Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ACL for H323 protocol 2

Status
Not open for further replies.

Ed.Sabano

IS-IT--Management
Jun 1, 2017
21
US
I have a vlan that i'm blocking from reaching our main network but i have a couple of avaya ip phones (9620s) that i want to allow to reach the ip 500v2.

I have 2 acls in place at the top allowing traffic in on the interface:

udp on port 1719 (gatekeeper discovery)
tcp h323

Phone will dial and then it will just cut off. Packet captures just showing exchanges on different ports.

What i am missing?
 
Depends on how sophisticated your firewall is.

You may find it easier to statically address the h andsets and then allow these source ip any ip (I.e. both udp.and tcp) to the ip of the ip500.

Crucially... for these extensions... remove 'use direct media path'

Why Do you want this sort of security?




Take Care

Matt
I have always wished that my computer would be as easy to use as my telephone.
My wish has come true. I no longer know how to use my telephone.
 
i was going for specific ports instead of ip but i guess that'll do. The phones are statically addressed.

As far as the security goes, its a different company on this vlan.

 
Ports used by H.323 phones are

DHCP - UDP/68
HTTP/S - 80/411
H.323 - UDP/1718-1720, TCP/1720
(S)RTP/RTCP - UDP/46750-50740 (default for IP500 9.1 but depends on IPO type and settings)

Check port matrix for complete list of IPO network ports

[URL unfurl="true"]https://downloads.avaya.com/css/appmanager/css/P8Secure/documents/101008914[/url]

"Trying is the first step to failure..." - Homer
 
You may also need 5005 as I have seen this port not being allowed stopping H323 phones working.

| ACSS SME |
 
The phone dials out, i call another extension, talk for a split second, and it cuts off. This is with just the ports i mentioned above.

I will check the port matrix, thanks.

I found the cause of the problem and it wasn't the ACL.

The switch for some strange reason kept putting the port that the phone is connected on to trunk. The ip acl takes care of it but i have yet to test out the ports that were mentioned.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top