Blizzard New Game Overwatch PA not allowing voice traffic through, Even with custom service ports.

Reply
Highlighted
L1 Bithead

Blizzard New Game Overwatch PA not allowing voice traffic through, Even with custom service ports.

It seems that I can not seem to get the voice chat in Blizzards over watch to work through a PA. 

So as a test i put TCP ports 1119, 3724, 6113, 80, and udp 26503-36503 and 3724 forward through allowing any app, to the PC running the game.  Still didn't make  a differance. Not sure if anyone has a PA setup with users playing games behind it or not, just wondering if anyone else has run into this issue. 

Cheers, 

Highlighted
L4 Transporter

Re: Blizzard New Game Overwatch PA not allowing voice traffic through, Even with custom service port

Hi,

 

You can always request a signature be made for this application:

 

https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Request-a-new-App-ID/ta-p/60834

 

In the mean time, try creating a temporary 'allow all' rule for your source IP and play the game to see what ports, urls & applications hit this rule. Then create a new rule based on what you discover.

 

Make sure you log the rule and have a url filtering profile attached set to alert.

 

hope this helps,

Ben

Highlighted
L1 Bithead

Re: Blizzard New Game Overwatch PA not allowing voice traffic through, Even with custom service port

Yeah so this is the odd thing, i have put in an wide open rule.  I have allowed all through and set the application default to any, and it still seems to clip on the outside. It seems very odd to me. 

I have requested the application into the new app id allready. 

 

Highlighted
L7 Applicator

Re: Blizzard New Game Overwatch PA not allowing voice traffic through, Even with custom service port

some voip implementations could be flak. is the voice chat being identified as something specific? you may need to disable the ALG on the application level

It's also possible that without a proper signature (while it is being created) you need to set static bi-directional NAT and allow some inbound ports to your IP

reaper - PANgurus.com
I drink and I know things
Highlighted
L1 Bithead

Re: Blizzard New Game Overwatch PA not allowing voice traffic through, Even with custom service port

Yeah so here is the crazy thing, i did a bi-directional NAT and and opened the firewall wide up (not too worried it's a home device use for testing before putting in production) and it still clipped the voice data on it.  I run the PC direct of the ISP no problem. Put the PA in wireline and same thing. It's super odd. I would have thought a bi-direction with wide open rules would work. Also made sure it wasn't application default but application any. 

Highlighted
L7 Applicator

Re: Blizzard New Game Overwatch PA not allowing voice traffic through, Even with custom service port

Sounds like you are hitting one of the ALG setups probably a VOIP one.  What do the logs say for the permitted traffic? This might help see what needs to be turned off or put in for override.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
Highlighted
L1 Bithead

Re: Blizzard New Game Overwatch PA not allowing voice traffic through, Even with custom service port

Disabling ALG made it work for me.

 

Highlighted
L4 Transporter

Re: Blizzard New Game Overwatch PA not allowing voice traffic through, Even with custom service port

@erikda  Have you open a case with TAC?   We have a case with TAC now to have them look into why in game chat is not working.   I would suggest to open a case with TAC from your end as well,  PAN will get this issue resolve.

 

 

 

 

Highlighted
L4 Transporter

Re: Blizzard New Game Overwatch PA not allowing voice traffic through, Even with custom service port

We had a troubleshoot session with TAC.  The workaround is setup an application override for traffic using UDP port 6250.  

 

https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-...

 

We are requesting an overwatch appid.  No ETA yet.  stay tune.

 

 

Highlighted
L1 Bithead

Re: Blizzard New Game Overwatch PA not allowing voice traffic through, Even with custom service port

Again, for me the solution was to disable ALG for application sip.

Voice now works in Overwatch, and Playerunknown's battlegrounds.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!