<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UDP Conversations for VOIP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/udp-conversations-for-voip/m-p/37133#M27237</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The help desk did all the work on the answer, I just put it with my post for everyone!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Mar 2011 18:52:45 GMT</pubDate>
    <dc:creator>manuel2000</dc:creator>
    <dc:date>2011-03-09T18:52:45Z</dc:date>
    <item>
      <title>UDP Conversations for VOIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/udp-conversations-for-voip/m-p/37131#M27235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an outside VOIP server running H323.&amp;nbsp; The phones internally use a keep-alive mecahnism over UDP 5000 as a destination and varying source ports.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The server on the untrust side of the firewall will send the same keep-alives in response. This is known by some firewalls as a UDP conversation or sometimes is necessary in transparent mode.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The service drops connections if the packet is not returned by the server to the phone.&amp;nbsp; To the PA by default the service appears to initiate a connection from Untrust to Untrust as a response, though it should be part of the Trust (Phone) to Untrust (Server) communication as a response.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Cisco, Checkpoint and Juniper There are fixups for the protocols and an extension of for the timeout valuees for UDP that are necessary.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way for me to allow these UDP conversations prevalent in voice communication over IP? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Mar 2011 16:17:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/udp-conversations-for-voip/m-p/37131#M27235</guid>
      <dc:creator>manuel2000</dc:creator>
      <dc:date>2011-03-09T16:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: UDP Conversations for VOIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/udp-conversations-for-voip/m-p/37132#M27236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All;&amp;nbsp; It turns out that the reason the second communication was showing as initiated from the VOIP Server was due to the UDP default timeout being 30 seconds.&amp;nbsp; To find out if this is the case with your installation on the command line goto: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show session info &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UDP Timeout will show as 30 seconds by default. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you then use "Application Override" you will be able to adjust the TCP, UDP and other timeouts for the application, in my case the specific VOIP app. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also found it helpful that should the connections stay open that show session info told me that at 80% of the allowable number of sessions (in a PA500 this is 65000), the timers will be halfed, saving me the problem of sessions bogging down the system if too many are open.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This feature is important as something like a Syslog server that matched the application override would produce millions of open (and staying open) UDP connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, Pen Name Manuel OUT!.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Mar 2011 18:51:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/udp-conversations-for-voip/m-p/37132#M27236</guid>
      <dc:creator>manuel2000</dc:creator>
      <dc:date>2011-03-09T18:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: UDP Conversations for VOIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/udp-conversations-for-voip/m-p/37133#M27237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The help desk did all the work on the answer, I just put it with my post for everyone!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Mar 2011 18:52:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/udp-conversations-for-voip/m-p/37133#M27237</guid>
      <dc:creator>manuel2000</dc:creator>
      <dc:date>2011-03-09T18:52:45Z</dc:date>
    </item>
  </channel>
</rss>

