Does anyone know if there's a way to get WebRTC traffic (used by Google Hangouts) to work through an XG firewall?
I just purchased two IP intercom units from www.nucleuslife.com, got them set up on my network, and confirmed that have Internet/WAN connectivity (I can ask Alexa to do things and get responses). The problem is they cannot see each other on my LAN. Each knows the other exists through my Nucleus account, but they show the other as "offline", thus cannot place calls. I've gone through all my firewall, IPS, etc. logs and show no signs of any traffic being blocked or dropped. I temporarily created new firewall rules allowing 'any' hosts and services from LAN to LAN, LAN to WAN and even WAN to LAN but it still didn't work.
I contacted Nucleus support and they said something in my network is blocking the WebRTC protocol. Two direct quotes from them below:
- "They should be able to contact each other without using the Internet. Are you able to use Google Hangouts on your network? We use the same protocol. Both TCP and UDP ports need to be available, but not any specific ones."
- "As neither device is seen by the mobile app, it sounds like WebRTC is being blocked by some configuration."
With that information I decided to try placing a hangouts call from my PC on the LAN to my wife's cell phone. It sat there saying "connecting..." but her phone never rang, nothing came through, and again, no blocked traffic in the various logs. Googling for Sophos and Hangouts led me to these two links:
- https://community.sophos.com/products/unified-threat-management/f/general-discussion/80297/outgoing-google-hangouts-video-no-longer-works
- http://ideas.sophos.com/forums/330219-sophos-xg-firewall/suggestions/13189158-allow-access-to-google-hangouts
The second link is not helpful, other than to suggest that XG blocking Google Hangouts is a known issue? The first link is specific to UTM, but suggests an external MTU-related solution. I will look into that deeper this evening after work, but I don't suspect that will be my answer. My devices are trying to talk LAN-to-LAN and per the support tech they should not need to go out to the WAN to connect. As such, I don't think a WAN MTU setting could be the culprit?
Does anyone have any thoughts or suggestions? Can anyone confirm that Google Hangouts is or is not working through their XG Firewall?
Thanks,
Marc
This thread was automatically locked due to age.