UCi2i Video Conference Endpoint Firewall Requirements. UCi2i Video Conference Endpoint Firewall Requirements



Similar documents
UCi2i Video Conference Endpoint Firewall Requirements

Cisco TelePresence Video Communication Server (Cisco VCS) IP Port Usage for Firewall Traversal. Cisco VCS X8.5 December 2014

Application Note. Onsight Connect Network Requirements v6.3

Cisco Expressway IP Port Usage for Firewall Traversal. Cisco Expressway X8.1 D December 2013

Personal Telepresence. Place the VidyoPortal/VidyoRouter on a public Static IP address

Crossing firewalls. Liane Tarouco Leandro Bertholdo RNP POP/RS. Firewalls block H.323 ports

LifeSize Transit Deployment Guide June 2011

VidyoWay IT Guide Product Version 3.0 Document Version 3.0 A 5/9/2014

IP Ports and Protocols used by H.323 Devices

White Paper. Traversing Firewalls with Video over IP: Issues and Solutions

Cisco TelePresence Video Communication Server Basic Configuration (Control with Expressway)

Application Note. Firewall Requirements for the Onsight Mobile Collaboration System and Hosted Librestream SIP Service v5.0

Application Note - Using Tenor behind a Firewall/NAT

Application Note. Onsight TeamLink And Firewall Detect v6.3

District of Columbia Courts Attachment 1 Video Conference Bridge Infrastructure Equipment Performance Specification

StarLeaf Network Guide

Successful IP Video Conferencing White Paper

Setting up a reflector-reflector interconnection using Alkit Reflex RTP reflector/mixer

Application Note. Onsight Connect Network Requirements V6.1

Video Conferencing and Firewalls

Cisco Expressway Basic Configuration

nexvortex Setup Guide

Firewalls and H.323 based VC-Systems

Cullen Jennings July 2015

Cisco Exam Implementing Cisco Video Network Devices (VIVND) Version: 7.1 [ Total Questions: 74 ]

LifeSize UVC Manager TM Deployment Guide

Unified Communications Mobile and Remote Access via Cisco VCS

Unified Communications Mobile and Remote Access via Cisco Expressway

Customer Guide. BT Business - BT SIP Trunks. BT SIP Trunks: Firewall and LAN Guide. Issued by: BT Business Date Issue: v1.

How To: Configure a Cisco ASA 5505 for Video Conferencing

Quick Installation Card

Polycom. RealPresence Ready Firewall Traversal Tips

Source-Connect Network Configuration Last updated May 2009

General Guidelines for SIP Trunking Installations

Unified Communications Mobile and Remote Access via Cisco VCS

About UCi2i The future of visual communications

Securing Networks with PIX and ASA

Firewall Firewall August, 2003

VegaStream Information Note Considerations for a VoIP installation

Unified Communications in RealPresence Access Director System Environments

MINIMUM NETWORK REQUIREMENTS 1. REQUIREMENTS SUMMARY... 1

Cisco Expressway Series

Cisco TelePresence Video Communication Server

Quick Installation Card

AVer EVC. Quick Installation Guide. Package Contents. 8. Mini Din 8 pin MIC Cable. 1. Main System. 9. HDMI Cable. 2. Camera. 10.

A host-based firewall can be used in addition to a network-based firewall to provide multiple layers of protection.

Cisco TelePresence Video Communication Server

Many network and firewall administrators consider the network firewall at the network edge as their primary defense against all network woes.

MS Skype for Business and Lync. Integration Guide

1) How do I setup my SIP trunk for inbound/outbound calling? We authenticate IP-PBX SIP Trunking traffic by:

How To Protect Your Network From A Hacker Attack On Zcoo Ip Phx From A Pbx From An Ip Phone From A Cell Phone From An Uniden Ip Pho From A Sim Sims (For A Sims) From A

ANS Monitoring as a Service. Customer requirements

General Guidelines for SIP Trunking Installations

Polycom RealPresence Access Director System

Cisco TelePresence Video Communication Server Starter Pack Express Bundle

Cisco TelePresence Multipoint Switch

Cisco TelePresence Video Communication Server Expressway

AVer Video Conferencing Network Setup Guide

Ports utilisés. Ports utilisés par le XT1000/5000 :

Cisco WebEx Telepresence

Virtual private network. Network security protocols VPN VPN. Instead of a dedicated data link Packets securely sent over a shared network Internet VPN

TMS Phone Books Troubleshoot Guide

This presentation discusses the new support for the session initiation protocol in WebSphere Application Server V6.1.

LifeSize Video Communications Systems Administrator Guide

Prepare your IP network for HD video conferencing

Polycom Unified Communications in RealPresence Access Director System Environments

Cisco TelePresence MCU 45X0, 53X0 and MCU MSE 8510

SIP Security Controllers. Product Overview

Deploying the Barracuda Load Balancer with Office Communications Server 2007 R2. Office Communications Server Overview.

Management, Logging and Troubleshooting

DEPLOYMENT GUIDE Version 1.2. Deploying the BIG-IP LTM for SIP Traffic Management

Requirements. System Requirements. System Requirements, page 1 Port Requirements, page 4 Supported Codecs, page 5

LifeSize Passport TM User and Administrator Guide

Virtual Server and DDNS. Virtual Server and DDNS. For BIPAC 741/743GE

Video Conferencing and Security

Configuring the Avaya B179 SIP Conference Phone with Avaya Aura Communication Manager and Avaya Aura Session Manager Issue 1.0

nexvortex Setup Template

3.2.2 Bandwidth Requirements

How To Deploy Sangoma Sbc Vm At Amazon Cloud Service (Awes) On A Vpc (Virtual Private Cloud) On An Ec2 Instance (Virtual Cloud)

should make before the N3 Managed Video Conference service is delivered. This guide outlines the preparations sites should undertake ahead of

Firewalls and VPNs. Principles of Information Security, 5th Edition 1

Basic Vulnerability Issues for SIP Security

Polycom RealPresence Access Director System

FIREWALLS & CBAC. philip.heimer@hh.se

VIDEOCONFERENCING. Video class

Cisco TelePresence Video Communication Server

Google Compute Engine Configuration

MyIC setup and configuration (with sample configuration for Alcatel Lucent test environment)

Polycom Unified Communications in RealPresence Access Director System Environments

Acano solution. Third Party Call Control Guide. March E

SCOPIA iview Management Suite

ThinkTel ITSP with Registration Setup Quick Start Guide

StarLeaf Connectivity Services. Deployment Guide

Cisco TelePresence Video Communication Server

Application Note. Onsight Mobile Collaboration Video Endpoint Interoperability v5.0

Interwise Connect. Working with Reverse Proxy Version 7.x

Scopia XT Desktop Server for IP Office

Transcription:

1 UCi2i Video Conference Endpoint Firewall Requirements

2 UCi2i VC Endpoint Firewall Requirements Dear customer, Due to the implementation of our secure video network, there are a few firewall rules that may be required depending on your network configuration to allow communication with the UCi2i infrastructure. This is to provide our clients with the best technology on the market. What this means to you In order for you and your client to take full advantage of our service, we may require you to make some changes to your firewall to allow communication from your current hardware/software to the UCi2i Firewall Traversal Servers. Please note that many firewalls work without any modification at all. If you wish to test your firewall before deploying our managed video service, then you can test SIP Video functionality by downloading the free video client from https://www.ciscojabbervideo.com and once installed and logged in, call test@uci2i.com from the Jabber video client. You should briefly see the following, and hear Hello, welcome to the conferencing system : - Please note the free Cisco Jabber video client has no customer support from Cisco or from UCi2i, however, feel free to let your friends/relatives know about it, and to use it to call them.

Video Conference Endpoint Firewall Requirements 3 What addresses and ports does video conferencing use? Please see below firewall port requirements. In order to provide resiliency, we will require you to open ports to multiple addresses. UCi2i address ranges: 91.244.117.67 91.244.117.85 91.233.183.163 91.233.183.175 REGISTRATION TO THE SIP PROXIES Please ensure that the correct ports are open depending on the video conferencing system you are using. There are different port requirements for SIP depending on what signalling method your system is using. The media requirements are the same regardless of the signalling method. Note these outbound exceptions are required to establish a UDP/TCP session. There are absolutely no inbound pinholes required. SIP Signalling(TLS) 5061 TCP Host ----> UCi2i SIP Signalling(TCP) 5060 TCP Host ----> UCi2i SIP Signalling(UDP) 5060 UDP Host ----> UCi2i Media (RTP) 2776 UDP Host ----> UCi2i Media (RTCP) 2777 UDP Host ----> UCi2i Media 50000-54999 UDP Host ----> UCi2i

4 H323: USING ASSENT FIREWALL TRAVERSAL If your video conference system supports Assent Traversal, you may need to open the ports below in order to register to our firewall traversal server. Gatekeeper RAS 1719 UDP Host ----> UCi2i Call Signalling 2776 TCP Host ----> UCi2i Media (RTP) 2776 UDP Host ----> UCi2i Media (RTCP) 2777 UDP Host ----> UCi2i Media 50000-54999 UDP Host ----> UCi2i H323: USING H.460.18/19 FIREWALL TRAVERSAL used by all Polycom/Lifesize devices If your video conference system is not a Cisco Telepresence device and supports H.460.18/19 firewall traversal, you will need to open the ports below in order to register to our firewall traversal server. Gatekeeper RAS 1719 UDP Host ----> UCi2i H.225 Protocol 1720 TCP Host ----> UCi2i H.245 Protocol 2777 TCP Host ----> UCi2i Media (RTP) 2776 UDP Host ----> UCi2i Media (RTCP) 2777 UDP Host ----> UCi2i Media 50000-54999 UDP Host ----> UCi2i

Video Conference Endpoint Firewall Requirements 5 ENDPOINT MANAGEMENT If you require your video endpoint to be managed by us, we will require an IP address which is accessible over the Internet. This can be a static NAT IP. Please ensure you have the below ports opened on your firewall to allow for monitoring and management of your video endpoint from our network. You will need to ensure your video endpoint is using an NTP server in order for it to authenticate with our Gatekeeper and for encryption to be active. HTTP or 80 TCP Host <----> UCi2i HTTPS (preferred) 443 TCP Host <----> UCi2i SNMP 161 UDP Host <---- UCi2i SNMP Traps 162 UDP Host ----> UCi2i Telnet or 23 TCP UCi2i ----> Host SSH (preferred) 22 TCP UCi2i ----> Host NTP NTP NTP NTP KEY Please see below explanations of the direction column (where applicable): Direction Host <----> UCi2i Host <---- UCi2i Host ----> UCi2i UCi2i ----> Host Host ---> NTP Server Explanation Ports needs to be opened inbound and outbound to/from your VC endpoint and UCi2i Ports need to be opened inbound to your VC endpoint from the UCi2i address ranges Ports need to be opened outbound from your VC endpoint to the UCi2i address ranges Ports need to be opened inbound to your VC endpoint from the UCi2i address ranges Ports need to be opened outbound from your VC endpoint to the NTP Server

6 Finally, if you have any problems, please feel free to call the UCi2i Helpdesk Numbers: +852-3746-6000 (HK) or +44-844-546-7005 (UK) or email/video call to vdesk@uci2i.com UCI2I OFFICE DETAILS APAC t: +852 3746 6001 V-Desk: +852 3746 6000 v/e: vdesk@uci2i.com 21/F, Wyler Centre Phase II 192-200 Tai Lin Pai Road Kwai Chung N.T. Hong Kong EMEA t: +44 844 546 7001 V-Desk: +44 844 546 7005 v/e: vdesk@uci2i.com 6 Mitre Passage Greenwich Peninsula London SE10 0ER