SROS Command Line Interface Reference Guide
Global Configuration Mode Command Set
5991-2114
© Copyright 2007 Hewlett-Packard Development Company, L.P.
441
ip rtp firewall-traversal [policy-timeout
<seconds>
]
Use the
ip rtp firewall-traversal
command to enable dynamic firewall traversal capability for
RTP-based traffic, allowing deep packet inspection of SDP packets to occur so RTP will correctly traverse
NAT in the firewall. This will open the proper ports dynamically for the RTP traffic.
Syntax Description
policy-timeout
<seconds>
Optional. Specifies timeout period allowed for inactive RTP sessions to
remain in the firewall. Range is 1 to 4,294,967,295.
Default Values
By default, the RTP dynamic firewall traversal is disabled and the default policy timeout period is 45
seconds.
Functional Notes
SIP uses the Session Description Protocol (SDP) to format the SIP message body in order to negotiate a
Real-time Transport Protocol (RTP)/Real-time Transport Control Protocol (RTCP) connection between two
or more User Agents (UAs). The ports used for this will always be selected in a pair, with the even port
used for RTP and the odd port for RTCP.
The SIP ALG (enabled using the
ip firewall alg sip
) configures the firewall to examine the ALL SIP
packets it identifies and maintain knowledge of SIP transmissions on the network. Since SIP packet
headers include port information for the call setup, the ALG must intelligently read the packets and
remember the information.
For a full SIP implementation, dynamic firewall traversal for RTP traffic must also be enabled using the
ip
rtp firewall-traversal
command. This allows the firewall to open the proper ports for the RTP traffic
between UAs.
For more details on SIP functionality in the SROS, refer to the
Functional Notes
and
Technology Review
sections of the
ip firewall alg [ftp | h323 | h323 timeout | pptp | sip]
.
Usage Examples
The following example enables dynamic firewall traversal and sets the policy timeout period at
60
seconds:
ProCurve(config)#
ip rtp firewall-traversal policy-timeout 60
Содержание ProCurve Secure 7102dl
Страница 2: ......
Страница 3: ...SROS Command Line Interface Reference Guide Software Version J 08 03 September 2007 61195880L1 35H ...
Страница 1454: ......