<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ALG for Facetime via NAT? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25937#M18915</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ALG? Dont you mean Appid?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Jan 2012 16:12:59 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-01-19T16:12:59Z</dc:date>
    <item>
      <title>ALG for Facetime via NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25936#M18914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We're running 4.0.5 and Facetime does not work as the packets coming from Apple's servers via the Internet are dropped. I noticed there was an ALG for H.323 in 4.1 but wasn't sure if that was related to Facetime or if there was anothe work around.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jan 2012 15:35:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25936#M18914</guid>
      <dc:creator>bjdraw</dc:creator>
      <dc:date>2012-01-19T15:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: ALG for Facetime via NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25937#M18915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ALG? Dont you mean Appid?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jan 2012 16:12:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25937#M18915</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-01-19T16:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: ALG for Facetime via NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25938#M18916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There has been an App-ID for facetime for some time and it works fine with NAT.&amp;nbsp; Facetime uses STUN to deal with NAT so it should be seamless anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jan 2012 06:45:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25938#M18916</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2012-01-20T06:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: ALG for Facetime via NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25939#M18917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;There still is according to: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://apps.paloaltonetworks.com/applipedia//"&gt;http://apps.paloaltonetworks.com/applipedia//&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like it depends on "ichat-av, sip, ssl, stun" which means that you need to allow those aswell (I think you will get an error or warning otherwise if you try to commit with not all dependencies set).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jan 2012 20:00:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25939#M18917</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-01-20T20:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: ALG for Facetime via NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25940#M18918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;mikand wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ALG? Dont you mean Appid?&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean an Application Layer Gateway which isn't exactly equal to an App-ID, is it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.paloaltonetworks.com/researchcenter/2010/08/whats-appening-with-apple-facetime/"&gt;http://www.paloaltonetworks.com/researchcenter/2010/08/whats-appening-with-apple-facetime/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did see the PAN AppID for Facetime, was just trying to determine if allowing it was as simple as a rule allowing that application from the Internet to my LAN, or perhaps the other way around since the traffic is actually initiated from my LAN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 13:55:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25940#M18918</guid>
      <dc:creator>bjdraw</dc:creator>
      <dc:date>2012-01-23T13:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: ALG for Facetime via NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25941#M18919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;kbrazil wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There has been an App-ID for facetime for some time and it works fine with NAT.&amp;nbsp; Facetime uses STUN to deal with NAT so it should be seamless anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a policy from zone Internet to zone Internet from Any IP to my Dynamic NAT IP which allows "facetime, aim-base, web-browsing, ssl, stun, sip, ichat-av" and tested unsuccesfully. The outbond traffic is correctly identified, but the traffic comging back from Apple's servers is allowed, but identified as "insufficient-data."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume allowing the AppID alone isn't enough to make it work with a Dynamic NAT? (We're NAT'ing all our clients out the same public IP)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 15:31:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25941#M18919</guid>
      <dc:creator>bjdraw</dc:creator>
      <dc:date>2012-01-23T15:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: ALG for Facetime via NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25942#M18920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Scratch this entire thread, NO inbound rules are required to make Facetime work on the PAN firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason mine wasn't working out of the box was becaue I had an explicit deny for SIP traffic destined from my network to the Internet. And since the Facetime AppID is dependant on SIP, it failed without logging. Interestingly with the rule disalbed, Facetime is working but sip traffic is still not logged. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 17:09:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25942#M18920</guid>
      <dc:creator>bjdraw</dc:creator>
      <dc:date>2012-01-23T17:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: ALG for Facetime via NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25943#M18921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Didnt you get any warning during commit that you had colliding rules?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And which PANOS is it you were using?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 19:41:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25943#M18921</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-01-23T19:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: ALG for Facetime via NAT?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25944#M18922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was running 4.0.8 (can't remember the exact 4.0 release) and I didn't get a warrning because my policy for traffic destined for the internet from the LAN was 'any' and I just added exclusions to block SIP and SMTP. If I had put an explicit rule allowing Facetime from the LAN to the Internet then I would've gotten an error.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2012 13:22:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alg-for-facetime-via-nat/m-p/25944#M18922</guid>
      <dc:creator>bjdraw</dc:creator>
      <dc:date>2012-01-25T13:22:13Z</dc:date>
    </item>
  </channel>
</rss>

