NETWORK SECURITY
Firewall Ports to Open
Installation Manual August, 2011
NETWORK SECURITY
After the IP
edge
system is installed, the SIP Trunks and/or Remote IP
Telephones working, it is the responsibility of the installer and system user
to setup the firewall to help prevent unauthorized access.
While this can be accomplished in many ways one basic method is using
lists. For example; Cisco devices can be configured using ACL’s (Access
control lists) and, in Sonicwall by setting up rules to Deny or allow specific
IP addresses, or other means in other firewalls.
For example; the firewall configuration could be set to only allow specific
IP’s. Contact your SIP Provider for a list of the IP’s their Signaling and
Media will use. For a remote IPT add the static IP to the safe list, if the
remote IPT is a dynamic IP you could list a range ips for use by the IPT, or
even better require the use of a hardware VPN for all remote phones and
software VPN for softphones that are roaming.
Any specific programming of firewall rules to secure access to the
network and IPedge server are the responsibility of the installing dealer
and/or customer and vary by the needs and level of protection determined
by the customer’s IT department. Toshiba technical support does not
assume responsibility to provide specific commands or to verify a network
or specific IPedge server is secure.
FIREWALL SETUP
This section discusses firewall setup. Be sure that all of the port numbers
from Step 2 above are programmed into the fire wall, pointing to the
IP
edge
server IP address.
Firewall Ports to Open
The following lists are the firewall ports that must be open for the IP
edge
system to function behind a firewall.
All Systems
These firewall ports must be open for every system:
•
1718 to 1719 UDP (Remote IP Telephone set registration)
•
21000 to 22999 UDP (Remote IP or SIP telephone audio)
•
2944 to 2944 TCP (Remote IP Telephone MEGACO signaling)
•
80 TCP (Redirects to 8080)
•
8080 TCP (Enterprise Manager)
•
10000 TCP (Webmin)
SIP Trunks and Stations
•
5060 UDP (SIP trunks or SIP telephones outside the firewall)
HTTPS
•
443 TCP and 8443 TCP (HTTPS)
Unifier
•
1100 to 1105 TCP (Systems connecting with unifier)
Meeting
•
8444 TCP (Meeting)
•
1935 TCP (Meeting)
•
1945 TCP (Meeting)
•
443 TCP (Meeting and/or HTTPS)
Net Server
•
8768 TCP (Net Server)
Summary of Contents for IP edge EC
Page 1: ...TOSHIBA Telecommunication Systems Division Installation Manual Title Page August 2011 ...
Page 18: ...This page is intentionally left blank ...
Page 32: ...This page is intentionally left blank ...
Page 78: ...This page is intentionally left blank ...
Page 82: ...This page is intentionally left blank ...
Page 92: ...This page is intentionally left blank ...
Page 96: ...This page is intentionally left blank ...
Page 100: ...This page is intentionally left blank ...
Page 144: ...This page is intentionally left blank ...
Page 205: ...THIS IS THE END OF THE DOCUMENT ...
Page 206: ......