Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Live Messenger > Unknown NAT Firewall

Reply
Thread Tools Display Modes

Unknown NAT Firewall

 
 
downunder
Guest
Posts: n/a

 
      10-01-2006
I'm unable to get Video and Audio conferencing to work. I have a Billion
7402VGO firewall / router with UPNP enabled. When I start WLM I can see
entries created in the UPNP portmap which leads me to believe that UPNP is
working.

However, firewall log also shows I was blocking UDP port 7001 in both
directions. A microsoft article (831703) states this is a test that
determines if the NAT or firewall device supports connections that permit
video conferencing, voice (computer-to-computer calling), or phone calling
(computer-to-phone calling).

Before opening up UDP port 7001, I received the following message when I
tested the connection status through WLM:
* You are connected to the internet through a Non-UPnP
firewall.(Administrator)

After opening up UDP port 7001, I received the following message.
* You are connected to the internet through an unknown NAT.
(Administrator)
However, I am still unable to start a Video conference.

After I switch the firewall off (except NAT), I receive the same message.
* You are connected to the internet through an unknown NAT.
(Administrator)
But I am now able to start a Video conference.

I realise WLM will use UPnP to open the necessary ports for Video
conferencing but are there some or standard packet filtering rules (like UDP
7001) that I need to setup to allow WLM to verify the network environment?

What's the ideal message I should receive when I test the connection status
in WLM?
"You are connected to the internet through an unknown NAT. (Administrator)"
or something else?

Ideally, I would like to be able to start a video conference without
switching off the firewall.

 
Reply With Quote
 
 
 
 
duoc
Guest
Posts: n/a

 
      10-09-2006
Port 7001 is used so that we can classify what NAT-type you are behind.
Unknown NAT simply means that we detected your NAT, but it does not behave in
a way where we can classify it (e.g. IP-restricted, port-restricted,
full-cone, symmetric, etc).

UPnP should help, but it also depends what your friend's connection is as
well.

I'm not sure how your firewall works. Is it possible that it is block
incoming UDP/TCP traffic, even though your NAT is allocating bindings through
UPnP? Some NATs/Firewalls do not allow incoming packets unless a
corresponding outgoing packet has been sent.


"downunder" wrote:

> I'm unable to get Video and Audio conferencing to work. I have a Billion
> 7402VGO firewall / router with UPNP enabled. When I start WLM I can see
> entries created in the UPNP portmap which leads me to believe that UPNP is
> working.
>
> However, firewall log also shows I was blocking UDP port 7001 in both
> directions. A microsoft article (831703) states this is a test that
> determines if the NAT or firewall device supports connections that permit
> video conferencing, voice (computer-to-computer calling), or phone calling
> (computer-to-phone calling).
>
> Before opening up UDP port 7001, I received the following message when I
> tested the connection status through WLM:
> * You are connected to the internet through a Non-UPnP
> firewall.(Administrator)
>
> After opening up UDP port 7001, I received the following message.
> * You are connected to the internet through an unknown NAT.
> (Administrator)
> However, I am still unable to start a Video conference.
>
> After I switch the firewall off (except NAT), I receive the same message.
> * You are connected to the internet through an unknown NAT.
> (Administrator)
> But I am now able to start a Video conference.
>
> I realise WLM will use UPnP to open the necessary ports for Video
> conferencing but are there some or standard packet filtering rules (like UDP
> 7001) that I need to setup to allow WLM to verify the network environment?
>
> What's the ideal message I should receive when I test the connection status
> in WLM?
> "You are connected to the internet through an unknown NAT. (Administrator)"
> or something else?
>
> Ideally, I would like to be able to start a video conference without
> switching off the firewall.
>

 
Reply With Quote
 
duoc
Guest
Posts: n/a

 
      10-09-2006
Port 7001 is used so that we can classify what NAT-type you are behind.
Unknown NAT simply means that we detected your NAT, but it does not behave in
a way where we can classify it (e.g. IP-restricted, port-restricted,
full-cone, symmetric, etc).

UPnP should help, but it also depends what your friend's connection is as
well.

I'm not sure how your firewall works. Is it possible that it is block
incoming UDP/TCP traffic, even though your NAT is allocating bindings through
UPnP? Some NATs/Firewalls do not allow incoming packets unless a
corresponding outgoing packet has been sent.


"downunder" wrote:

> I'm unable to get Video and Audio conferencing to work. I have a Billion
> 7402VGO firewall / router with UPNP enabled. When I start WLM I can see
> entries created in the UPNP portmap which leads me to believe that UPNP is
> working.
>
> However, firewall log also shows I was blocking UDP port 7001 in both
> directions. A microsoft article (831703) states this is a test that
> determines if the NAT or firewall device supports connections that permit
> video conferencing, voice (computer-to-computer calling), or phone calling
> (computer-to-phone calling).
>
> Before opening up UDP port 7001, I received the following message when I
> tested the connection status through WLM:
> * You are connected to the internet through a Non-UPnP
> firewall.(Administrator)
>
> After opening up UDP port 7001, I received the following message.
> * You are connected to the internet through an unknown NAT.
> (Administrator)
> However, I am still unable to start a Video conference.
>
> After I switch the firewall off (except NAT), I receive the same message.
> * You are connected to the internet through an unknown NAT.
> (Administrator)
> But I am now able to start a Video conference.
>
> I realise WLM will use UPnP to open the necessary ports for Video
> conferencing but are there some or standard packet filtering rules (like UDP
> 7001) that I need to setup to allow WLM to verify the network environment?
>
> What's the ideal message I should receive when I test the connection status
> in WLM?
> "You are connected to the internet through an unknown NAT. (Administrator)"
> or something else?
>
> Ideally, I would like to be able to start a video conference without
> switching off the firewall.
>

 
Reply With Quote
 
downunder
Guest
Posts: n/a

 
      10-10-2006
Hi. Thanks for the response.

The 7402VGO Firewall has different levels of protection that you can enable
* None
* Low Security
* Medium Security
* High Security
* All blocked / User Defined

I usually use Medium Security which adopts a restrictive plicy by blocking
all traffic except the standard ports such HTTP(80), FTP(21), SSL(443) etc.
You can open other ports if you want to.

When the firewall is set to Medium it is obviously interfering with
Messengers ability to open the necessary ports and video conferencing doesn't
work.

When the firewall is disabled (none), NAT is still enabled and video
conferencing does work.

I'd like to open as few ports as possible in order to get messenger working.
Can you specify the minimum ports and or ranges that need to be opened
(Inbound & Outbound) and what protocol (UDP/TCP) for each port?

Thanks.


"duoc" wrote:

> Port 7001 is used so that we can classify what NAT-type you are behind.
> Unknown NAT simply means that we detected your NAT, but it does not behave in
> a way where we can classify it (e.g. IP-restricted, port-restricted,
> full-cone, symmetric, etc).
>
> UPnP should help, but it also depends what your friend's connection is as
> well.
>
> I'm not sure how your firewall works. Is it possible that it is block
> incoming UDP/TCP traffic, even though your NAT is allocating bindings through
> UPnP? Some NATs/Firewalls do not allow incoming packets unless a
> corresponding outgoing packet has been sent.
>
>
> "downunder" wrote:
>
> > I'm unable to get Video and Audio conferencing to work. I have a Billion
> > 7402VGO firewall / router with UPNP enabled. When I start WLM I can see
> > entries created in the UPNP portmap which leads me to believe that UPNP is
> > working.
> >
> > However, firewall log also shows I was blocking UDP port 7001 in both
> > directions. A microsoft article (831703) states this is a test that
> > determines if the NAT or firewall device supports connections that permit
> > video conferencing, voice (computer-to-computer calling), or phone calling
> > (computer-to-phone calling).
> >
> > Before opening up UDP port 7001, I received the following message when I
> > tested the connection status through WLM:
> > * You are connected to the internet through a Non-UPnP
> > firewall.(Administrator)
> >
> > After opening up UDP port 7001, I received the following message.
> > * You are connected to the internet through an unknown NAT.
> > (Administrator)
> > However, I am still unable to start a Video conference.
> >
> > After I switch the firewall off (except NAT), I receive the same message.
> > * You are connected to the internet through an unknown NAT.
> > (Administrator)
> > But I am now able to start a Video conference.
> >
> > I realise WLM will use UPnP to open the necessary ports for Video
> > conferencing but are there some or standard packet filtering rules (like UDP
> > 7001) that I need to setup to allow WLM to verify the network environment?
> >
> > What's the ideal message I should receive when I test the connection status
> > in WLM?
> > "You are connected to the internet through an unknown NAT. (Administrator)"
> > or something else?
> >
> > Ideally, I would like to be able to start a video conference without
> > switching off the firewall.
> >

 
Reply With Quote
 
downunder
Guest
Posts: n/a

 
      10-10-2006
Hi. Thanks for the response.

The 7402VGO Firewall has different levels of protection that you can enable
* None
* Low Security
* Medium Security
* High Security
* All blocked / User Defined

I usually use Medium Security which adopts a restrictive plicy by blocking
all traffic except the standard ports such HTTP(80), FTP(21), SSL(443) etc.
You can open other ports if you want to.

When the firewall is set to Medium it is obviously interfering with
Messengers ability to open the necessary ports and video conferencing doesn't
work.

When the firewall is disabled (none), NAT is still enabled and video
conferencing does work.

I'd like to open as few ports as possible in order to get messenger working.
Can you specify the minimum ports and or ranges that need to be opened
(Inbound & Outbound) and what protocol (UDP/TCP) for each port?

Thanks.

"duoc" wrote:

> Port 7001 is used so that we can classify what NAT-type you are behind.
> Unknown NAT simply means that we detected your NAT, but it does not behave in
> a way where we can classify it (e.g. IP-restricted, port-restricted,
> full-cone, symmetric, etc).
>
> UPnP should help, but it also depends what your friend's connection is as
> well.
>
> I'm not sure how your firewall works. Is it possible that it is block
> incoming UDP/TCP traffic, even though your NAT is allocating bindings through
> UPnP? Some NATs/Firewalls do not allow incoming packets unless a
> corresponding outgoing packet has been sent.
>
>
> "downunder" wrote:
>
> > I'm unable to get Video and Audio conferencing to work. I have a Billion
> > 7402VGO firewall / router with UPNP enabled. When I start WLM I can see
> > entries created in the UPNP portmap which leads me to believe that UPNP is
> > working.
> >
> > However, firewall log also shows I was blocking UDP port 7001 in both
> > directions. A microsoft article (831703) states this is a test that
> > determines if the NAT or firewall device supports connections that permit
> > video conferencing, voice (computer-to-computer calling), or phone calling
> > (computer-to-phone calling).
> >
> > Before opening up UDP port 7001, I received the following message when I
> > tested the connection status through WLM:
> > * You are connected to the internet through a Non-UPnP
> > firewall.(Administrator)
> >
> > After opening up UDP port 7001, I received the following message.
> > * You are connected to the internet through an unknown NAT.
> > (Administrator)
> > However, I am still unable to start a Video conference.
> >
> > After I switch the firewall off (except NAT), I receive the same message.
> > * You are connected to the internet through an unknown NAT.
> > (Administrator)
> > But I am now able to start a Video conference.
> >
> > I realise WLM will use UPnP to open the necessary ports for Video
> > conferencing but are there some or standard packet filtering rules (like UDP
> > 7001) that I need to setup to allow WLM to verify the network environment?
> >
> > What's the ideal message I should receive when I test the connection status
> > in WLM?
> > "You are connected to the internet through an unknown NAT. (Administrator)"
> > or something else?
> >
> > Ideally, I would like to be able to start a video conference without
> > switching off the firewall.
> >

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
IE8 has encountered and unknown error, module unknown (xp) Bruce Leavitt Internet Explorer 5 05-15-2009 04:53 PM
Firewall Vista also blocks outgoing traffic? Is the firewall good Jerry Windows Update 1 04-09-2008 08:48 PM
Firewall rule created, but firewall drops FIST Windows Vista Security 1 04-16-2007 11:52 PM
Firewall rules: how to get list of allow program through firewall? Manoj Chanchawat, Symantec Corporation. Windows Vista Security 1 10-18-2006 07:55 PM
sp2 firewall compatible with norton internet security firewall ? marvin Windows Update 2 09-18-2004 02:56 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59