300-710 · Question #313
Remote users who connect via Cisco Secure Client to the corporate network behind a Cisco Secure Firewall Threat Defense device are reporting no audio on calls when calling between remote users using…
The correct answer is B. Cisco Secure Firewall Threat Defense needs a NAT policy that allows outside to outside. When two remote VPN users call each other, both appear as 'outside' clients to the FTD. Their audio (RTP/RTCP media) streams must travel from one outside VPN endpoint, through the FTD, and back out the same outside interface to the other VPN endpoint - this is called…
Question
Remote users who connect via Cisco Secure Client to the corporate network behind a Cisco Secure Firewall Threat Defense device are reporting no audio on calls when calling between remote users using their softphones. These same users can call internal users on the corporate network without any issues. What is the cause of this issue?
Options
- AThe hairpinning feature is not available on Cisco Secure Firewall Threat Defense
- BCisco Secure Firewall Threat Defense needs a NAT policy that allows outside to outside
- CThe Enable Spoke to Spoke Connectivity through Hub option is not selected on Cisco Secure
- DSplit tunneling is enabled for the Remote Access VPN on Cisco Secure Firewall Threat Defense
How the community answered
(46 responses)- A7% (3)
- B83% (38)
- C9% (4)
- D2% (1)
Explanation
When two remote VPN users call each other, both appear as 'outside' clients to the FTD. Their audio (RTP/RTCP media) streams must travel from one outside VPN endpoint, through the FTD, and back out the same outside interface to the other VPN endpoint - this is called hairpinning. By default, FTD does not route traffic from the outside interface back out the same outside interface. A NAT policy that permits outside-to-outside traffic (hairpin NAT or U-turn NAT) must be configured (B) to allow media to flow between the two remote users. Calls to internal users work because traffic simply flows from outside to inside without hairpinning. Option A is incorrect because hairpinning is supported on FTD via NAT policy. Option C refers to a Cisco FlexVPN/DMVPN spoke-to-spoke feature, not applicable here. Option D (split tunneling) would not cause one-way audio between remote users.
Topics
Community Discussion
No community discussion yet for this question.