background image

| 37

RADVISION | RADVISION Port Security Reference Guide

 

In addition to the ports listed in 

Table 1-27

, RADVISION MCUs offer configurable security access 

levels enabling and disabling Telnet, FTP, SNMP and ICMP (ping) services, as shown in 

Table 1-27

Media Video Processor for SCOPIA MCU

Table 1-28

 lists the ports supported by the MVP.     

3336

XML (TCP)

MCU version 3 XML API Both

Cannot use MCU 
Conference Control 
web user interface. 
Cannot use version 3 
XML API to control MCU

Conference Control web 
client terminal, iVIEW 
Management Suite or 
third-party controlling 
applications

3337

XML (TCP)

MCU version 3 
Cascading XML API

Both

Cannot cascade 
between two MCUs

Other MCUs

5060 
(configurable)

SIP (TCP/UDP) SIP signaling

Both

Cannot connect SIP 
calls

Any SIP entities

6000-6999 
(configurable)

RTP/RTCP 
(UDP)

RTP/RTCP audio

Both

Cannot 
transmit/receive audio 
stream

Any RTP/RTCP media 
enabled entity

10000-11000 
(configurable)

RTP/RTCP 
(UDP)

RTP media

Both

Cannot 
transmit/receive 
media stream

Any H.323 or SIP media 
enabled entity

Table 1-26

Ports Supported by SCOPIA MCU

Port

Protocol/Use

Functionality

Direction Result of Blocking 

Port on Firewall

Description

Table 1-27

SCOPIA MCU

 Security Modes

Security Mode

Telnet

FTP

SNMP

ICMP (ping)

Standard

Active

Active

Active

Active

High

Inactive

Inactive

Active

Active

Maximum

Inactive

Inactive

Inactive

Inactive

Table 1-28

MVP-supported Ports

Port

Protocol/Use

Functionality

Direction

Result of Blocking 
Port on Firewall

Description

21

FTP (TCP)

Software upgrade and 
video stream recording 

Both

Cannot upgrade 
version

Upgrade Utility

23

Telnet (TCP)

MVP online log

Both

Cannot view logs

Telnet client

161 (for 
future use)

SNMP (UDP)

Configuration and 
status

Both

Cannot configure 
or check the status 
of the MCU via 
SNMP

iVIEW Network Manager, 
iVIEW Management Suite 
or any other SNMP 
manager station

2946

MEGACO (TCP) Control protocol 

between MCU and MVP

Both

MVP cannot 
connect to MCU

MEGACO (H.248) Protocol

Summary of Contents for SyncMaster VC240

Page 1: ...RADVISION Port Security Reference Guide Version 7 6...

Page 2: ...d in this guide is made either by RADVISION Ltd or its agents RADVISION Ltd reserves the right to revise this publication and make changes without obligation to notify any person of such revisions or...

Page 3: ...t on the firewall The following SCOPIA Solution products are described in this document SCOPIA Elite MCU page 4 SCOPIA Video Gateway for Microsoft Lync page 8 SCOPIA ECS Gatekeeper page 9 SCOPIA iVIEW...

Page 4: ...user interfaces In Cannot administer MCU Web client Used for software upgrade 161 SNMP UDP Configuration and status In Cannot configure or check the status of the MCU via SNMP iVIEW Network Manager iV...

Page 5: ...36 XML TCP MCU version 3 XML API Both Cannot use MCU Conference Control web user interface Cannot use version 3 XML API to control MCU Conference Control web client terminal iVIEW Management Suite or...

Page 6: ...edia enabled entity Every call uses two audio ports and six video ports For highly utilized systems above 90 we recommend multiplying by a factor of 1 5 Using its full capacity the SCOPIA Elite 5100 S...

Page 7: ...etval with the parameter mf BasePort to set the lower port value 16384 16984 configure within this range RTP RTCP UDP RTP RTCP audio media upper blade only Both Cannot transmit receive audio media str...

Page 8: ...c Web client 162 SNMP UDP SNMP Trap events Out Cannot receive Traps iVIEW Network Manager iVIEW Management Suite or any other SNMP manager station 1024 1174 configurable H 245 TCP H 245 signaling Both...

Page 9: ...ing Port on Firewall Description 21 FTP TCP File Transfer Protocol for offline viewing of ECS logs and CDRs Both Cannot view logs or retrieve CDR files FTP client CDR server 80 configure via webs ini...

Page 10: ...ey of type REG_SZ called PortMax Give it the value of the highest port number ECS should use 6 Restart ECS There may be other applications on the same computer which altered the global maximum port fo...

Page 11: ...Port on Firewall Description Table 1 7 ECS outgoing ports connections Port Range Protocol Functionality Direction Result of Blocking Port on Firewall Description 23 Telnet TCP Control of Sony endpoint...

Page 12: ...ss book feature Cannot retrieve logs from some devices such as MCM 24 Telnet TCP Polycom endpoint control Optional Out Disables Polycom endpoint control 25 TCP Connect SMTP server for sending email no...

Page 13: ...IEW Management Suite XML API Out iVIEW Management Suite XML cannot communicate with the B2BUA component 3340 TCP TLS Connection to SCOPIA Desktop Out SCOPIA Desktop cannot use iVIEW Management Suite t...

Page 14: ...s port defaults to 80 In 8089 XML TCP SCOPIA PathFinder Server XML API port for connecting to SCOPIA PathFinder Server v7 0 and later Optional Out 11098 11099 TCP Required by the JBoss application ser...

Page 15: ...uilt in H 460 functionality thereby avoiding the need for a SCOPIA PathFinder Client If an H 323 endpoint located in a partner company does not have H 460 capabilities it must communicate via the SCOP...

Page 16: ...tekeeper 2776 UDP H 460 19 Multiplex Media Channel Client to SCOPIA PathFinder Server H 460 18 endpoints cannot set up logical channels media exchange of calls which traverse the firewall using H 460...

Page 17: ...ndpoints Any H 323 entity using a Q 931 signaling in DPA mode 4000 5000 configure within this range TCP UDP Direct Public Access DPA for H 323 call signaling control and media traversal ExternalH 323...

Page 18: ...SCOPIA PathFinder Server Port Range Protocol Functionality Direction Result of Blocking Port on Firewall Recipient Client or Server Type 53 DNS UDP Query DNS for domain per call SCOPIA PathFinder Serv...

Page 19: ...signaling and call control SCOPIA PathFinder Server to H 323 entity Cannot setup connect DPA mode calls with external SCOPIA PathFinder Server The approximate number of ports required is the number of...

Page 20: ...ent Port Range Protocol Functionality Direction Result of Blocking Port on Firewall Recipient Client or Server Type 3089 TCP and UDP PathFinder tunneling service SCOPIAPathFinder Client to Server SCOP...

Page 21: ...o the internal network Port Range Protocol Direction Severity Functionality 80 TCP Incoming Optional Used to access the SCOPIA Desktop Server web portal via a web browser The alternative is to configu...

Page 22: ...ployments where the SCOPIA Desktop Server works in conjunction with the MCU only this port range is used for establishing connection from the SCOPIA Desktop Server to MCU In deployments where the SCOP...

Page 23: ...he internal network Port Range Protocol Direction Severity Functionality Table 1 13 Ports to and from the SCOPIA Desktop Server connected to the public internet Port Range Protocol Direction Severity...

Page 24: ...ough the SCOPIA Desktop Server Table 1 15 STUN Server port required for access by SCOPIA Desktop Client Port Range Protocol Direction Severity Functionality 3478 UDP Incoming Optional The STUN access...

Page 25: ...ic through standard HTTP Some firewalls may inspect traffic on port 80 and not allow the tunneled RTSP RTP on that port We therefore recommend using the QuickTime standard port 7070 as the alternate T...

Page 26: ...o edit this range 1 Navigate to C Program Files Radvision SCOPIA Desktop ConfSrv 2 Edit the file config val 3 Locate the 1 system section At the bottom of that section add two lines 2 portFrom lowest...

Page 27: ...tunneled via TCP port 443 and performance will not be optimal At full capacity the SCOPIA XT1009 requires 76 ports Limit the range of the of the multimedia ports in the SCOPIA Desktop XT Server Admin...

Page 28: ...annot send SNMP events Interface to iVIEW Network Manager or any other SNMP manager station 1718 H 225 0 RAS UDP H 323 call signaling to a GK for Gatekeeper Automatic Discovery procedure Out to the mu...

Page 29: ...not discover the presence of a firewall or NAT only manual configuration available Discover the presence of a firewall or NAT and the public IP address The range can be modified by the user interface...

Page 30: ...er 80 HTTP TCP Open APIs and remote software uprades either via the web interface or via iVIEW Management Suite Both Web server and open APIs do not function Web based software upgrades will not funct...

Page 31: ...does not communicate with the unit Internal use 5060 TCP UDP SIP SIP signaling Both Cannot connect SIP calls Any SIP entity 3230 3251 configurable UDP RTP RTCP RTP media Both Cannot transmit receive...

Page 32: ...9 H 245 TCP H 245 Both No H 245 H 323 entity 1503 TCP T 120 data collaboration Both Cannot establish a T 120 connection to from the Gateway Any T 120 endpoint 1619 RAS UDP IVR RAS receiving Gatekeeper...

Page 33: ...orts Incoming connections continued Port Range Protocol Functionality Direction Result of Blocking Port on Firewall Description Table 1 22 SCOPIA Gateway supported ports Outgoing Connections Port Rang...

Page 34: ...ents Out Cannot receive Traps iVIEW Network Manager iVIEW Management Suite or any other SNMP manager station 443 HTTPS TCP in use Secure web interface Both Cannot administer the Gateway 1024 4999 H 24...

Page 35: ...ion Table 1 25 MVP M II supported Ports Port Range Protocol Functionality Direction Result of Blocking Port on Firewall Description 21 FTP TCP Software upgrade and video stream recording Both Cannot u...

Page 36: ...EW Network Manager iVIEW Management Suite or any other SNMP manager station 162 SNMP UDP SNMP Trap events Out Cannot receive Traps iVIEW Network Manager iVIEW Management Suite or any other SNMP manage...

Page 37: ...dia enabled entity 10000 11000 configurable RTP RTCP UDP RTP media Both Cannot transmit receive media stream Any H 323 or SIP media enabled entity Table 1 26 Ports Supported by SCOPIA MCU Port Protoco...

Page 38: ...Cannot work with different fonts Font client software 10000 10575 configurable from version 2 5 RTP RTCP UDP RTP RTCP media Both Cannot transmit receive media stream Any RTP RTCP media enabled entity...

Page 39: ...d wireless for high definition video conferencing systems innovative converged mobile services and highly scalable video enabled desktop platforms on IP 3G and emerging next generation networks For mo...

Reviews: