Damien Sandras wrote:

Le ven 15/11/2002 à 11:40, Gilles Sadowski a écrit :
1. I use GnomeMeeting v0.12.2 on Debian GNU/Linux woody (kernel 2.4.19) as it is the last available in sections stable/testing.

GnomeMeeting 0.12.2 is very old. You should upgrade to 0.94.1. There are
many new options to limit the upload since 0.84.1 that were not
available in 0.12.2, that greatly improves the quality. That could help
you. I know that only 0.12.2 is in Woody, but that is not normal to keep
that old version (one year old).
OK.  I've upgraded.  Now I'm in 'unstable' :-{

2. I'm behind a firewall running a kernel 2.4.17 with the H323 patch (as explained in the FAQ), performing NAT. The gnomemeeting calls are redirected to the internal computer.

That patch is severely buggy and won't always work with GnomeMeeting (it
is random), a better solution is to use simple port forwarding with
0.94.1 and IP Translation.
It worked for me but, anyway, I've upgraded to kernel 2.4.19 without the h323 patch... But I have a hard time connecting with a NetMeeting user (I don't know if it is because of NetMeeting or my GnomeMeeting setup)
I use the Shorewall netfilter firewall.
The following is an excerpt (the part concerned with the gnomemeeting-related ports) of the command 'iptables -L' ('dawn' is the name of the machine behind the firewall on which GnomeMeeting runs):
Chain net2loc (1 references)
target prot opt source destination ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED newnotsyn tcp -- anywhere anywhere state NEW tcp flags:!SYN,RST,ACK/SYN ACCEPT tcp -- anywhere dawn state NEW tcp dpt:1720 ACCEPT tcp -- anywhere dawn state NEW tcp dpts:30000:30010 ACCEPT udp -- anywhere dawn state NEW udp dpts:5000:5003

Then here are some of the logged messages about dropped packets:
Nov 23 21:53:31 lestat kernel: Shorewall:net2all:DROP:IN=ppp0 OUT= MAC= SRC= DST= LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=13490 DF PROTO=TCP SPT=2151 DPT=1503 WINDOW=8192 RES=0x00 SYN URGP=0

Nov 23 22:07:08 lestat kernel: Shorewall:net2all:DROP:IN=ppp0 OUT= MAC= SRC= DST= LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=43454 DF PROTO=TCP SPT=2235 DPT=32773 WINDOW=8192 RES=0x00 SYN URGP=0
Of course ports 1503 and 32773 are blocked because only 1720, 30000 to 30010 and 5000 to 5003 are allowed and redirected to 'dawn'.

On the NetMeeting side my 'Connect/callto' trials were never seen. On my side, the 'Connect' windows appeared several times but clicking on the 'connect' button was to no avail. Finally, at some point, after many trials, the link was established, but then after 3 minutes or so, GnomeMeeting crashed! :-( After restarting, we tried to reestablish the connection but it didn't work...

Does someone have an idea on what's wrong here?
Thanks for your help.


