<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you allow Polycom (nat) via Palo Alto FW? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39340#M28874</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We only have Tandberg but they are all standards based an interopable, so the Polycom "should" act the same&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Apr 2010 19:07:57 GMT</pubDate>
    <dc:creator>john.langford@aplp.net</dc:creator>
    <dc:date>2010-04-13T19:07:57Z</dc:date>
    <item>
      <title>How do you allow Polycom (nat) via Palo Alto FW?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39336#M28870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm having issue with configuring NATing for my Polycom unit sitting behind the firewall to work.&amp;nbsp; I have allowed all the required apps for Polycom to allow outgoing and incoming.&amp;nbsp; My issue is when I can only call out to another party with public IP but can't receive call from outside the network.&amp;nbsp; I have both NAT rule for both ways in place.&amp;nbsp; Any one have experience with similar setup? &lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tevin.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Apr 2010 21:28:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39336#M28870</guid>
      <dc:creator>akatev</dc:creator>
      <dc:date>2010-04-12T21:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39337#M28871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you running PAN-OS version 3.1.0 as 3.1.0 has enhancements for ALG in a NAT'ed environment?&amp;nbsp; Please check out the release notes for version 3.1.0 and give 3.1.0 a try.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Apr 2010 21:33:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39337#M28871</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2010-04-12T21:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39338#M28872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;I also had a problem with a Tandberg NAT.&lt;SPAN class="480374818-13042010"&gt; I&amp;nbsp; am running 3.1.&lt;/SPAN&gt; The trick was to change the outbound NAT for the Tandberg&amp;nbsp; from dynamic ip and port to dynamic ip. I also had to allow the following&amp;nbsp; applications both inbound and outbound - h.245, h.323, rtcp and rtp.&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 18:52:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39338#M28872</guid>
      <dc:creator>john.langford@aplp.net</dc:creator>
      <dc:date>2010-04-13T18:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39339#M28873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;P class="MsoPlainText"&gt;So setting the NAT type to dynamic IP solved your problem for both Polycom &amp;amp; Tanberg?&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 19:04:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39339#M28873</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2010-04-13T19:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39340#M28874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We only have Tandberg but they are all standards based an interopable, so the Polycom "should" act the same&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 19:07:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39340#M28874</guid>
      <dc:creator>john.langford@aplp.net</dc:creator>
      <dc:date>2010-04-13T19:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39341#M28875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I won't have a down time window until the end of this month to upgrade to 3.1.&amp;nbsp; So will have to let you the status later.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Apr 2010 22:20:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39341#M28875</guid>
      <dc:creator>akatev</dc:creator>
      <dc:date>2010-04-22T22:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39342#M28876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So our PA is on version 3.1.3-h1 now and still having issue with NATing for Polycom.&amp;nbsp; We were close on being able to get our PA to make and receive call to the external network.&amp;nbsp; However, when calling internally, our NATed Polycom called the internal system with its public IP instead eventhough it was an internal IP call.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2010 03:33:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39342#M28876</guid>
      <dc:creator>akatev</dc:creator>
      <dc:date>2010-08-04T03:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39343#M28877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the same issue.&lt;/P&gt;&lt;P&gt;Our PAN runs PANOS 3.1.5 and protects a Tandberg MCU4250.&lt;/P&gt;&lt;P&gt;MCU has a private address (192.168.x.y) and I can ping it from Internet through the PAN with its public address (195.101.x.y).&lt;/P&gt;&lt;P&gt;But when I try to establish a videoconference, it fail.&lt;/P&gt;&lt;P&gt;During the process, the first TCP session connects correctly, client and MCU discuss and negotiate dynamic parameters. PAN correctly detects the h323 application.&lt;/P&gt;&lt;P&gt;But in the second (dynamic) TCP connection, I notice that the client try to establish a connection to the private address. The PAN does not modify the h323 payload.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The filter rule accepts following applications (from untrust to trust) from any to 195.101.x.y : h.245 h.323 rtcp rtp icmp rsvp&lt;/P&gt;&lt;P&gt;The NAT rule&amp;nbsp; simply "nats" statically (from untrust to trust) any-&amp;gt;195.101.x.y to any-&amp;gt;192.168.x.y.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did I miss a parameter or a trick ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Oct 2010 16:54:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39343#M28877</guid>
      <dc:creator>LCMember1210</dc:creator>
      <dc:date>2010-10-05T16:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39344#M28878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try creating your NAT rule by making your source and destination zone from "untrust" to "untrust".&lt;/P&gt;&lt;P&gt;Then create an security policy from untrust to trust, any any any -any application-, any, Action Deny policy.&amp;nbsp; This will log all your denied traffic and possibly from there we can indentify what application you may be missing, and add that to your rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Oct 2010 22:46:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39344#M28878</guid>
      <dc:creator>odaos</dc:creator>
      <dc:date>2010-10-07T22:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39345#M28879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It didn't work...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried to change the NAT rule to :&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Original packet :&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;any to trust, 192.168.* to any,&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Translated packet :&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;195.101.* (static-ip, bidirectional) to none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The payload of the h323 packet wasn't change...&lt;/P&gt;&lt;P&gt;For the second dynamic connection, the client on the Internet, tries to connect to the private address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For NATing H323 flow, is there a "priority" in the NAT rules ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 21:26:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39345#M28879</guid>
      <dc:creator>LCMember1210</dc:creator>
      <dc:date>2010-10-08T21:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39346#M28880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did anyone figure out the resolution to this. We are having the same issue connecting our external VSX to a nat'ed RMX 2000 bridge. Subsquent packets from the VSX try to connect to the private address and not the nat'ed address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Nov 2010 21:50:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39346#M28880</guid>
      <dc:creator>owenusa</dc:creator>
      <dc:date>2010-11-22T21:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39347#M28881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the Polycom using H.323 protocol?&amp;nbsp; If so, we should support static NAT today.&amp;nbsp; You might want to work with Support to see if there is a configuration or content issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;H.323 is not supported with Port Address Translation (PAT) today, but will be in a future release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Nov 2010 22:47:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39347#M28881</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2010-11-22T22:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39348#M28882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone have luck with setting this up yet?&amp;nbsp; I'm struggling to have this to work after our deloyment with PA firewall.&amp;nbsp; It was working fine before with the SSG.&amp;nbsp; I have to literally uncheck the box for 'NAT is H.323 compatible' on my Polycom to be able to receive call from the public IP.&amp;nbsp; When i do that, incoming call from the public works but all the internal call is broken.&amp;nbsp; So i have to flip this option back and forth.&amp;nbsp; It's a real pain. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Dec 2011 19:25:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39348#M28882</guid>
      <dc:creator>akatev</dc:creator>
      <dc:date>2011-12-05T19:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39349#M28883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you checked with Polycom to see why internal calls didn't work with the NAT option unchecked?&amp;nbsp; For internal calls, there is no NAT'ing so the option should not have affected internal calls.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Dec 2011 22:32:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39349#M28883</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2011-12-05T22:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39350#M28884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also, the latest PAN-OS version (4.1) has NAT enhancements for H.323 traffic (specifically Polycom).&amp;nbsp; You might test that code in your lab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Dec 2011 23:15:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39350#M28884</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-12-05T23:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: How do you allow Polycom (nat) via Palo Alto FW?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39351#M28885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can answer this question, because I used to work at Polycom and this was a common question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The HDX (or any Polycom product) is limited to NAT ON or NAT OFF.&amp;nbsp; There is NO intelligence in the box to assume "Oh, this call is internal, but I see that NAT is enabled, let me just use my internal IP"&amp;nbsp; ON means NAT is ON, whether internal or external address is being used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To get around this, you NEED to put your Polycom, into a DMZ Zone off the FW, allow it to have a public IP address.&lt;/P&gt;&lt;P&gt;Your FW rules would allow from Internet to DMZ, or Public IP to public IP&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your internal users would now use the Public IP of the Polycom codec.&amp;nbsp; No more calling via the internal IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is just how it works.... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 02:56:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-allow-polycom-nat-via-palo-alto-fw/m-p/39351#M28885</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2012-12-12T02:56:50Z</dc:date>
    </item>
  </channel>
</rss>

