Grey Headline (continued)

Other Issues

TANDBERG VIDEO COMMUNICATIONS SERVER ADMINISTRATOR GUIDE

Firewall Traversal and Dual Network Interfaces

 

Firewall Configuration

 

 

 

The Dual Network Interfaces option enables the LAN 2 interface on your VCS Expressway (the option is not available on a VCS Control). The LAN 2 interface is used in situations where your VCS Expressway is located in a DMZ that consists of two separate networks - an inner DMZ and an outer DMZ - and your firewall rules prevent communication between the two.

With the LAN 2 interface enabled, you can configure the VCS with two separate IP addresses, one for each network in the DMZ. Your VCS then acts as a proxy server between the two networks, allowing calls to pass between the internal and outer firewalls that make up your DMZ.

All ports configured on the VCS, including those relating to firewall traversal, will apply to both IP addresses; it is not possible to configure these ports separately for each IP address.

In order for Expressway™ firewall traversal to function correctly, the firewall must be configured to:

allow initial outbound traffic from the client to the ports being used by the VCS Expressway

allow return traffic from those ports on the VCS Expressway back to the originating client.

TANDBERG offers a downloadable tool, the Expressway Port Tester, that allows you to test your firewall configuration for compatibility issues with your network and endpoints. It will advise if necessary which ports may need to be opened on your firewall in order for the Expressway™ solution to function correctly. The Expressway Port Tester currently only supports H.323. Contact your TANDBERG representative for more information.

We recommend that you turn off any H.323 and SIP protocol support on the firewall: these ! are not needed in conjunction with the TANDBERG Expressway™ solution and may interfere

with its operation.

Introduction

Getting Started

 

Overview and

 

System

 

VCS

 

Zones and

 

Call

 

Bandwidth

Firewall

Applications

 

Maintenance

 

Appendices

 

Status

 

Configuration

 

Configuration

 

Neighbors

 

Processing

 

Control

Traversal

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

D14049.04

 

 

 

 

 

 

 

 

155

 

 

 

 

 

 

 

 

JULY 2008

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Page 155
Image 155
TANDBERG D14049.04 manual 155, Other Issues