Lync Edge External to internal Communication or Internal to External Communications Firewall issues

I am not a Firewall person. Lets just get that clear. I want to make sure I don’t forget this. I did run into this with my mentor and a customer who had an inbound outbound Lync issue for external access.  I turned out to be the blood hound in this situation. The Fox I had cornered was one that does not show up well on a packet trace. It appears like a tarpit. Packets response times increase in latency. There is no exact error to speak of. If you look at a trace you may find this under

So you will add your policy rule for Source NAT translation for your AV firewall rule. Next you will disable Palo alto syn cookies. This setting may cause latency with lync communications.

http://digitalscepter.com/wp-content/uploads/PAN-Guides/Palo-Alto-3.1_Administrators_Guide.pdf

http://www.google.com/url?sa=t&rct=j&q=palo%20alto%20syn%20cookie&source=web&cd=11&ved=0CCgQFjAAOAo&url=https%3A%2F%2Fwww.nsslabs.com%2Fsystem%2Ffiles%2Fpublic-report%2Ffiles%2Fnss%2520labs%2520network%2520firewall%2520remediation%2520brief%25202011%2520v8.pdf&ei=dxyBUoXJB8rokAf3kYDYDQ&usg=AFQjCNGaUrAWWNhwra96huOkZIf8neONHg&sig2=HJDW0gCBP9RTGBJoirofLw&bvm=bv.56146854,d.eW0

I included an example Wireshark TCP graph of what the failed transmits may look like. If this graph shows a straight 45 degree angle line, then this is likely not your issue.

 

This is only one of several settings that may cause this. ALG filtering is also the same graph. I Just happened to find this on Palo Alto but any Next Generation Firewall is likely to show this issue if the source port translation, destination translation, and Firewall filtering settings are not corrected. I hope this is helpful and Lync On.

 

 

 

Untitled

 

Advertisements

One thought on “Lync Edge External to internal Communication or Internal to External Communications Firewall issues

  1. It’s a shame you don’t have a donate button! I’d without
    a doubt donate to this superb blog! I suppose for now i’ll settle for book-marking and adding
    your RSS feed to my Google account. I look forward to new updates and will share this website with my Facebook group.
    Chat soon!

    Like

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s