| You are here: Home > Help & Support > Knowledgebase > Categories > VoIP > Getting started |
How to configure specialist firewalls for use with VoIP |
| Article Number: 59 | Rating: Unrated | Last Updated: Fri, Oct 1, 2010 at 3:47 PM |
Getting StartedSome specialist firewalls require extra configuration in order to successfully pass SIP packets to and from your network - specific notes on these firewalls can be found below. Advanced ConfigurationSonicwall Firewalls - The problem with invite packets being dropped was due to an intrusion protection filter designed to protect against a vunerability known as "sipXtapi Remote Buffer overflow" running SonicOS Standard. SIP equipment used is a Gradwell Branded Camrivox Flexor 151. 1. Firewall setup Click "Rule Wizard..." at the top. Follow the wizard through to create a "Public Server Rule" to the Server IP address (the IP address of your ATA) and using the pre-defined service "SIP". The Destination interface should be LAN. I personally found that although the Flexor 151 allegedly requires several port ranges to be open, the predefined SIP (simply UDP 5060 only) works fine and calls inbound and outbound work fine. I also went back into the Access Rules page, "Configured" the new rule and clicked on the Bandwidth tab. I ticked "Enable Outbound Bandwidth Management", and gave both Guaranteed and Maximum bandwidth as 256Kbps (should be plenty). I set the bandwidth priority to "0 Highest". 2. Security Services Client AV Enforcement: this should be disabled. By all means enable it temporarily to force a new client to download the antivirus software, but if it remains enabled, the ATA will be blocked from the firewall, because obviously it doesn't run the antivirus software! Gateway Antivirus: this is safe to enable. Intrusion Prevention: for safety's sake, it's good to enable this on all interfaces, but unless you Prevent only High Priority attacks, there is a problem with the VoiP category - specifically the following condition: "VoIP sipXtapi Remote Buffer Overflow, SID: 3363, Priority: Medium". To disable this policy, in the list of IPS Policies, click Configure next to the VoiP Category, and set Prevention (and optionally detection) to "Disable".
|
Attachments
There are no attachments for this article.
|
What keypad options do I need to know to listen to my voicemail?
Viewed 1349 times since Wed, Nov 10, 2010
Protecting your VoIP account from fraud
Viewed 2029 times since Tue, Apr 19, 2011
What are the IP addresses of Gradwell’s DNS servers?
Viewed 569 times since Tue, Sep 20, 2011
Sending SMS messages
Viewed 1399 times since Thu, Dec 2, 2010
What is Network Address Translation (NAT)?
Viewed 1454 times since Sun, Feb 20, 2011
How do I view my invoices and payments that I’ve made to Gradwell for phone services?
Viewed 927 times since Thu, Jan 6, 2011
What are "concurrent calls" and how do they affect me?
Viewed 1840 times since Tue, Nov 30, 2010
How do I use call barring to block calls to certain destinations?
Viewed 1878 times since Mon, Apr 18, 2011
Who can I call for free?
Viewed 2781 times since Wed, Sep 15, 2010
How do I receive SMS messages sent to VoIP numbers?
Viewed 3635 times since Wed, Sep 15, 2010
|






