7.9 Media hairpinning
103
Example: Two SIP telephones in the LAN
Let us suppose two SIP telephones are located in the LAN. These telephones authenticate at
a SIP server in the Internet. The parameters may be as follows:
•
IP addresses of the phones:
192.168.1.100
and
192.168.1.101
•
Public IP address of the firewall:
195.192.33.1
•
SIP server:
sip.server.com
For the telephones, define corresponding traffic rules — see chapter
(as apparent from
figure
, simply specify
Source
of the
Full cone NAT
traffic rule by IP address of the other
telephone).
Both telephones will be registered on SIP server under the firewall’s public IP address
(
195.192.33.1
). If these telephones establish mutual connection, data packets (for voice
transmission) from both telephones will be sent to the firewall’s public IP address (and to the
port of the other telephone). Under normal conditions, such packets would be dropped. How-
ever,
WinRoute
is capable of using a corresponding record in the NAT table to recognize that
a packet is addressed to a client in the local network. Then it translates the destination IP
address and sends the packet back to the local network (as well as in case of port mapping).
This ensures that traffic between the two phones will work correctly.
Note:
1.
Hairpinning requires traffic between the local network and the Internet being allowed (be-
fore processed by the firewall, packets use a local source address and an Internet destina-
tion address — i.e. this is an outgoing traffic from the local network to the Internet). In
default traffic rules created by the wizard (see chapter
), this condition is met by the
NAT
rule.
2.
In principle, hairpinning does not require that
Full cone NAT
is allowed (see chapter
However, in our example,
Full cone NAT
is required for correct functioning of the
SIP
protocol.
Содержание KERIO WINROUTE FIREWALL 6
Страница 1: ...Kerio WinRoute Firewall 6 Administrator s Guide Kerio Technologies s r o...
Страница 157: ...12 3 Content Rating System Kerio Web Filter 157 Figure 12 7 Kerio Web Filter rule...
Страница 189: ...14 4 URL Groups 189 Description The item s description comments and notes for the administrator...
Страница 247: ...19 4 Alerts 247 Figure 19 14 Details of a selected event...
Страница 330: ...Chapter 23 Kerio VPN 330 Figure 23 55 The Paris filial office VPN server configuration...
Страница 368: ...368...