Chapter 14 ALG
ZyWALL ATP Series User’s Guide
351
14.3 ALG Technical Reference
Here is more detailed information about the Application Layer Gateway.
SIP Signaling Inactivity
Timeout
Most SIP clients have an “expire” mechanism indicating the lifetime of signaling
sessions. The SIP user agent sends registration packets to the SIP server periodically and
keeps the session alive in the Zyxel Device.
If the SIP client does not have this mechanism and makes no calls during the Zyxel
Device SIP timeout, the Zyxel Device deletes the signaling session after the timeout
period. Enter the SIP signaling session timeout value (1~86400).
Restrict Peer to Peer
Signaling Connection
A signaling connection is used to set up the SIP connection.
Enable this if you want signaling connections to only arrive from the IP address(es) you
registered with. Signaling connections from other IP addresses will be dropped.
Restrict Peer to Peer
Media Connection
A media connection is the audio transfer in a SIP connection.
Enable this if you want media connections to only arrive from the IP address(es) you
registered with. Media connections from other IP addresses will be dropped.
You should disable this if have registered for cloud VoIP services.
SIP Signaling Port
If you are using a custom UDP port number (not 5060) for SIP traffic, enter it here. Use the
Add
icon to add fields if you are also using SIP on additional UDP port numbers.
Enable H.323 ALG
Turn on the H.323 ALG to detect H.323 traffic (used for audio communications) and
help build H.323 sessions through the Zyxel Device’s NAT. Enabling the H.323 ALG also
allows you to use the application patrol to detect H.323 traffic and manage the H.323
traffic’s bandwidth (see
).
Enable H.323
Transformations
Select this to have the Zyxel Device modify IP addresses and port numbers embedded
in the H.323 data payload.
You do not need to use this if you have a H.323 device or server that will modify IP
addresses and port numbers embedded in the H.323 data payload.
H.323 Signaling Port
If you are using a custom TCP port number (not 1720) for H.323 traffic, enter it here.
Additional H.323
Signaling Port for
Transformations
If you are also using H.323 on an additional TCP port number, enter it here.
Enable FTP ALG
Turn on the FTP ALG to detect FTP (File Transfer Program) traffic and help build FTP
sessions through the Zyxel Device’s NAT. Enabling the FTP ALG also allows you to use the
application patrol to detect FTP traffic and manage the FTP traffic’s bandwidth (see
).
Enable FTP
Transformations
Select this option to have the Zyxel Device modify IP addresses and port numbers
embedded in the FTP data payload to match the Zyxel Device’s NAT environment.
Clear this option if you have an FTP device or server that will modify IP addresses and
port numbers embedded in the FTP data payload to match the Zyxel Device’s NAT
environment.
FTP Signaling Port
If you are using a custom TCP port number (not 21) for FTP traffic, enter it here.
Additional FTP Signaling
Port for Transformations
If you are also using FTP on an additional TCP port number, enter it here.
Apply
Click
Apply
to
save your changes back to the Zyxel Device.
Reset
Click
Reset
to return the screen to its last-saved settings.
Table 141 Configuration > Network > ALG (continued)
LABEL
DESCRIPTION