The predefined H.323 service objects in the default configuration for NetDefendOS 11.03 and
later already have their
Protocol
property set to be
H.323
. This will not be true where
NetDefendOS has been upgraded to version 11.03 or later.
H.323 Settings
Both the
H.323 ALG
object (for IP Rules) and the
VoIP Profile
(for IP Policies) objects allow the
following property settings to be configured:
•
Allow TCP Data Channels
This option allows TCP based data channels to be negotiated. Data channels are used, for
example, by the T.120 protocol.
•
Max TCP Data Channels
The maximum number of TCP data channels can be specified.
•
Gatekeeper Registration Lifetime
The gatekeeper registration lifetime can be controlled in order to force re-registration by
clients within a certain time. A shorter time forces more frequent registration by clients with
the gatekeeper and less probability of a problem if the network becomes unavailable and the
client thinks it is still registered.
•
Translate Addresses
The default value for address translation is
Automatic
. If set to
Specific
, a particular network
and IP address can be set. If not enabled then no address translation will be done on logical
channel addresses and the administrator needs to be sure about IP addresses and routes
used in a particular scenario.
•
Network and IP Address
This option is available if the Translate Address option is set to
Specific
. For NATed traffic,
the Network specifies what is allowed to be translated. The IP Address specifies which IPv4
address to NAT with. If Translate Addresses is to
Automatic
, the external IP address is found
automatically through route lookup.
H.323 Service Object Setup
Presented next are some examples of H.323 setup. For each setup, a
Service
object is used. The
properties of the
Service
objects created for H.323 should be as follows:
•
H.323 Service - Type: TCP, Destination port: 1720
•
H.323 Gatekeeper Service - Type: UDP, Destination port: 1719
There are predefined
Service
objects in NetDefendOS which are called
h323
and
h323-gatekeeper
and these could be used instead of the custom
Service
objects used in the example. However, if
using these objects with an
IP Policy
, it should be checked that the
Protocol
property of the
Service
is set to
H.323
. This is automatically true for the default configuration of NetDefendOS
11.03 or later but not true for upgrades from versions prior to 11.03.
Chapter 6: Security Mechanisms
481
Summary of Contents for NetDefendOS
Page 30: ...Figure 1 3 Packet Flow Schematic Part III Chapter 1 NetDefendOS Overview 30 ...
Page 32: ...Chapter 1 NetDefendOS Overview 32 ...
Page 144: ...Chapter 2 Management and Maintenance 144 ...
Page 284: ...Chapter 3 Fundamentals 284 ...
Page 392: ...Chapter 4 Routing 392 ...
Page 419: ... Host 2001 DB8 1 MAC 00 90 12 13 14 15 5 Click OK Chapter 5 DHCP Services 419 ...
Page 420: ...Chapter 5 DHCP Services 420 ...
Page 573: ...Chapter 6 Security Mechanisms 573 ...
Page 607: ...Chapter 7 Address Translation 607 ...
Page 666: ...Chapter 8 User Authentication 666 ...
Page 775: ...Chapter 9 VPN 775 ...
Page 819: ...Chapter 10 Traffic Management 819 ...
Page 842: ...Chapter 11 High Availability 842 ...
Page 866: ...Default Enabled Chapter 13 Advanced Settings 866 ...
Page 879: ...Chapter 13 Advanced Settings 879 ...