- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-07-2012 08:48 AM
Hello PAN,
It seems to me that in order to have skype working correctly - particually with multi-site PA's with Site2Site VPN tunnels in between - it is nessesarely to enable both unknown-tcp & unknown-udp.
At least - all our connection problems / delivery delays seems to go away whit the above allowed.
But obviously - allowing "unknown" traffic thru your firewall is not the most obvious solution......
A more soft solution could be if it's possible to define a private application/service where:
if client is connected to skype with src.port = x
then
allow unknown-tcp and unknown-udp where src.port = x
Does anyone know if this is possible somehow
Thanks
Jørgen
06-07-2012 10:51 AM
Hello Jørgen,
There is not currently a way to apply a security policy based on source port.
Please ensure you are running the latest application and content release as we are continually modifying the applications. In our latest release(311) the skype-probe application has been modified so updating may resolve your issue.
If you continue to see skype identified as unknown-udp and unknown-tcp on the latest release, please gather packet captures of the traffic and open a support case so we may address the problem in a future application and content release.
- Stefan
06-08-2012 04:26 PM
Stefan,
I just confirmed that we are on 311-1412 and we're experiencing the same problem. I have some logs and a pcap that I'll open a case with. Although in my traffic analysis I noted that the unknown-tcp source ports did vary from the allowed skype and skype-probe packets. Specifically this is causing an interruption and non-delivery of chat messages in our case. The chat message time stamp will be replaced by "pending" when this occurs.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!