So, I'm running the 5.0.10 PAN. We are in the middle of a Polycom installation. Internal traffic within the polycom system is working fine (since no FW is in place). The problem is of course the outside users. We are using NAT for external stuff. I created a single Inbound rule (Untrust-&amp;gt;trust) to the RPAD server. No Applications selected. Instead I specified all the port numbers as custom services and attached them to the rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When a user tries to connect, the call is connected and the user is registered. However, no media/content would go through. As a side note, SIP works external, but not H.323.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Frank - West Chester University&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 00:37:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-with-polycom-rpad-real-presence/m-p/2518#M1874</guid>
      <dc:creator>FrankPiscitello-WCU</dc:creator>
      <dc:date>2014-01-23T00:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: PAN with Polycom RPAD (Real Presence)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-with-polycom-rpad-real-presence/m-p/2519#M1875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is your end device Call server/PBX is NAT aware..? Is there a predict session available&amp;nbsp; from the signaling session...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest you to enable packet capture for ingress and egress on the PAN firewall just to see, the Layer-7 Payload and how it modified by PAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find below few related discussions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/21721"&gt;nat&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/23792"&gt;Polycom Real Presence issue&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 01:06:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-with-polycom-rpad-real-presence/m-p/2519#M1875</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-23T01:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: PAN with Polycom RPAD (Real Presence)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-with-polycom-rpad-real-presence/m-p/2520#M1876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, we got it working. Application Override is where we had to go. We setup an application "Polycom" and put ALL the tcp/udp ports required to connect to the RPAD system. Then I put 4 application over-ride policies in place. 2 for Outbound from the RPAD (TCP/UDP) and 2 for Inbound (TCP/UDP) both pointing to the "Polycom" application Object I made earlier.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I then had connections made and verified through the traffic log that the inbound/outbound traffic was being IDed as "Polycom" not H323, SIP, etc... Dials were made and media was connected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 16:46:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-with-polycom-rpad-real-presence/m-p/2520#M1876</guid>
      <dc:creator>FrankPiscitello-WCU</dc:creator>
      <dc:date>2014-01-23T16:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: PAN with Polycom RPAD (Real Presence)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-with-polycom-rpad-real-presence/m-p/2521#M1877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your update here. If &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;app&lt;/SPAN&gt;-override solved the problem here, it means the PAN&amp;nbsp; FW was changing the payload information from the layer-7 which was not acceptable for your end server. Hence, your end server/call manager/PBX is a NAT aware box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This type of situation could handle in 2 ways:&lt;/P&gt;&lt;P&gt;a. Make the end system, NAT aware and create an application-override in PAN firewall for signaling and media traffic.&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;b. Make the server as a legacy device (no NAT aware) and do the pinholing at the PAN firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 17:44:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-with-polycom-rpad-real-presence/m-p/2521#M1877</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-23T17:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: PAN with Polycom RPAD (Real Presence)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-with-polycom-rpad-real-presence/m-p/2522#M1878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The real question is, why would PAN be modified the payload of layer-7 during the App-ID phase?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jan 2014 20:13:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-with-polycom-rpad-real-presence/m-p/2522#M1878</guid>
      <dc:creator>FrankPiscitello-WCU</dc:creator>
      <dc:date>2014-01-24T20:13:14Z</dc:date>
    </item>
  </channel>
</rss>

