
Caution:
Systems deployed outside a firewall are potentially vulnerable to unauthorized access. Visit
the Polycom Security section of the Knowledge Base at
for timely security
information. You can also register to receive periodic updates and advisories.
Configure the System for H.460 Firewall/NAT Traversal
H.460 firewall/NAT traversal can be necessary if you’re calling with a cloud-based conferencing service or
your system is outside a corporate network (for example, a home office).
Make sure you register your system with a network device that supports H.460.18 and H.460.19
standards (for example, a RealPresence Access Director system or a Polycom VBP device).
Procedure
1.
In the system web interface, go to
Network
>
Primary Network
.
2.
Go to
Firewall
.
3.
Make sure that the
Enable H.460 Firewall Traversal
check box is selected.
4.
Verify the firewalls that you traverse allow your system to use outbound TCP and UDP
connections.
▪ Firewalls with a stricter rule set must allow the system to use at least the following outbound
TCP and UDP ports: 1720 (TCP), 14085-15084 (TCP), 1719 (UDP), and 16386-25386
(UDP).
▪ Firewalls must allow inbound traffic to the TCP and UDP ports used for outbound traffic.
5.
Configure the following settings:
Setting
Description
Fixed Ports
Defines which TCP and UDP ports your system uses
for firewall traversal.
Enable this option if your firewall isn’t H.323
compatible. The system assigns a port range starting
with the TCP and UDP ports you specify (port 3230 is
where the range begins by default).
Note: For the fixed ports you configure, you must
open the corresponding ports on your firewall.
For H.323, open TCP port 1720. For SIP, open
UDP port 5060, TCP 5060, or TCP 5061
depending on if you’re using UDP, TCP, or
TLS, respectively, as the SIP transport
protocol.
Disable this option if your firewall is H.323 compatible
or the system isn’t behind a firewall.
Securing the System
48