I came accross something odd the other day, I had some Cisco IP Phones on a DMZ interface and the Call Manager was behind the inside interface. If you made a call from a 7940 to a 7940 everything worked fine, if you made a call from a 7905 to a 7940 it failled!

I ran a packet capture and found that the phone was "bouncing" the RTP stream off the firewall rather than connecting directly to the peer phone... very weird! The problem was solved by enabling...

same-security-traffic permit intra-interface

I thought I post this for some future googlers!


