Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How Many Open RTP Ports do I need 4

Status
Not open for further replies.

jinxs

Vendor
Mar 28, 2003
725
US
Hi Everyone,

I have a customer that has IP Phones on LAN 1 of the IP Office and SIP Trunks on the LAN 2(WAN). I advised that I needed port 5060 UDP and 49152-53246 UDP opened on the Firewall for the SIP from the ITSP IP Address. They do not want to open 4,094 ports. The have a 3rd party PCI audit done and are afraid they will not comply with the audit. Would 254 ports be sufficient on the WAN side for 10 SIP Trunks? I can only assume yes but I just wanted to confirm since I cannot find any docs to confirm or deny this. Thanks in advance.

 
10 Channels on the trunk means you will only have 10 RTP streams at once passing through the firewall at maximum trunk useage. Open 49152 - 49172, leaving 20 rtp ports available and note it in your documentation. If their trunk increases in capacity or they start registering remote phones through an SBC that number will have to increase.

Never open all of the ports on that upper range to the internet. There are critical ports in that range that will be exploitable from the internet like the Monitor port 50794, Manager Port 50798, etc etc. People will poke at your system and cause all sorts of havoc if you leave that entire range exposed to the internet.


Here is a link to all of the ports used by the system. Read it over so you see what I am saying.
 
That's why they changed the default RTP ports which should now be

IP500 V2 Range = 46750 to 50750.
Linux Range = 40750 to 50750



"Trying is the first step to failure..." - Homer
 
Also you would need to change the RTP Port Number Range to the 20 ports you're using on System -> LAN2

"Trying is the first step to failure..." - Homer
 
...you normally need two ports per call, one RTP, one RTCP.

Stuck in a never ending cycle of file copying.
 
Thank you all! That is what I thought the case was. Pink love for all.
 
Was a little irritated but sizbut confirms what I thought.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top