D-Link DFL-2500 User Guide - Page 180

H.323 ALG Configuration

Page 180 highlights

18.4. H.323 161 • NAT, SAT The H.323 ALG supports version 5 of the H.323 specification. This specification is built upon H.225.0 v5 and H.245 v10. In addition to support voice and video calls, the H.323 ALG supports application sharing over the T.120 protocol. T.120 uses TCP to transport data while voice and video is transported over UDP. To support gatekeepers, the ALG makes sure to monitor RAS traffic between H.323 endpoints and the gatekeeper, in order to configure the firewall to let calls through. NAT and SAT rules are supported, allowing clients and gatekeepers to use private IP addresses on a network behind the firewall. 18.4.5 Scenarios: H.323 ALG Configuration The H.323 ALG can be configured to suit different usage scenarios. It is possible to configure if TCP data channels should be allowed to traverse the firewall or not. TCP data channels are used by the T.120 protocol (see 18.4.3), for instance. Also, the maximum number of TCP data channels can be limited to a fixed value. The gatekeeper registration lifetime can be controlled by the firewall in order to force re-registration of clients within a time frame specified by the administrator. Presented here are a few network scenarios, visualized in network diagrams. The scenarios are examples of network setups where the H.323 ALG is suitable to use. For each scenario a configuration example of both the ALG and the rules are presented. The three service definitions used in these scenarios are: • Gatekeeper (UDP ALL → 1719) • H323 (H.323 ALG, TCP ALL → 1720) • H323-Gatekeeper (H.323 ALG, UDP → 1719) D-Link Firewalls User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365

18.4. H.323
161
NAT, SAT
The H.323 ALG supports version 5 of the H.323 specification. This
specification is built upon H.225.0 v5 and H.245 v10. In addition to
support voice and video calls, the H.323 ALG supports application sharing
over the T.120 protocol. T.120 uses TCP to transport data while voice and
video is transported over UDP.
To support gatekeepers, the ALG makes sure to monitor RAS traffic
between H.323 endpoints and the gatekeeper, in order to configure the
firewall to let calls through.
NAT and SAT rules are supported, allowing clients and gatekeepers to use
private IP addresses on a network behind the firewall.
18.4.5
Scenarios
: H.323 ALG Configuration
The H.323 ALG can be configured to suit different usage scenarios.
It is possible to configure if TCP data channels should be allowed to
traverse the firewall or not. TCP data channels are used by the T.120
protocol (see
18.4.3
), for instance. Also, the maximum number of TCP
data channels can be limited to a fixed value.
The gatekeeper registration lifetime can be controlled by the firewall in
order to force re-registration of clients within a time frame specified by the
administrator.
Presented here are a few network scenarios, visualized in network diagrams.
The scenarios are examples of network setups where the H.323 ALG is
suitable to use. For each scenario a configuration example of both the ALG
and the rules are presented.
The three service definitions used in these scenarios are:
Gatekeeper (UDP ALL
1719)
H323 (H.323 ALG, TCP ALL
1720)
H323-Gatekeeper (H.323 ALG, UDP
1719)
D-Link Firewalls User’s Guide