PDA

View Full Version : video chat over a proxy - can it be done?


krisleech
08-10-2005, 08:39 AM
Hi ya,

I trying to get video chat working over the internet, with no joy.

My setup is fairly standard for a business. We have a LAN made up of Win 2k PC's, we are connected to the internet by ADSL and protected by a firewall. The internet connection is shared by a proxy server. The firewall and proxy are software based and both sit on the same PC.

The firewall/proxy is a standard PC with two network cards, one card goes to the ADSL router (WAN) and one goes to the LAN router.

All traffic to/from the WAN passes through the firewall and proxy.

Now im trying to get iVisit (ivisit.com) video chat to work and it does work if i install it on the firewall/proxy PC, but it does not work on any of the workstations. The only difference being the firewall/proxy PC has direct access to the internet and the workstations go thru the proxy. Its not a firewall issue, it has the needed ports open and i have tried taking it down with no luck. Therefore (i think) it must be the proxy.

Has anyone got a video chat software to work thru a proxy, I am willing to use different video chat and proxy software as long as its not too expensive.

Can anyone name a working combo or suggest how my exisiting setup could work?

Cheers K.

ADSL MODEM <-> FIREWALL/PROXY PC <-> LAN ROUTER <-> WORKSTATIONS

hobbes
08-10-2005, 09:10 AM
What ports does iVisit require to be open incoming/outgoing?

Have you verified the firewall has those ports open and is providing the proper NAT for?

krisleech
08-10-2005, 09:18 AM
iVisit requires ports 9935 - 9945 UDP in both directions to be open. This is there loose configuration, you can just open port 9940.

I know the firewall is correct because I can connect with the install on the firewall PC which stills goes thru the firewall, so the correct ports must be open.

Also I have tried turning the firewall off with no joy.

I dont know much about NAT, my router has NAPT turned on. But again I do have iVisit connecting so NAT should be correct??

Cheers K.

hobbes
08-10-2005, 10:44 AM
Although you may be able to use the software on the firewall, that does not mean the firewall will also allow the packets to flow into the internal network. I would suggest you contact iVisit, letting them know your firewall info, for instructions on the proper configuration.

krisleech
08-10-2005, 11:18 AM
I have a rule that says any UDP packets can go in and out on ports 9935 - 9945. This basically opens a hole in the firewall. And it is not specific to an application so it means the iVisit app, the proxy app or any other app can send/recv. UDP packets at those ports.

I have contacted iVisit but they cant offer any help except the ports to open.

If I do a ethereal capture as iVisit trys to log on I get a number of NetBIOS packets sent out requesting that iVisit.com replies. Of couse there is no reply as iVisit.com is not on the LAN. And NetBIOS is blocked from going in/out of the LAN for security reasons.

I think fundermentally iVisit can not work over a proxy.

So what I'm really after is someone who has a setup that works.