sk182835 - VoIP H.323 calls are dropped with reason "Handler 'h323_h245_code' reject"

VoIP H.323 calls are dropped with reason "Handler 'h323_h245_code' reject"

Product

Security Gateways

Version

R81.10 (EOS), R81.20, R82

Last Modified

2025-06-15

Symptoms

@;116090.10298104; 1Nov2024 11:22:45.534169;[vs_0];[tid_0];[fw4_0];fw_log_drop_ex: Packet proto=6 xx.xx.xx.xx:11133 -> xx.xx.xx.xx:50361 dropped by fw_post_vm_chain_handler Reason: Handler 'h323_h245_code' reject;

Cause

The H.323 connection is registered by the fileapp module which processes the DATA on non-FTP protocols wrongly in some scenarios.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

This immediate workaround is available:

Disabling H.323 inspection

Note: If NAT is involved for H.323 connection, using customized service will disable the NAT on the H.323 payload which might cause the RTP audio and video streams can't be established.

  1. Create customized TCP/UDP services for the relevant ports used by the H.323 protocols like TCP 1720 and port range for the RTP audio and video streams (please refer to the VoIP meeting conferencing system vendor for more details.) or just use the predefined service tcp-high-ports which doesn't have protocol handler defined.

  2. Use only the customized TCP/UDP services in the specific Access Control rule which allows the H.323 traffic, remove any other H.323 predefined services like H323 / H323_ras / H323_ras_only / H323_any in this rule.

Note: If you have a separate Application & URL Filtering ordered layer, please create a rule identical to the Network rule to disable H.323 inspection in this policy layer too.

  1. Install the Access Control policy and check the firewall logs to ensure that the new H.323 connection will be matched by the customized services defined.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General

Status: Approved by TAC

Date Created: 2024-12-13

Last Modified: 2025-06-15