Re: Multisite/Firewall/Configuration Question

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Florian,

with GnuGk you should be able to tunnel out older endpoints not
supporting firewall traversal or RTP multiplexing in configurations
where an endpoint capable of traversal would be able to connect.

In your diagram there are 2 firewalls between GnuGk and the VCS and
that might be an issue. Usually you need one gatekeeper per firewall to
traverse.

Such a traversal zone setup is sketched on the website:
http://www.gnugk.org/gnugk-traversal.html

Regards,
Jan

-- 
Jan Willamowius, Founder of the GNU Gatekeeper Project
EMail  : jan@xxxxxxxxxxxxxx
Website: http://www.gnugk.org
Support: http://www.willamowius.com/gnugk-support.html


Florian von Kurnatowski wrote:
> Jan, All,
> 
> first of all - Happy New Year to Everyone!
> 
> I have a configuration task at hand and I was just wondering whether anyone had done this before and would have a sample config to start with. The issue is to connect two sites via a VPN. One site has a Tandberg Cisco VCS Expressway unit available to manage inbound traffic. That site's firewall is very restrictive, only allows inbound traffic and does not support port range setups by policy, so all inbound traffic would require to use RTP Multiplexing as well as H.460 firewall traversal with keep alive connections. The primary purpose of that VCS is to support directly-registered endpoints, and it works fine using both Tandberg C-Series equipment (using proprietary Assent protocols) as well as Polycom HDX using H.460.18/19.
> 
> Now, the new site to be connected has
> - multiple systems
> - old systems not supporting RTP multiplexing (e.g. Polycom VSX)
> - does some further routing elsewhere
> 
> So I thought of using GnuGK for the purpose, understanding that it could act as a local gatekeeper at the new site and managing both the traversal and the multiplexing towards the VCS.
> 
> Not tried yet, but would anyone have an idea
> a) whether this configuration is possible
> b) whether there are any specific issues or limitations with it
> c) have a working config sample? :-)
> 
> Very grateful for any advice. I have attached a diagram showing the various components and networks.
> 
> Thanks in advance,
> Florian.


------------------------------------------------------------------------------
Master HTML5, CSS3, ASP.NET, MVC, AJAX, Knockout.js, Web API and
much more. Get web development skills now with LearnDevNow -
350+ hours of step-by-step video tutorials by Microsoft MVPs and experts.
SALE $99.99 this month only -- learn more at:
http://p.sf.net/sfu/learnmore_122812
_______________________________________________________

Posting: mailto:Openh323gk-users@xxxxxxxxxxxxxxxxxxxxx
Archive: http://sourceforge.net/mailarchive/forum.php?forum_name=openh323gk-users
Unsubscribe: http://lists.sourceforge.net/lists/listinfo/openh323gk-users
Homepage: http://www.gnugk.org/


[Index of Archives]     [SIP]     [Open H.323]     [Gnu Gatekeeper]     [Asterisk PBX]     [ISDN Cause Codes]     [Yosemite News]

  Powered by Linux