
22-55
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
H.323 Inspection
The media negotiated between these endpoints have an LCN of 258 with the foreign RTP IP address/port
pair of 172.30.254.203/49608 and an RTCP IP address/port of 172.30.254.203/49609 with a local RTP
IP address/port pair of 10.130.56.3/49608 and an RTCP port of 49609.
The second LCN of 259 has a foreign RTP IP address/port pair of 172.30.254.203/49606 and an RTCP
IP address/port pair of 172.30.254.203/49607 with a local RTP IP address/port pair of
10.130.56.3/49606 and RTCP port of 49607.
Monitoring H.323 RAS Sessions
The
show h323-ras
command displays information for H.323 RAS sessions established across the
FWSM between a gatekeeper and its H.323 endpoint. Along with the
debug h323 ras event
and
show
local-host
commands, this command is used for troubleshooting H.323 RAS inspection engine issues.
The
show h323-ras
command displays connection information for troubleshooting H.323 inspection
engine issues. The following is sample output from the
show h323-ras
command.
hostname#
show h323-ras
Total: 1
GK Caller
172.30.254.214 10.130.56.14
This output shows that there is one active registration between the gatekeeper 172.30.254.214 and its
client 10.130.56.14.
H.323 GUP Support
The H.323-GUP feature is used for creation of the secondary channel for the H.323-GUP connection
from the H.323-RAS connection, and for translation (NAT) of the embedded addresses in the GUP
messages. It enables Gatekeepers to communicate with each other through the firewall.
You do not need to enable H.323-GUP explicitly. To utilize this feature, enable H.323-RAS inspection
with the appropriate access list (allowing UDP port 1719).
Limitations:
•
H.323-GUP inspection is relevant only in topologies where the Cisco Gatekeeper devices are
employed because GUP is a Cisco proprietary protocol.
•
Dynamic NAT and dynamic PAT are not supported in H.323 GUP inspection.
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......