Download Print this page

Cisco ASA 5506-X Configuration Manual page 197

Cli
Hide thumbs Also See for ASA 5506-X:

Advertisement

Chapter 8
Inspection for Voice and Video Protocols
If the ASA needs to perform NAT on IP addresses in messages, it changes the checksum, the UUIE
length, and the TPKT, if it is included in the TCP packet with the H.225 message. If the TPKT is sent in
a separate TCP packet, the ASA proxy ACKs that TPKT and appends a new TPKT to the H.245 message
with the new length.
The ASA does not support TCP options in the Proxy ACK for the TPKT.
Note
Each UDP connection with a packet going through H.323 inspection is marked as an H.323 connection
and times out with the H.323 timeout as configured with the timeout command.
You can enable call setup between H.323 endpoints when the Gatekeeper is inside the network. The ASA
Note
includes options to open pinholes for calls based on the RegistrationRequest/RegistrationConfirm
(RRQ/RCF) messages. Because these RRQ/RCF messages are sent to and from the Gatekeeper, the
calling endpoint's IP address is unknown and the ASA opens a pinhole through source IP address/port
0/0. By default, this option is disabled. To enable call setup between H.323 endpoint, enter the
ras-rcf-pinholes enable command during parameter configuration mode while creating an H.323
Inspection policy map. See
H.239 Support in H.245 Messages
The ASA sits between two H.323 endpoints. When the two H.323 endpoints set up a telepresentation
session so that the endpoints can send and receive a data presentation, such as spreadsheet data, the ASA
ensure successful H.239 negotiation between the endpoints.
H.239 is a standard that provides the ability for H.300 series endpoints to open an additional video
channel in a single call. In a call, an endpoint (such as a video phone), sends a channel for video and a
channel for data presentation. The H.239 negotiation occurs on the H.245 channel.
The ASA opens pinholes for the additional media channel and the media control channel. The endpoints
use open logical channel message (OLC) to signal a new channel creation. The message extension is part
of H.245 version 13.
The decoding and encoding of the telepresentation session is enabled by default. H.239 encoding and
decoding is preformed by ASN.1 coder.
Limitations for H.323 Inspection
H.323 inspection is tested and supported for Cisco Unified Communications Manager (CUCM) 7.0. It is
not supported for CUCM 8.0 and higher. H.323 inspection might work with other releases and products.
The following are some of the known issues and limitations when using H.323 application inspection:
Configure H.323 Inspection Policy Map, page
Only static NAT is fully supported. Static PAT may not properly translate IP addresses embedded in
optional fields within H.323 messages. If you experience this kind of problem, do not use static PAT
with H.323.
Not supported with dynamic NAT or PAT.
Not supported with extended PAT.
Not supported with NAT between same-security-level interfaces.
Not supported with outside NAT.
8-6.
Cisco ASA Series Firewall CLI Configuration Guide
H.323 Inspection
8-5

Hide quick links:

Advertisement

loading