| 18
RADVISION | RADVISION Port Security Reference Guide
Note:
When an H.323 endpoint (or other H.323 entity) within the enterprise connects to the SCOPIA
PathFinder Server in the DMZ via the internal firewall (
Figure 1-2
on page 18), you need to install
a SCOPIA PathFinder Client within the enterprise, or use H.460-enabled endpoints. Otherwise you
must open the internal firewall to the SCOPIA PathFinder Server (1024-65535).
Figure 1-2
Contacting SCOPIA PathFinder Server from within the enterprise
Table 1-10
lists the outbound ports supported by SCOPIA PathFinder Server.
Table 1-10
Outbound ports supported by SCOPIA PathFinder Server
Port Range
Protocol
Functionality
Direction
Result of Blocking Port on
Firewall
Recipient Client
or Server Type
53
DNS (UDP)
Query DNS for
domain per call
SCOPIA
PathFinder
Server to
another server
Cannot support domain
name calls and dialing by
URI.
DNS server
1719
(configurable)
RAS (UDP)
Communication
with gatekeeper
SCOPIA
PathFinder
Server to the
main
gatekeeper
Cannot relay H.323
communication.
Gatekeeper
1720
TCP
H.323 IP call
signaling
SCOPIA
PathFinder
Server to
external SCOPIA
PathFinder
Server
No signaling capabilities:
guest users cannot dial into
internal endpoints
Any H.323 entity
using a Q.931
signaling in DPA
mode
3089
TCP
Neighbor server
signaling and media
connection
SCOPIA
PathFinder
Server to
another Server
Cannot connect to neighbor
server.
PathFinder Server