Firewall Traversal Configuration Overview - Cisco TelePresence Administrator's Manual

Video communication server
Hide thumbs Also See for TelePresence:
Table of Contents

Advertisement

Firewall traversal
Any H.323 or SIP call leg to/from a VCS Control through a traversal zone configured to use Assent.
n
Any H.323 call leg to/from a VCS Control through a traversal server zone configured to use H460.19 in
n
demultiplexing mode
H.323 call legs between a VCS Expressway and an Assent or H.460.19 enabled endpoint
n
The VCS Expressway uses non-demultiplexed media for call legs directly to/from SIP endpoints (that is
endpoints which do not support Assent or H.460.19), or if the traversal server zone is not configured to use
H.460.19 in demultiplexing mode.
Media demultiplexing ports on the VCS Expressway are allocated from the general range of traversal media
ports. This applies to all RTP/RTCP media, regardless of whether it is H.323 or SIP. The default media port
range of 36000 to 59999 applies to new installations of X8.1 or later. The first 2 ports in the range are used for
multiplexed traffic only (with Large VM deployments the first 12 ports in the range – 36000 to 36011 – are
used). The previous default range of 50000 - 54999 still applies to earlier releases that have upgraded to X8.1.
For example, in a SIP call from within an enterprise to an endpoint at home through a VCS Control/VCS
Expressway pair, the only demultiplexing that would occur would be on the VCS Expressway ports facing
the VCS Control:
Enterprise
endpoint
RTP ports
RTCP ports
However, an H.323 call from within an enterprise to an Assent capable H.323 endpoint at home through the
same VCS Control/VCS Expressway would perform demultiplexing on both sides of the VCS Expressway:
Enterprise
endpoint
RTP ports
RTCP ports
If the VCS Expressway has Advanced Networking, it will still use the same port numbers as described
above, but they will be assigned to the internal and external IP addresses.

Firewall traversal configuration overview

This section provides an overview to how the VCS can act as a traversal server or as a traversal client.
VCS as a firewall traversal client
The VCS can act as a firewall traversal client on behalf of SIP and H.323 endpoints registered to it, and any
systems that are neighbored with it. To act as a firewall traversal client, the VCS must be configured with
information about the systems that will act as its firewall traversal server.
Cisco VCS Administrator Guide (X8.1.1)
VCS Control
Non-
Non-
demuxed
demuxed
36002 36004
36003 36005
VCS Control
Non-
Non-
demuxed
demuxed
36002 36004
36003 36005
VCS Expressway
Demuxed Non-
demuxed
36000 36002
36001 36003
VCS Expressway
Demuxed Demuxed
36000 36000
36001 36001
About firewall traversal
Home
endpoint
Home
endpoint
Page 55 of 507

Advertisement

Table of Contents
loading

This manual is also suitable for:

Telepresence x8.1.1

Table of Contents