122
Security
Media Application Server ports
All Media Application Server ports have a hidden signature to provide basic
protection against rogue clients. Any attempt to connect to MAS ports
by rogue clients without the proper signature are terminated before any
malicious activity takes place. All messaging that is sent from clients to MAS
Services is validated before any action is taken.
If validation fails, the command is discarded. All IM Chat messages are
encrypted using shared secret key encryption. To successfully connect
to a MAS service, a user must be authenticated and registered with the
Session Manager. No additional authentication takes place directly between
a client and a MAS service
The MAS services offer the security protection provided by the Microsoft
Windows 2000 Server operating system. The port range used by the
Media Application Server software is configurable. However, by default, the
services use port 5060 for SIP messaging and 53500 and up (in increments
of four per participant media type) for RTP/RTCP.
The following table identifies the UDP/TCP ports used for Media Application
Server services.
Table 33
Media Application Server IP ports
Application
Use
Port and protocol
SIP
Session Signaling
5060 UDP and
TCP
RTP/RTCP
Media channels
53500 and up (in
groups of 4 per
media flow)
Terminal Services
Remote Console
3389 TCP
Multimedia conductor
Platform Connect
ivity
4004 TCP
IVR media processor
Platform Connect
ivity
4001 TCP
External Session API (ESA)
Platform Connect
ivity
6032 TCP
Conference media processor
Platform Connect
ivity
7080 TCP
Multimedia content store
Platform Connect
ivity
52005 TCP
Stream Source
Music streaming
19999 TCP
Nortel Media Application Server
Media Application Server Planning and Engineering
NN42020-201
01.04
Standard
4.0
27 July 2007
Copyright © 2007, Nortel Networks
.