Ok I found the solution for the replay and the records. They all work perfectly now.
Here is my config:
firewall { all-ping enable broadcast-ping disable group { address-group IPTV-Multicast { address 224.0.0.0/4 address 239.0.0.0/8 address 233.0.0.0/8 address 9.0.0.0/8 address 80.0.0.0/8 description "" } } ipv6-receive-redirects disable ipv6-src-route disable ip-src-route disable log-martians enable name WAN_IN { default-action drop description "WAN to internal" rule 10 { action accept description "Allow established/related" state { established enable related enable } } rule 20 { action drop description "Drop invalid state" state { invalid enable } } rule 21 { action accept description "Allow IPTV Multicast" destination { group { address-group IPTV-Multicast } } log disable protocol tcp_udp source { address 0.0.0.0/0 } } rule 22 { action accept description "Allow IGMP" log disable protocol igmp } } name WAN_LOCAL { default-action drop description "WAN to router" rule 10 { action accept description "Allow established/related" state { established enable related enable } } rule 20 { action drop description "Drop invalid state" state { invalid enable } } rule 21 { action accept description "Allow IPTV Multicast" destination { group { address-group IPTV-Multicast } } log disable protocol tcp_udp source { address 0.0.0.0/0 } } rule 22 { action accept description "Allow IGMP" log disable protocol igmp } } receive-redirects disable send-redirects enable source-validation disable syn-cookies enable } interfaces { ethernet eth0 { description Local duplex auto speed auto } ethernet eth1 { description Local duplex auto speed auto } ethernet eth2 { description Local duplex auto speed auto } ethernet eth3 { description Local duplex auto speed auto } ethernet eth4 { description Local duplex auto speed auto } ethernet eth5 { duplex auto speed auto vif 10 { address dhcp description Internet dhcp-options { client-option "send dhcp-client-identifier "dslforum.org,Fast5360-sunrise";" default-route update default-route-distance 210 name-server update } firewall { in { name WAN_IN } local { name WAN_LOCAL } } } } loopback lo { } switch switch0 { address 192.168.1.1/24 description Local mtu 1500 switch-port { interface eth0 { } interface eth1 { } interface eth2 { } interface eth3 { } interface eth4 { } vlan-aware disable } } } port-forward { auto-firewall enable hairpin-nat disable rule 1 { description "xbox one nat" forward-to { address 192.168.1.20 port 1-65000 } original-port 1-65000 protocol tcp_udp } wan-interface eth5.10 } protocols { igmp-proxy { interface eth5.10 { alt-subnet 0.0.0.0/0 role upstream threshold 1 } interface switch0 { alt-subnet 0.0.0.0/0 role downstream threshold 1 } } } service { dhcp-server { disabled false global-parameters "option unifi-address code 43 = string;" hostfile-update disable shared-network-name LAN { authoritative enable subnet 192.168.1.0/24 { default-router 192.168.1.1 dns-server 192.168.1.1 lease 86400 start 192.168.1.38 { stop 192.168.1.243 } static-mapping sunrisetv { ip-address 192.168.1.204 mac-address 00:03:xx:xx:xx static-mapping-parameters "option domain-name-servers 212.98.37.128, 194.230.55.99;" static-mapping-parameters "option unifi-address Use your log tv. you can find this with wireshark (windows);" } } } use-dnsmasq disable } dns { forwarding { cache-size 150 listen-on switch0 } } gui { http-port 80 https-port 443 older-ciphers enable } nat { rule 5010 { description "masquerade for WAN" log disable outbound-interface eth5.10 protocol all type masquerade } } ssh { port 22 protocol-version v2 } upnp { listen-on switch0 { outbound-interface eth5.10 } } } system { host-name ubnt login { user ubnt { authentication { encrypted-password $1$zKNoUbAo$gomzUbYvgyUMcD436Wo66. } level admin } } ntp { server 0.ubnt.pool.ntp.org { } server 1.ubnt.pool.ntp.org { } server 2.ubnt.pool.ntp.org { } server 3.ubnt.pool.ntp.org { } } syslog { global { facility all { level notice } facility protocols { level debug } } } time-zone Europe/Zurich } /* Warning: Do not remove the following line. */ /* === vyatta-config-version: "config-management@1:conntrack@1:cron@1:dhcp-relay@1:dhcp-server@4:firewall@5:ipsec@5:nat@3:qos@1:quagga@2:system@4:ubnt-pptp@1:ubnt-util@1:vrrp@1:webgui@1:webproxy@1:zone-policy@1" === */ /* Release version: v1.9.0.4901118.160804.1131 */
And for records and replay it is necessary to activate the RTPS protocol in the nat in order to use the RTP protocol.
Use this command:
sudo modprobe nf_nat_rtsp
And now all work :-)
Big thanks to humba