Chapter 7. Firewall and Client Configuration
The Firewall
The firewall to which the Telecommuting Module is connected should have the following
configuration:
SIP over UDP
•
Let through UDP traffic between the Internet (all high ports) and the Telecommuting
Module (port 5060). You must allow traffic in both directions.
•
Let through UDP traffic between the Internet (all high ports) and the Telecommuting
Module (the port interval for media streams which was set on the
Basic Settings
page).
You must allow traffic in both directions.
•
Let through UDP traffic between the Telecommuting Module (all high ports) and the In-
ternet (port 53). You must allow traffic in both directions. This enables the Telecommuting
Module to make DNS queries to DNS servers on the Internet. If the DNS server is located
on the same network as the Telecommuting Module, you don’t have to do this step.
•
NAT between the Telecommuting Module and the Internet must not be used.
SIP over TCP/TLS
•
Let through TCP traffic between the Internet (all high ports) and the Telecommuting Mod-
ule (ports 1024-32767). You must allow traffic in both directions.
•
Let through UDP traffic between the Internet (all high ports) and the Telecommuting
Module (the port interval for media streams which was set on the
Basic Settings
page).
You must allow traffic in both directions.
•
Let through UDP traffic between the Telecommuting Module (all high ports) and the In-
ternet (port 53). You must allow traffic in both directions. This enables the Telecommuting
Module to make DNS queries to DNS servers on the Internet. If the DNS server is located
on the same network as the Telecommuting Module, you don’t have to do this step.
•
NAT between the Telecommuting Module and the Internet must not be used.
SIP clients
The SIP clients on the internal network should have the Telecommuting Module’s IP address
on that network as their outgoing SIP proxy and registrar.
Other
The DNS server used must have a record for the SIP domain, which states that the Telecom-
muting Module handles the domain, or many SIP clients won’t be able to use it (if you don’t
use plain IP addresses as domains).
The Standalone type
Using the Standalone type, the network configuration should look like this:
59
Содержание BETA
Страница 1: ...3Com VCX IP Telecommuting Module Getting started Guide ...
Страница 2: ......
Страница 4: ......
Страница 6: ...ii ...
Страница 8: ......
Страница 22: ...Chapter 3 Installing 3Com VCX IP Telecommuting Module 14 ...
Страница 24: ......
Страница 42: ...Chapter 4 Network Configuration 34 ...
Страница 64: ...Chapter 6 Administration of the Telecommuting Module 56 ...
Страница 70: ......