RE: Question about NATed endpoints

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



All true. From the gatekeeper point of view all H.323 messages
should contain only public IPs. An H.323 aware firewall/NAT system
should keep all IP/port mappings and perform H.323 message translation
transparently to the endpoint and gatekeeper.

On Tue, 2004-07-06 at 20:32, James Lertora wrote:
> Ok, so let me get this straight.
> 
> If the firewall is truly H.323 aware then I shouldn't see the private IP
> addr
> of the VoIP gateway when registered to the GK. True / False
> 
> If the firewall is truly H.323 aware then when an inbound setup message is 
> seen it should open the appropriate (TCP/UDP) sessions for the NATed VoIP
> gateway that is registered with the GK. True/False 
> 
> Thanks again this is very helpful.
> 
> -Jamie
>   
> 
> James Lertora
> Technical Support
> Patton Electronics
> mailto:support@xxxxxxxxxx
>  
> New!
> Enhanced Warranty and Advanced Replacements are now available for RAS
> products. 
> Join the Patton users group and learn how others are using the Patton RAS. 
>  
> See www.patton.com/support http://www/patton.com/support  for more
> information.
>  
> Software/Drivers -->  http://upgrades.patton.com
> 
> 
> > -----Original Message-----
> > From: openh323gk-users-admin@xxxxxxxxxxxxxxxxxxxxx 
> > [mailto:openh323gk-users-admin@xxxxxxxxxxxxxxxxxxxxx] On 
> > Behalf Of Michal Zygmuntowicz
> > Sent: Tuesday, July 06, 2004 12:47 PM
> > To: openh323gk-users@xxxxxxxxxxxxxxxxxxxxx
> > Subject: Re:  Question about NATed endpoints
> > 
> > 
> > If your firewall is H.323 aware, then the gatekeeper will
> > never see the endpoint private IP, as the firewall provides 
> > proper address translation. In your case (non H.323 aware 
> > firewall), you need to forward proper TCP/UDP ports on the 
> > firewall or to put the endpoint in DMZ.
> > 
> > On Tue, 2004-07-06 at 17:56, James Lertora wrote:
> > > Does anybody have an idea how the support on the GK for NATed 
> > > endpoints works ? When I get a registration for a gateway that is 
> > > NATed it registers with the private IP
> > > and if I force an unregistration I will see the public IP 
> > from which the
> > > VoIP endpoint
> > > originated. When sending a setup message, if port 1720 TCP 
> > is open and using
> > > an H.323 aware 
> > > firewall, how does the set up message make it to the VoIP endpoint ?
> > >  
> > > 
> > > James Lertora
> > > Technical Support
> > > Patton Electronics
> > > mailto:support@xxxxxxxxxx




-------------------------------------------------------
This SF.Net email sponsored by Black Hat Briefings & Training.
Attend Black Hat Briefings & Training, Las Vegas July 24-29 - 
digital self defense, top technical experts, no vendor pitches, 
unmatched networking opportunities. Visit www.blackhat.com

_______________________________________________________

List: Openh323gk-users@xxxxxxxxxxxxxxxxxxxxx
Archive: http://sourceforge.net/mailarchive/forum.php?forum_id=8549
Homepage: http://www.gnugk.org/

[Index of Archives]     [SIP]     [Open H.323]     [Gnu Gatekeeper]     [Asterisk PBX]     [ISDN Cause Codes]     [Yosemite News]

  Powered by Linux