Recommended configuration for firewall traversal
When a VCS Expressway is neighbored with a VCS Control for firewall traversal, you should typically set
Calls to unknown IP addresses
to
Indirect
on the VCS Control and
Direct
on the VCS Expressway. When
a caller inside the firewall attempts to place a call to an IP address outside the firewall, it will be routed as
follows:
1. The call will go from the endpoint to the VCS Control with which it is registered.
2. As the IP address being called is not registered to that VCS, and its
Calls to unknown IP addresses
setting is
Indirect
, the VCS will not place the call directly. Instead, it will query its neighbor VCS
Expressway to see if that system is able to place the call on the VCS Control’s behalf. Note that you need
to configure a search rule for
Any IP Address
against the traversal server zone.
3. The VCS Expressway receives the call and because its
Calls to unknown IP addresses
setting is
Direct
, it will make the call directly to the called IP address.
Cisco VCS Administrator Guide (X8.1.1)
Page 202 of 507
Dial plan and call processing
Dialing by IP address