TD 92326GB
2009-03-10 / Ver. E
Installation and Operation Manual
VoIP Gateway
165
B.1
NAT and Firewalls
If a firewall is protecting your network from the Internet and you want to establish
connections between the VoIP Gateway and remote terminals via the Internet, ensure that
the firewall is correctly configured.
Firewalls usually have two functions. They control access to equipment and areas within
your network and they implement IP address translation in networks that do not have
their own regular network address, so called NAT (Network Address Translation). NAT can
also be implemented by routers.
In connection with VoIP, both functions require a detailed analysis of the data stream in
order to be implemented. The analysis must be performed by the firewall or router
firmware. Please refer to the documentation of the product you are using.
If the product does not support
H.323 firewalling
there are several ways of proceeding:
• The firewall can be configured to allow all required data to and from the VoIP Gateway.
This solution is usually not well received by system administrators, but it does not
present a security problem since the VoIP Gateway does not perform any services other
than “voice over IP”. No security gaps are caused in the network by opening the path
to and from the VoIP Gateway.
• If none of the H.323 devices (whose data is to cross the firewall) are third party
products, the number of ports to be released can be restricted. For this
H.245
The VoIP Gateway loses its
configuration after it has
been disconnected from
the power supply.
The configuration has not
been saved in the
nonvolatile memory.
Save the configuration to non-
volatile memory after any
successful change, see
Change and Save the
Configuration
The VoIP Gateway is
connected to the network
behind a “firewall” and the
configuration is not
working
The firewall does not
allow any access to the
VoIP Gateway.
In the firewall, enable the
services tcp/23 (telnet) and tcp/
80 (http) for the VoIP Gateway.
The VoIP Gateway is
connected to the network
behind a “firewall” and no
connections can be
established to other VoIP
devices.
The firewall does not
support the H.323
protocol.
Activate “H.323 Firewalling” in
your firewall software and if
necessary “H.323 NAT” too.
Refer to your firewall
documentation for this purpose.
Refer to section
You are using the
“gwload.exe” utility.
Uploading of new firmware
fails, although the VoIP
Gateway is found.
Your computer's arp-
cache contains incorrect
information.
Clear the computer's arpcache.
To do this with a Windows PC,
use the command arp –d ip-addr.
Fax transmissions are
interrupted.
T.38 is not authorised in
the gateway definition.
Activate the T.38 protocol, see
Fax transmissions are
interrupted, in particular
with lengthy faxes.
The gateway and PBX to
which the fax machine is
connected, have not a
synchronous ISDN clock.
Provide correct clock
synchronisation, see