I have viewed the Document Link below regarding the Protocols and Port Numbers in use for CCM 4.2
However from viewing captures of traffic on the Voice-VLAN I see that there are a wide range of unassigned TCP ports in use in communication between IP Phones and our H323 Gateways, ie using a wide range of source and destination ports (unassigned TCP)when communicating with Skinny and H245 signalling. This coupled with the fact that it states (in the port usage doc) that ephemeral ports are used between IP Phones for TFTP 69 then ephemeral UDP, H245 signalling ephemeral TCP, gives me the belief that there will be a lot of ports open on our Firewalls and therefore security will be compromised.
Am I correct in assuming that an ephemeral port range would be 1024 - 65534?
Thanks in advance for your help.