Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

ASA 55xx and Videoconferencing and VCS

I'm not a Security or ASA guy but I always encounter on all my projects the question of "can you help me translate into a configuration that TCP/IP ports you need for your videoconferencing?"

APpreciate it a lot if someone can send or email or PM me a working config(scrubs the confidential info) of the ASA that will work for the setup that has

VCS Control

VCS Expressway

Internal video endpoints calling External (different company's) endpoints

Thanks

3 REPLIES
Cisco Employee

ASA 55xx and Videoconferencing and VCS

Hi,

Well, there is no special configuration, it really depends on the device you are using, the protocols and the support for NAT. Basically, If the VCS needs to be accesed from the internet, I would use an static 1 to 1 and translate the device to a public IP, Then allow the voice protocol to be use and finally, enable the inspection depending of the protocol to be used (Most of the time h323).

Hope it helps.

Mike

Mike
New Member

ASA 55xx and Videoconferencing and VCS

Sory forgot to add more details.

The protocols will be H.323 and SIP.  Tandberg(now Cisco) has a document that lists all the TCP and UDP ports that are required to be open in the firewall.

It is just translating those ports into an actual ASA command lines or config that I need since I am not an ASA guy.

I just want to help the customer that is asking for assistance as I always encounter this question and it is a bt frustrating not have the info.  I am enrolling myself in an ASA class soon though.

Cisco Employee

ASA 55xx and Videoconferencing and VCS

Hi,

Basically if your Tandberg is sitting on the inside, and the calls are coming from the outside, you will just need an access list permitting port TCP 1720 (control channel for H323) TCP/UDP 5060 (Control channel for SIP). Also, make sure that the inspections are configured on the firewall, to see that, you will need to do a show run policy-map, that will list the protocols to be inspected.

The RTP ports, will be opened dynamically on demand if the inspections are configured.

Mike

Mike
685
Views
0
Helpful
3
Replies
CreatePlease login to create content