Cisco PIX 525 Spécifications Page 370

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 604
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 369
21-44
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 21 Applying Application Layer Protocol Inspection
Managing SIP Inspection
MESSAGE/INFO requests can come in at any time after registration/subscription. For example, two
users can be online at any time, but not chat for hours. Therefore, the SIP inspection engine opens
pinholes that time out according to the configured SIP timeout value. This value must be configured at
least five minutes longer than the subscription duration. The subscription duration is defined in the
Contact Expires value and is typically 30 minutes.
Because MESSAGE/INFO requests are typically sent using a dynamically allocated port other than port
5060, they are required to go through the SIP inspection engine.
Note Only the Chat feature is currently supported. Whiteboard, File Transfer, and Application Sharing are not
supported. RTC Client 5.0 is not supported.
SIP inspection NATs the SIP text-based messages, recalculates the content length for the SDP portion of
the message, and recalculates the packet length and checksum. It dynamically opens media connections
for ports specified in the SDP portion of the SIP message as address/ports on which the endpoint should
listen.
SIP inspection has a database with indices CALL_ID/FROM/TO from the SIP payload that identifies the
call, as well as the source and destination. Contained within this database are the media addresses and
media ports that were contained in the SDP media information fields and the media type. There can be
multiple media addresses and ports for a session. RTP/RTCP connections are opened between the two
endpoints using these media addresses/ports.
The well-known port 5060 must be used on the initial call setup (INVITE) message. However,
subsequent messages may not have this port number. The SIP inspection engine opens signaling
connection pinholes, and marks these connections as SIP connections. This is done for the messages to
reach the SIP application and be NATed.
As a call is set up, the SIP session is considered in the “transient” state until the media address and media
port is received in a Response message from the called endpoint indicating the RTP port the called
endpoint listen on. If there is a failure to receive the response messages within one minute, the signaling
connection is torn down.
Once the final handshake is made, the call state is moved to active and the signaling connection remains
until a BYE message is received.
If an inside endpoint initiates a call to an outside endpoint, a media hole is opened to the outside interface
to allow RTP/RTCP UDP packets to flow to the inside endpoint media address and media port specified
in the INVITE message from the inside endpoint. Unsolicited RTP/RTCP UDP packets to an inside
interface does not traverse the security appliance, unless the security appliance configuration
specifically allows it.
Enabling and Configuring SIP Inspection
To enable SIP inspection or change the default port used for receiving SIP traffic, perform the following
steps:
Step 1 Name the traffic class by entering the following command in global configuration mode:
hostname(config)# class-map
class_map_name
Replace class_map_name with the name of the traffic class, for example:
hostname(config)# class-map sip_port
Vue de la page 369
1 2 ... 365 366 367 368 369 370 371 372 373 374 375 ... 603 604

Commentaires sur ces manuels

Pas de commentaire