
8-13
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 8 Inspection for Voice and Video Protocols
MGCP Inspection
MGCP messages are transmitted over UDP. A response is sent back to the source address (IP address
and UDP port number) of the command, but the response may not arrive from the same address as the
command was sent to. This can happen when multiple call agents are being used in a failover
configuration and the call agent that received the command has passed control to a backup call agent,
which then sends the response. The following figure illustrates how you can use NAT with MGCP.
Figure 8-1
Using NAT with MGCP
MGCP endpoints are physical or virtual sources and destinations for data. Media gateways contain
endpoints on which the call agent can create, modify and delete connections to establish and control
media sessions with other multimedia endpoints. Also, the call agent can instruct the endpoints to detect
certain events and generate signals. The endpoints automatically communicate changes in service state
to the call agent.
•
Gateways usually listen to UDP port 2427 to receive commands from the call agent.
•
The port on which the call agent receives commands from the gateway. Call agents usually listen to
UDP port 2727 to receive commands from the gateway.
Note
MGCP inspection does not support the use of different IP addresses for MGCP signaling and RTP data.
A common and recommended practice is to send RTP data from a resilient IP address, such as a loopback
or virtual IP address; however, the ASA requires the RTP data to come from the same address as MGCP
signaling.
1199
3
6
Ci
s
co
C
a
llM
a
n
a
ger
G
a
tew
a
y i
s
told
to
s
end it
s
medi
a
to
209.165.200.2
3
1
(p
u
blic
a
ddre
ss
of the IP Phone)
M
IP
M
M
Ci
s
co
PGW 2200
H.
3
2
3
To P
S
TN
209.165.201.10
209.165.201.11
209.165.201.1
IP
IP
Br
a
nch office
s
RTP to 209.165.201.1
from
209.165.200.2
3
1
RTP to 10.0.0.76
from
209.165.200.2
3
1
10.0.0.76
209.165.200.2
3
1
MGCP
S
CCP
GW
GW
209.165.200.2
3
1
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......