Chapter 16 ALG
ZyWALL USG 50-H User’s Guide
275
• The SIP ALG allows UDP packets with a specified port destination to pass through.
• The ZyWALL allows SIP audio connections.
• You do not need to use STUN (Simple Traversal of User Datagram Protocol (UDP)
through Network Address Translators) for VoIP devices behind the ZyWALL when you
enable the SIP ALG.
Peer-to-Peer Calls and the ZyWALL
The ZyWALL ALG can allow peer-to-peer VoIP calls for both H.323 and SIP. You must
configure the firewall and virtual server (port forwarding) to allow incoming (peer-to-peer)
calls from the WAN to a private IP address on the LAN (or DMZ).
VoIP Calls from the WAN with Multiple Outgoing Calls
When you configure the firewall and virtual server (port forwarding) to allow calls from the
WAN to a specific IP address on the LAN, you can also use policy routing to have H.323 (or
SIP) calls from other LAN or DMZ IP addresses go out through a different WAN IP address.
The policy routing lets the ZyWALL correctly forward the return traffic for the calls initiated
from the LAN IP addresses.
For example, you configure the firewall and virtual server to allow LAN IP address
A
to
receive calls from the Internet through WAN IP address
1
. You also use a policy route to have
LAN IP address
A
make calls out through WAN IP address
1
. Configure another policy route
to have H.323 (or SIP) calls from LAN IP addresses
B
and
C
go out through WAN IP address
2
. Even though only LAN IP address
A
can receive incoming calls from the Internet, LAN IP
addresses
B
and
C
can still make calls out to the Internet.
Figure 212
VoIP Calls from the WAN with Multiple Outgoing Calls
VoIP with Multiple WAN IP Addresses
With multiple WAN IP addresses on the ZyWALL, you can configure different firewall and
virtual server (port forwarding) rules to allow incoming calls from each WAN IP address to go
to a specific IP address on the LAN (or DMZ). Use policy routing to have the H.323 (or SIP)
calls from each of those LAN or DMZ IP addresses go out through the same WAN IP address
that calls come in on. The policy routing lets the ZyWALL correctly forward the return traffic
for the calls initiated from the LAN IP addresses.
Содержание ZyWall USG 50-H Series
Страница 2: ......
Страница 10: ...Safety Warnings ZyWALL USG 50 H User s Guide 10...
Страница 28: ...Table of Contents ZyWALL USG 50 H User s Guide 28...
Страница 30: ...30...
Страница 34: ...Chapter 1 Introducing the ZyWALL ZyWALL USG 50 H User s Guide 34...
Страница 40: ...Chapter 2 Features and Applications ZyWALL USG 50 H User s Guide 40...
Страница 92: ...Chapter 5 Configuration Basics ZyWALL USG 50 H User s Guide 92...
Страница 130: ...Chapter 6 Tutorials ZyWALL USG 50 H User s Guide 130...
Страница 146: ...146...
Страница 156: ...Chapter 8 Interface ZyWALL USG 50 H User s Guide 156 Figure 128 Network Interface Ethernet Edit wan2...
Страница 157: ...Chapter 8 Interface ZyWALL USG 50 H User s Guide 157 Figure 129 Network Interface Ethernet Edit lan1...
Страница 208: ...Chapter 8 Interface ZyWALL USG 50 H User s Guide 208 Figure 161 Network Interface Bridge Add...
Страница 224: ...Chapter 9 Trunks ZyWALL USG 50 H User s Guide 224...
Страница 250: ...Chapter 12 Zones ZyWALL USG 50 H User s Guide 250...
Страница 280: ...Chapter 16 ALG ZyWALL USG 50 H User s Guide 280...
Страница 286: ...Chapter 17 IP MAC Binding ZyWALL USG 50 H User s Guide 286...
Страница 287: ...287 PART III Firewall Firewall 289...
Страница 288: ...288...
Страница 304: ...Chapter 18 Firewall ZyWALL USG 50 H User s Guide 304...
Страница 306: ...306...
Страница 313: ...Chapter 19 IPSec VPN ZyWALL USG 50 H User s Guide 313 Figure 238 VPN IPSec VPN VPN Connection Edit IKE...
Страница 356: ...Chapter 21 SSL User Screens ZyWALL USG 50 H User s Guide 356...
Страница 358: ...Chapter 22 SSL User Application Screens ZyWALL USG 50 H User s Guide 358...
Страница 368: ...Chapter 24 L2TP VPN ZyWALL USG 50 H User s Guide 368...
Страница 394: ...Chapter 25 L2TP VPN Example ZyWALL USG 50 H User s Guide 394...
Страница 395: ...395 PART V Application Patrol Application Patrol BWM 397...
Страница 396: ...396...
Страница 421: ...421 PART VI Anti X ADP 423...
Страница 422: ...422...
Страница 429: ...Chapter 27 ADP ZyWALL USG 50 H User s Guide 429 Figure 359 Profiles Traffic Anomaly...
Страница 432: ...Chapter 27 ADP ZyWALL USG 50 H User s Guide 432 Figure 360 Profiles Protocol Anomaly...
Страница 440: ...Chapter 27 ADP ZyWALL USG 50 H User s Guide 440...
Страница 442: ...442...
Страница 462: ...Chapter 29 Addresses ZyWALL USG 50 H User s Guide 462...
Страница 474: ...Chapter 31 Schedules ZyWALL USG 50 H User s Guide 474...
Страница 484: ...Chapter 32 AAA Server ZyWALL USG 50 H User s Guide 484...
Страница 506: ...Chapter 34 Certificates ZyWALL USG 50 H User s Guide 506...
Страница 510: ...Chapter 35 SSL Application ZyWALL USG 50 H User s Guide 510...
Страница 511: ...511 PART VIII System System 513...
Страница 512: ...512...
Страница 552: ...552...
Страница 568: ...Chapter 38 Logs ZyWALL USG 50 H User s Guide 568 Figure 464 Maintenance Log Log Setting Edit System Log...
Страница 584: ...Chapter 40 Diagnostics ZyWALL USG 50 H User s Guide 584...
Страница 586: ...Chapter 41 Reboot ZyWALL USG 50 H User s Guide 586...
Страница 596: ...Chapter 43 Product Specifications ZyWALL USG 50 H User s Guide 596...
Страница 598: ...598...
Страница 636: ...Appendix A Log Descriptions ZyWALL USG 50 H User s Guide 636...
Страница 640: ...Appendix B Common Services ZyWALL USG 50 H User s Guide 640...
Страница 646: ...Appendix C Importing Certificates ZyWALL USG 50 H User s Guide 646...