Cisco PIX 525 Spécifications Page 202

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 466
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 201
5-26
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 5 Configuring Application Inspection (Fixup)
Voice Over IP
Note When this feature is turned on, outside NAT/alias/bi-directional NAT and Policy NAT will not work.
When a packet from the lower security level (e.g., outside) comes to the higher security level (e.g.,
inside), since we retain the NATted IP addresses in it, and don't send the packet through the NAT engine,
outside NAT will not be performed for the inbound SIP packets.
Instant Messaging (IM)
Instant Messaging refers to the transfer of messages between users in near real-time. SIP supports the
Chat feature on Windows XP using Windows Messenger RTC Client version 4.7.0105 only. The
MESSAGE/INFO methods and 202 Accept response are used to support IM as defined in the following
RFCs:
Session Initiation Protocol (SIP)-Specific Event Notification, RFC 3265
Session Initiation Protocol (SIP) Extension for Instant Messaging, RFC 3428
MESSAGE/INFO requests can come in at any time after registration/subscription. For example, two
users can be online at any time, but not chat for hours. Therefore, the SIP fixup opens U_sip pinholes
which will time out according to the configured SIP timeout value. This value must be configured at least
five minutes longer than the subscription duration. The subscription duration is defined in the Contact
Expires value and is typically 30 minutes.
Because MESSAGE/INFO requests are typically sent using a dynamically allocated port other than port
5060, they are required to go through the SIP fixup.
Note Only the Chat feature is currently supported. Whiteboard, File Transfer, and Application Sharing are not
supported. RTC Client 5.0 is not supported.
Viewing SIP Information
To view information about the SIP sessions established across the PIX Firewall, enter the following
command:
show sip
For further information about using this command to troubleshoot CTIQBE application inspection
issues, refer to the show sip command in the Cisco PIX Firewall Command Reference.
Technical Background
SIP inspection NATs the SIP text-based messages, recalculates the content length for the SDP portion of
the message, and recalculates the packet length and checksum. It dynamically opens media connections
for ports specified in the SDP portion of the SIP message as address/ports on which the endpoint should
listen.
Note When using PAT, if a SIP device transmits a packet in which the SDP portion has an IP address in the
owner/creator (o=) field that is different than the IP address in the connection field (c=), the IP address
in the o= field may not be properly translated. This is due to a limitation in the SIP protocol, which does
not provide a port value in the o= field.
Vue de la page 201
1 2 ... 197 198 199 200 201 202 203 204 205 206 207 ... 465 466

Commentaires sur ces manuels

Pas de commentaire