Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Firewall ports issue (H323. interconnection)

Status
Not open for further replies.

Guilherme1000

Technical User
Apr 17, 2012
270
BR
Hello all,

I have a interconnection between three sites over a H.323 trunk.

we have a firewall and this is causing several communications issues.

I have been looking for ports to enable on the firewall 'cause everytime the IT manager monitors the traffic, a new port has to be open.
then I've come across the H.323 ports problem, 'cause there is a large range of dynamic ports (1024-65535) wich may causes security issues if open.

I know somehow we can use NAT to provide additional security, but Im not sure how does it works.

How can I use it to solve my problem?
 
Do not use NAT....that will just stop H323 working completely. You need to open the ports if you want to use voice across the link, isn't each site secure in it's own right? IT men always overreact when it comes to opening ports on internal links, in reality if they are on the internal network having some open ports on those links is the least of your worries :)



"No problem monkey socks
 
Yes, but the dynamic RTP port range is like 49152 - 53246, not from 1024 so some 48,128 ports fewer than you thought :)



"No problem monkey socks
 
do you know any specific documentation that contains the exactly range of ports?
 
Here is an extract from the installation manual, even shows the traffic direction :)



"No problem monkey socks
 
just a sanity check
you are using a VPN between sites correct?
don't try a direct connection on public IP Addresses it would be a major security risk.

if it is a vpn then there is no point in blocking ports

A Maintenance contract is essential, not a Luxury.
Do things on the cheap & it will cost you dear
 
We know that, but some people who should know better just don't :)



"No problem monkey socks
 
Look if you have H323 ALG on your router to, you need to unchek it if you are ...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top