sk182835 - VoIP H.323 calls are dropped with reason "Handler 'h323_h245_code' reject"
VoIP H.323 calls are dropped with reason "Handler 'h323_h245_code' reject"
Product
Security Gateways
Version
R81.10 (EOS), R81.20, R82
Last Modified
2025-06-15
Symptoms
The VoIP H.323 calls fail, but there is no firewall drop log in the SmartConsole.
The
fw ctl zdebug + dropcommand shows that the RTP traffic is dropped as follows.
@;116090.10298104; 1Nov2024 11:22:45.534169;[vs_0];[tid_0];[fw4_0];fw_log_drop_ex: Packet proto=6 xx.xx.xx.xx:11133 -> xx.xx.xx.xx:50361 dropped by fw_post_vm_chain_handler Reason: Handler 'h323_h245_code' reject;
Cause
The H.323 connection is registered by the fileapp module which processes the DATA on non-FTP protocols wrongly in some scenarios.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 25
- Jumbo Hotfix Accumulator for R81.20 starting from Take 99
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
This immediate workaround is available:
Disabling H.323 inspection
Note: If NAT is involved for H.323 connection, using customized service will disable the NAT on the H.323 payload which might cause the RTP audio and video streams can't be established.
Create customized TCP/UDP services for the relevant ports used by the H.323 protocols like TCP 1720 and port range for the RTP audio and video streams (please refer to the VoIP meeting conferencing system vendor for more details.) or just use the predefined service
tcp-high-portswhich doesn't have protocol handler defined.Use only the customized TCP/UDP services in the specific Access Control rule which allows the H.323 traffic, remove any other H.323 predefined services like
H323 / H323_ras / H323_ras_only / H323_anyin this rule.
Note: If you have a separate Application & URL Filtering ordered layer, please create a rule identical to the Network rule to disable H.323 inspection in this policy layer too.
- Install the Access Control policy and check the firewall logs to ensure that the new H.323 connection will be matched by the customized services defined.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-12-13
Last Modified: 2025-06-15