Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

polycom behind the asa.

Hi. i try to configure an static pat to get access to a polycom service.

Im trying to use a police nat but it doesnt work.

---

object-group service LIFESIZE-UDP udp

port-object range 60000 64900

port-object eq sip

object-group service LIFESIZE-TCP tcp

port-object eq h323

port-object range 60000 64999

port-object eq www

object-group service POLYCOM-TCP tcp

port-object eq h323

port-object range 3230 3270

object-group service POLYCOM-UDP udp

port-object range 3230 3253

access-list VIDEOCONFNATPORTS extended permit tcp host 10.1.1.7 object-group LIFESIZE-TCP interface outside object-group LIFESIZE-TCP

access-list VIDEOCONFNATPORTS extended permit udp host 10.1.1.7 object-group LIFESIZE-UDP interface outside object-group LIFESIZE-UDP

access-list VIDEOCONFNATPORTS extended permit tcp host 10.1.1.7 object-group POLYCOM-TCP interface outside object-group POLYCOM-TCP

access-list VIDEOCONFNATPORTS extended permit udp host 10.1.1.7 object-group POLYCOM-UDP interface outside object-group POLYCOM-UDP access-list VIDEOCONFNATPORTS extended permit tcp host 10.1.1.7 object-group LIFESIZE-TCP interface outside object-group LIFESIZE-TCP

access-list VIDEOCONFNATPORTS extended permit udp host 10.1.1.7 object-group LIFESIZE-UDP interface outside object-group LIFESIZE-UDP

access-list VIDEOCONFNATPORTS extended permit tcp host 10.1.1.7 object-group POLYCOM-TCP interface outside object-group POLYCOM-TCP

access-list VIDEOCONFNATPORTS extended permit udp host 10.1.1.7 object-group POLYCOM-UDP interface outside object-group POLYCOM-UDP

static (inside,outside) interface access-list VIDEOCONFNATPORTS

---

I try to modify this and change the order of inside and outside, and i try to made this only with one port only like a test to reduce the complex.

But im not sure if i can get control in a static pat for a range of ports.

Of if someone have any advise to make this please tell me.

Thanks a lot.

1 REPLY
Silver

Re: polycom behind the asa.

For VPN Gateways that run Cisco IOS Software Releases earlier than 12.2(13)T, the IPSec passthrough feature is needed on the router that performs PAT to allow Encapsulating Security Payload (ESP) through.

The following URL helps you in configuration:

http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a0080094ecd.shtml#conf

808
Views
1
Helpful
1
Replies