Category Archives: Technology

Day 7: Working with Your Firewall Traversal Unit

This post continues our 20 Day Challenge to understand the technical aspects of videoconferencing.

Last week we discussed the two main ways to make videoconferencing work on your network. In today’s post, we look a little closer at the firewall traversal solutions.

Firewall Traversal

As a reminder, a firewall traversal box sits on the edge of the network, usually beside the firewall. Video traffic goes through the traversal box, and regular traffic goes through the firewall.

Some choices for this product include:

Benefits

The main reason to acquire a firewall traversal system is to securely pass video traffic through the firewall without reconfiguring your network.

Challenges

The main challenge of firewall traversal units is the problems it causes for receiving calls from other schools and content providers who aren’t on your network.

Working Around the Dialing Challenges

So, let’s say that your network has a firewall traversal unit and you can’t set up your videoconferencing any other way. Here are some tips for managing the dialing problems that will arise in regular use of curriculum videoconferencing. These dialing challenges are due to the necessity of receiving calls from off your network. Unfortunately some vendors and resellers continue to be stuck in the mode of thinking of a closed network, and provide advice to schools that doesn’t apply when they need to receive calls from other schools around the world.

Dial Out
First, realize that in most cases, you may need to dial out to the other site you want to connect to. Generally this isn’t a problem for connecting to content providers, most of whom are set up to receive a call to a direct IP address. However, as more schools use this method to set up videoconferencing, you may find schools you want to connect to who are also set up as dial out only; which means you may not be able to connect to them without using a bridge for you both to dial into.

Dialing Philosophies
Second, realize that Polycom and LifeSize prefer the IP##alias format; and Cisco-TANDBERG prefers the alias@IP or name@domain format. Because the standard isn’t well enough defined here, it leaves room for different implementations.

Polycom
If you have the Polycom Video Border Proxy (previously called V2IU), here are some tips:

  • Make sure it has the setting to translate the @ sign to a # sign. This will make it easier for Tandberg systems to call you.
  • If a newer Polycom system is calling you, they usually can dial the IP##alias format.
  • If a Tandberg system is calling you, have them dial the alias@IP format. (However, older Tandberg remotes do not have the @ sign easily accessible. If they are unable to use their web interface or address book for dialing, you may still have to dial out only to Tandberg sites.)
  • If a LifeSize system is calling you, they can do the IP##alias format.

If none of these work, you’ll have to call the other site or connect through a bridge.

Cisco-TANDBERG
If you have the Cisco-Tandberg Border Controller, here are some tips:

  • Polycom systems can dial the IP##alias format.
  • If a Tandberg system is calling you, have them dial the alias@IP format. (However, older Tandberg remotes do not have the @ sign easily accessible. If they are unable to use their web interface or address book for dialing, you may still have to dial out only to Tandberg sites.)
  • If a LifeSize system is calling you, they can do the IP##alias format.

If none of these work, you’ll have to call the other site or meet on a bridge.

LifeSize
If you have a LifeSize unit behind the LifeSize Transit, here are some tips:

  • Polycom systems can dial in using the IP##alias format.
  • Tandberg systems can dial in using the alias@IP format.
  • LifeSize can dial in using the IP##alias format.

If none of these work, you’ll have to call the other site or meet on a bridge.

References

Your Turn

  • These notes are based on our experiences connecting to schools around the country. If you have further insight to add, please comment!

Team-written by Janine Lim, Shane Howard, and Roxanne Glaser with input from Lori Colwill. The opinions expressed in these posts are based on our collective video conference experience connecting classes across multiple networks to connect them to zoos, museums, experts and other classes during the past 10 years. This series of posts reflects our usage and understanding, not that of any vendor or manufacturer. No one is paying us to write these. We are just sharing what we have learned.

Day 6: 5 Things That Can Make Your Video Conference Look Horrible

This post continues our 20 Day Challenge to understand the technical aspects of videoconferencing.

VC is a good test of the health of your network. If you have poor or unacceptable video quality, then check for these things:

1. Quality of Ethernet Cable

Make sure you have a good Ethernet cable. No crinks or folds or twists. Make sure it hasn’t been run over by the cart too many times! (For the vendors reading this, yes, this is an issue in K12 schools!)

2. Hubs in the Network Path

Replace any hubs in the path of the video conference traffic. Hubs seriously deteriorate the quality of the connection. Replace them!

3. Filter Settings.

We have all experienced odd behaviors and weird symptoms of videoconferences that ended up being the fault of the filter. Make sure the filter is allowing all necessary traffic to the videoconference systems. Review this port list if needed.

4. Excessive Bandwidth Use Behaviors

One common challenge in bandwidth-starved districts is the use of streaming video tools such as Discovery Education streaming and similar services. On a full-bandwidth network, someone live streaming a video can clobber the quality of the videoconference occurring at the same time. A solution used in Berrien RESA’s service area is to turn off the ability for teachers to live-stream the videos. Instead they must order their videos to be downloaded at night.

Another unfortunate challenge in some districts is that of computer labs used by students without appropriate supervision.

  • Students playing online multi-player games
  • Downloading large software files
  • Downloading large movies
  • Downloading music collections

All these cause havoc on the bandwidth usage.

Do what it takes (technological or political solutions) to make sure that non-academic use of technology doesn’t interfere with real engaging learning experiences.

5. Conflicting Router Settings

10/100 M and Full/Half Duplex Settings
The 10/100M or Full/half duplex settings on the router need to match those settings on the endpoint. When these settings don’t match, the endpoint and the router are constantly negotiating how to communicate and therefore using up processing power and bandwidth, which causes horrible quality. There was a time a few years ago in videoconferencing where it was recommended to hard set both of them to the highest that the router could do. However, with newer routers, generally you’ll get the best success with both set to auto. Experiment to see which works best if necessary.

Timeout Limits
Review the time out limits on the router or the wireless access points. If a call drops consistently after a set amount of time, this could be a timeout limit somewhere in the network path of the videoconference. When the videoconference call starts, the two endpoints communicate on certain ports; but after that, the communication happens on the audio/video streaming ports. In some cases, the router thinks that the connection is no longer being used, so it ends the call. Check the settings!

Cohesive NAT settings
If you’re using the NAT solution, make sure the NAT settings are cohesive on the firewall / router and endpoint. We have all seen situations where the settings are good enough that calls occur, but the quality is poor. Making sure the settings are correct improves the quality. In particular, check the “fixed ports” and “firewall is H.323 compatible” settings. Experiment if necessary to see which settings work best.

References

Your Turn

  • Have you noticed any of these challenges? How did you solve them?
  • What other problems would you add to this list? Please comment!

Team-written by Janine Lim, Shane Howard, and Roxanne Glaser. The opinions expressed in these posts are based on our collective video conference experience connecting classes across multiple networks to connect them to zoos, museums, experts and other classes during the past 10 years. This series of posts reflects our usage and understanding, not that of any vendor or manufacturer. No one is paying us to write these. We are just sharing what we have learned.

Day 5: How To Manage Your Bandwidth

This post continues our 20 Day Challenge to understand the technical aspects of videoconferencing.

Another key component of a quality videoconferencing is proper bandwidth management.

First Assess Your Network

  • How much bandwidth are you currently using?
  • Does it sometimes peak to your maximum?

A videoconference of 384K only uses about 400-500K; however, if your bandwidth is full and maxed out; the other traffic can clobber your videoconference so you have very poor quality. If your traffic EVER spikes to the max during school hours when you might have a videoconference, you need to put a solution in place to guarantee the quality of your videoconference. Here are three options:

VLANS

  • Described as a virtual LAN, a VLAN consists of a group of devices/hosts that communicate as if they were on the same broadcast domain, even if not on the same physical location.
  • Example: Most video networks use VLANs to keep their video traffic separate from their normal data traffic. This helps with quality and bandwidth management.

Router QoS

  • Another method is to set quality of service for videoconferencing on the parts of the network that you can control.
  • In Berrien RESA’s case, the schools get their Internet access through us. So we set QoS on their router and on our router. This guarantees the quality of the videoconference between the school and us. This was more essential in the early days of our videoconferencing when the districts had T1s to us. Now most of them are on fiber.

Packet Shaping

  • Another way to guarantee the traffic for the videoconference is by using packet shaping.
  • In Berrien RESA’s case, this is done by using Packeteer to guarantee up to 6 Meg of traffic from our network out to the world for the IP addresses of our videoconference systems and MCU. This means that if our bandwidth out is maxed out; our videoconferences will still be high quality. So far, even on super busy days of 20-30 VCs, we haven’t used more than that 6 Meg.

References

Your Turn

  • How is the health of your network bandwidth?
  • What methods do you use, prefer or recommend for bandwidth management?

Team-written by Janine Lim, Shane Howard, and Roxanne Glaser. The opinions expressed in these posts are based on our collective video conference experience connecting classes across multiple networks to connect them to zoos, museums, experts and other classes during the past 10 years. This series of posts reflects our usage and understanding, not that of any vendor or manufacturer. No one is paying us to write these. We are just sharing what we have learned.

Day 4: Making H.323 Video Conferencing Work on a Network

This post continues our 20 Day Challenge to understand the technical aspects of videoconferencing.

There are two main methods for installing videoconference hardware on your network. We prefer the NAT static IP method; but we also realize that’s “old school”. Be that as it may, we’ve noticed a trend across the U.S. that some states with a strong Internet2 influence are more likely to use the static IP method.

Let’s consider in more depth the two methods for installing your videoconference system.

1. Static IP NATed Through Firewall

This method provides a public IP address that can be dialed and so the endpoint can easily place and receive calls.

To setup:

  1. First on the router (or firewall), set up a NAT (Network Address Translation) mapping an assigned static public IP address to the internal address that the endpoint will use.
  2. Then, on the endpoint, go into the LAN settings and put in the internal IP address information (DNS, internal IP, gateway, etc.). This part is very similar to how you would set up a computer on your network.
  3. Next, on the endpoint, go into the IP Network H.323 Firewall settings, and add the Public IP address. Some systems have options for autodetecting the NAT, manual defining the NAT, and H.460 Firewall Traversal, and fixed ports. You may need to experiment with these settings until you find the one that works best with your firewall. Change one setting at a time, then try to dial out to a test site and see if it will connect. (At this point, you may or may not receive video from the test site; but at least see if it will dial out.)

The endpoint needs to know the NAT information so that it can properly package the bits of data so that return traffic actually gets through!

Videoconference Traffic Ports
The final area you’ll need to set is to make sure that the firewall is allowing traffic through the right ports for videoconferencing.

First, a little history. The H.323 standard was developed without firewalls in mind. So since then, manufacturers have been challenged to develop equipment and work together to adapt the standards to work better through firewalls. This means that the way H.323 communicates on your network isn’t exactly firewall friendly. It’s helpful to know what happens when a call is set up:

  • First the two systems communicate through TCP and UDP port 1720 to set up the call. This is standard across all vendors.
  • If a gatekeeper is used, then the endpoint communicates with the gatekeeper through ports 1718 and 1719 (TCP and UDP). (More on gatekeepers in a future post.)
  • During this initial communication, the two endpoints talk to each other to share capabilities (called the caps exchange). This includes, which ports the video and audio streaming is shared through. There is a wide range of ports allowed for this streaming, and it depends on your settings (i.e. fixed ports), and the other endpoints settings, on what it will actually settle on.
  • For a full list of ports used in videoconferencing, see this list.

Bottom Line
For ports, you need to open these ports for the static IP that the videoconference system is using:

  • 1720 TCP UDP both ways
  • If you use a gatekeeper off your network, 1718 and 1719. (Janine’s schools do this; Shane & Roxanne’s don’t).
  • The fixed ports you set on the endpoint.

That’s the minimum.

In our cases, we also need to remote manage the school’s endpoints. So we also have the tech director open these ports:

  • Web access (port 80)
  • Telnet access
  • FTP access (for remotely upgrading the system)
  • SNMP (if we have the systems in a management system such as RENOVO, Tandberg Management Suite (TMS), or Polycom Converged Management Application (CMA).

If there are concerns about security, these ports can be set to accept traffic only from our network.

Some Final Notes

  • Call a test site and make sure you can send and receive video and audio.
  • Some of our schools are set up this way, but due to restrictions on the firewall’s capabilities or on the school network policy, the units can only dial out. However, wherever possible, we try to get the units set up so they can place & receive calls to an IP address.
  • One security method is to keep the unit turned off when it is not in use.
  • In some cases, if you do not have the videoconference unit NATed, you are still able to dial out of your network to other public sites, but are not able to have other sites dial back to you.

2. Firewall Traversal Appliance

Firewall

The newer method, recommended by resellers and manufacturers, is to purchase an additional firewall traversal product. The firewall traversal box sits on the edge of the network, usually beside the firewall. In this setup, video traffic goes through the traversal box, and regular traffic goes through the firewall.

Some choices for this product include:

Generally you’ll have better luck if you buy the same vendor’s firewall traversal product as the endpoints.

Installation will be done by the reseller that sold you the equipment; so there isn’t any extra configuration needed on your end.

Dialing
So the way dialing happens with this scenario, is the person off your network calls the IP of the firewall traversal product and the extension of the endpoint. There is no public IP for the endpoint (although if someone wants your public IP, you give them the IP of the firewall traversal product plus the alias or extension.)

The challenge with dialing is that there are currently three different methods for passing the extension, and not all of the vendors support all of the methods. i.e. This is an area that isn’t really standardized yet. It’s a good place for arguments too, as you’ll hear the vendors say their way is better. But as an end user, you need to be able to call any K12 school. Period.

Advantages

  • You don’t have to configure your network as described above.

Disadvantages

  • You will guaranteed have problems with other schools calling you. Cisco-Tandberg units can’t dial into the Polycom method; (although Polycom units can dial the Cisco-Tandberg method). More on dialing in a future post.
  • Extra cost.

References

Your Turn

  • Which method was used for installing your videoconference system?
  • Do you have an opinion or preference for one of these methods? Please share!
  • If you disagree with our view here, we welcome your thoughtful (not flaming) comments.

Team-written by Janine Lim, Shane Howard, and Roxanne Glaser. The opinions expressed in these posts are based on our collective video conference experience connecting classes across multiple networks to connect them to zoos, museums, experts and other classes during the past 10 years. This series of posts reflects our usage and understanding, not that of any vendor or manufacturer. No one is paying us to write these. We are just sharing what we have learned.

Day 3: How to Determine Public vs. Private IP Addresses

This post continues our 20 Day Challenge to understand the technical aspects of videoconferencing.

Why Do IP Addresses Matter?

IP Addresses are used in standards-based H.323 videoconferencing; not for Skype or other proprietary desktop / web based conferencing tools.

Many corporations only videoconference within their network and therefore don’t need to dial IP addresses. But in the K12 space, we are always dialing out to schools outside of our network / area. So, the way to dial other people is to use their IP address. (Usually. More on other H.323 dialing in a later posts on gatekeepers and firewall traversal units.)

To be able to receive a call from someone, you need to know your public IP address!

Public IP Addresses

A public IP (Internet Protocol) address is an number that is accessible by anyone on the internet. Public IP addresses are reserved for public access. They are used to direct traffic coming in from outside your network. IP address look like this 199.108.230.249 or 12.23.17.16 or some similar variation. Some video conference units enter the dot with a *; and others use a dot. But the number itself has dots! The correct way to refer to it is with the term dot (not period or star or asterisk).

Private IP Addresses

Private IP addresses are used only within your network. No one outside your network can dial a private IP address because they aren’t on your network. Think of it like dialing a phone extension within the school. Outsiders couldn’t get you with just that 3 or 4 digit number. They have to dial the full public number. In this case, they can look similar; the difference is what the number starts with. Private IP addresses always start with:

  • 10.x.x.x
  • 172.16.x.x
  • 192.168.x.x

Dynamic or Static?

You also need to know if your IP is dynamic or static. Dynamic IP addresses change. They can change when a computer (or videoconference system) is rebooted, or when something changes on the network. Static IP addresses are always the same number. Many videoconference systems are installed with a static IP address, as this makes it much easier for others to dial you.

What do you know about your IP address?

  • Does it always stay the same? or does it change?
  • If it changes, do you know how often it changes? What triggers the change? When and how often do you need to check if it changed?

For example, some schools use cable to access the Internet and may not invest in static IP addresses (they usually cost extra with cable). In this case, often when the equipment is turned off and on again, it picks up a new IP address. This behavior is called “dynamic”.

References

Your Turn

  • Do you know your public IP address?
  • Do you know if your address is dynamic or static?

Team-written by Janine Lim, Shane Howard, and Roxanne Glaser. The opinions expressed in these posts are based on our collective video conference experience connecting classes across multiple networks to connect them to zoos, museums, experts and other classes during the past 10 years. This series of posts reflects our usage and understanding, not that of any vendor or manufacturer. No one is paying us to write these. We are just sharing what we have learned.

Day 2: Understanding Technical Video Conference Terms

First things first, on our journey here to understand the technical aspects of videoconferencing. Definitions! This is an area where there is a lot of confusion in K12 education.

IP Videoconferencing

This is an ambiguous term. “IP” just means Internet protocol. It just means that you’re using the Internet. Some people used to use this term to differentiate between IP (over the Internet) and ISDN (digital phone lines) videoconferencing. But now, most videoconferencing is over the Internet. Whether web based, software based, hardware based, videoconferencing generally connects over the Internet. So the more useful terms are exactly HOW are you videoconferencing. What software or hardware are you using and does it use a standard?

H.323 Videoconferencing (Standards-based)

The videoconferencing we use is standards-based. That is, whether you are using Polycom, Tandberg, LifeSize (etc) equipment or software, you can connect to any other equipment or software that is also using the H.323 standard. Most of the content providers we connect to, the content that Whirlidurb offers, and the collaborations and events in CAPspace all use the H.323 standard .

Skype, Windows Messenger, Google Chat, TokBox, etc.

Each of these videoconferencing tools is “proprietary” software running on a computer with any type of webcam. You can only connect to the people using the same software or web application.

Desktop Videoconferencing (can be standards-based or proprietary)

Desktop videoconferencing is also known as software-based videoconferencing. You need:

  • a computer
  • a webcam
  • videoconference software

In a classroom, desktop videoconferencing can be used for the whole class by connecting the computer to a projector.

Desktop videoconference software options include:

Hardware-based Videoconferencing (standards-based)

Many schools install videoconference carts, with a videoconference appliance. This “box” is also known as:

  • the codec
  • the endpoint
  • the camera

Carts installed in schools usually include:

  • A camera
  • The codec (the “box” that has all the smarts to make VC happen)
  • A microphone
  • A display – often a 30-50 inch LCD monitor or a projector
  • A document camera
  • A way to connect the computer
  • A remote for video conference unit

Bridge (only standards-based)

Some large school districts and many educational service agencies have additional videoconferencing equipment: the “bridge” or MCU (multipoint control unit).

  • A bridge allows for multiple videoconferences (aka conference rooms) at the same time
  • A bridge allows two or more videoconference sites or endpoints to connect into the same conference
  • A bridge allows multi-vendor endpoints to co-exist in a conference

References

For further reading, see these resources:

Your Turn

  • Do you know what kind of videoconferencing you have? Is it standards-based (H.323) or not?
  • If you use desktop videoconferencing, what kind are you using? Who can you connect to?

Knowing this will make it easier to connect to other educators!

Team-written by Janine Lim, Shane Howard, and Roxanne Glaser. The opinions expressed in these posts are based on our collective video conference experience connecting classes across multiple networks to connect them to zoos, museums, experts and other classes during the past 10 years. This series of posts reflects our usage and understanding, not that of any vendor or manufacturer. No one is paying us to write these. We are just sharing what we have learned.

Day 1 Talk Like a Techie: 20 Days VC Challenge

It’s time for the 3rd annual 20 Day Challenge on videoconferencing topics, written by Roxanne Glaser and Janine Lim!

This year we tackle the complicated and challenging area of the technical aspects of videoconferencing. In K12 education, it’s often hard to find someone with knowledge of how standards-based (H.323) videoconferencing interacts with the district network. This can cause quality issues that present a barrier to educators and teachers who want to use videoconferencing. So for the next 20 days of blog posts, we’ll be sharing some best practices and background knowledge of how videoconferencing works on your network.

Target Audience

Our target audience for this series includes:

  • Educational service agency personnel involved with videoconferencing
  • District technology coordinators and technicians involved with making videoconferencing work on the network
  • School level educators who need enough background knowledge to effectively communicate with network folks

Guest Blogger Shane Howard

We are joined this year, by award-winning multi-talented Super Bridge Dude, Shane Howard (who by the way has his own band!). Shane has many qualifications to contribute to this blog challenge:

  • supporting schools’ use of videoconferencing for over 13 years
  • expertise in working with school networks to optimize videoconferencing
  • also known as Rudolph and has appeared on screens as a school bus and a sun!
  • runs the SIG IVC Ops at the ISTE conference, making sure all the connections went smoothly.

Topics

During the course of the next 20 days, we’ll be discussing various topics that affect the educational experience of videoconferencing, including:

  • Definitions and background knowledge
  • Setting up your network for videoconferencing
  • Firewalls, firewall traversal units, gatekeepers
  • Dialing quirks and tips
  • Basic troubleshooting

Whether you are new to videoconferencing, or an old pro, we hope that this series of posts will help you improve your practice so that your teachers can be more successful in their use of videoconferencing.

Task

Your Turn

  • What do you find most technically challenging about videoconferencing?

Multifunction Devices & Classroom Videconferencing

Recently, I read this post on the Radvision blog about multi-funtion devices vs. single-function devices. While Sagee was focusing on the Flip camera vs. the iPhone and other Smartphone, I couldn’t help but think about classroom videoconferencing.

Single Device
Would you rather have a single device that only does one thing: videoconferencing?

Multifunction Device

Or would you rather have a device that does multiple things: an interactive whiteboard plus a camera for videoconferencing:

Silvia Tolisano's class interviews an Olympian

A device that can:

  • Do Skype videoconferencing
  • Do standards-based videoconferencing
  • Display web pages and movies
  • Can use for drawing and concept maps
  • And much much more…

This is my vision for my schools: to provide a login to standards-based videoconferencing so that they can use whatever tool necessary to videoconference with whoever they want. All from the comfort of the classroom and using the “technology central tool” in their classroom.

What do you think?

Upcoming H323 Network Training

From the megaconference listserv, information about this upcoming training from the University of Wisconsin:

Understanding and Troubleshooting Videoconferencing Networks, November 2-3, 2010

I took this workshop a few years ago, and it is excellent! Even if you’re an educator (like me), learning to be a VC technician as well, it is definitely helpful. Teaches you the language and concepts you need to talk to your network people. When I attended, I thought I didn’t know enough to be able to learn anything from it, but suprisingly, I did! You can read my past blog posts about this workshop here and here.

When I participated, a whole group in Michigan organized to have the workshop at one site and then we split the cost between all the attendees.

They don’t pay me, or even ask me, to advertise this workshop. I’m just sharing it with you because it was such a benefit to me.

Upgrade to our Distance Learning Room

Yesterday and today I’ve been teaching several sessions on videoconferencing & Skype to our annual Berrien RESA Tech Camp. I’ve been super excited because I got to teach with our new upgraded room!

It’s actually not as upgraded as some of you can afford, but I’m still excited!

Before

So first, here’s what it looked like before.

This 60 inch monitor was part of a Goals 2000 Grant installation in 1999. Look at how the colors were bleeding apart in the top right. Very annoying!

After

Of course, now, this is Michigan, and we’re out of money! So the upgrade was actually driven by the Smart award presentation given to MACUL Educator of the Year winners. The award included a Smart Board, projector, clickers, slate, document camera, as well as all the software. I’ve been so excited because I wanted to figure out how to get desktop videoconferencing working on an interactive whiteboard.

Last Friday, just in time for tech camp, the last piece was finished in the DL room – mounting the Smart Board, building a cabinet for the Polycom VSX 7000. Here’s what it looks like in a “standards based” videoconference with the Polycom just dialed out to my office unit.

(Apologies for the cell phone quality picture.)

Here’s what it looks like in a Skype call with Roxanne Glaser for my workshop today. I circled the Logitech webcam so you could see where that is.

Next I want to figure out how to use a long USB extension cable to mount the webcam somewhere close to the monitor for whole class connections. Although, the more I play with Skype / desktop VC, I think it’s nicer to be able to pick the webcam up and move it around as needed (sort of like manual presets! ha!).

So that’s my new distance learning room. The monitor hanging in the ceiling came out. The pole in the middle of the room came out. It’s a lot cleaner-looking and much more flexible now. Yay! And, now we can do Smart Board training in this room too!

I know, I know. A “real” upgrade would mean upgrading to HD videoconferencing. Well that’s on the list, but for now I’m happy with this!