How to configure Microsoft NetMeeting to pass through a Symantec firewall
Question/Issue:
This document describes how to configure Microsoft NetMeeting to pass through a Symantec firewall.
Solution:
This configuration has been lab tested on both LAN and WAN (Internet Routable addresses), audio and video only. Other NetMeeting components have yet to be lab tested.
- Enable the H323 Daemon.

- Create an alias:
- Name: Whatever you prefer.
- Alias Replacement is the outside or DMZ IP address of the firewall.
- Destination Host is the inside or actual IP address of the computer.
Note: In this example the IP address 172.18.128.146 is a member of the inside network (DMZ) but can be replaced by the outside IP (Internet Routable) of the firewall.

- Create Protocols TCP/522, 389, 1503, and 1731

- Create a GSP for each protocol.


- Add all the newly created GSPs and H323 to a NetMeeting Rule (inbound/outbound):
- Include the following Services to each rule in the Included Services window of the dialog box (note that we are adding the ping* service so that we can test outbound traffic).

- Add a Redirect for each GSP and H323 Daemon as the Service.
Requested address = the routable address.
Redirected address is the actual address of the computer (leaving the port blank).


- Save and reconfigure.
Note: Even with all configured correctly, NetMeeting will give the following error on an outbound connection (from behind the firewall to outside):

This does not go away, but the meeting will work. Occasionally the connection needs to be attempted several times, and audio is a bit choppy.
Document ID: 2002090410251554
Last Modified: 08/06/2003
Date Created: 09/04/2002
Product(s): Symantec Enterprise Firewall 6.5, Symantec Enterprise Firewall 7.x, Symantec Gateway Security Appliance 1.0, Symantec VelociRaptor 1.1, Symantec VelociRaptor 1.5
Release(s): Symantec Enterprise Firewall 6.5.2, Symantec Enterprise Firewall 7.0, Symantec Enterprise Firewall 7.03, Symantec Enterprise Firewall 7.04, Symantec Gateway Security Appliance 1.0, Symantec VelociRaptor 1.1, Symantec VelociRaptor 1.5