Howto13r1:Firewall Settings: Difference between revisions

From innovaphone wiki
Jump to navigation Jump to search
No edit summary
Line 25: Line 25:
| LDAPS (tcp/636)<br>
| LDAPS (tcp/636)<br>
''&bull; <span style="font-size:11px;">optionally LDAP (tcp/389) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">optionally LDAP (tcp/389) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">needed if you want offer LDAP lookups</span>''
''&bull; <span style="font-size:11px;">needed if you want to offer LDAP lookups</span>''
|| LDAPS (tcp/636)<br>
|| LDAPS (tcp/636)<br>
''&bull; <span style="font-size:11px;">optionally LDAP (tcp/389) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">optionally LDAP (tcp/389) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">needed if you want offer LDAP lookups</span>''
''&bull; <span style="font-size:11px;">needed if you want to offer LDAP lookups</span>''
|| LDAPS (tcp/636)<br>
|| LDAPS (tcp/636)<br>
''&bull; <span style="font-size:11px;">optionally LDAP (tcp/389) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">optionally LDAP (tcp/389) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">needed if you want offer LDAP lookups</span>''
''&bull; <span style="font-size:11px;">needed if you want to offer LDAP lookups</span>''
|| /  
|| /  
|| /
|| /
Line 37: Line 37:
| HTTPS (tcp/443)<br>
| HTTPS (tcp/443)<br>
''&bull; <span style="font-size:11px;">optionally HTTP (tcp/80) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">optionally HTTP (tcp/80) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">needed if you want offer myApps</span>''<br>
''&bull; <span style="font-size:11px;">needed if you want to offer myApps</span>''<br>
''&bull; <span style="font-size:11px;">please also allow wss/ws (websocket) connections</span>''
''&bull; <span style="font-size:11px;">please also allow wss/ws (websocket) connections</span>''
|| HTTPS (tcp/443)<br>
|| HTTPS (tcp/443)<br>
''&bull; <span style="font-size:11px;">optionally HTTP (tcp/80) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">optionally HTTP (tcp/80) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">needed if you want offer myApps</span>''<br>
''&bull; <span style="font-size:11px;">needed if you want to offer myApps</span>''<br>
''&bull; <span style="font-size:11px;">please also allow wss/ws (websocket) connections</span>''
''&bull; <span style="font-size:11px;">please also allow wss/ws (websocket) connections</span>''
|| HTTPS (tcp/443)<br>
|| HTTPS (tcp/443)<br>
''&bull; <span style="font-size:11px;">optionally HTTP (tcp/80) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">optionally HTTP (tcp/80) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">needed if you want offer myApps</span>''<br>
''&bull; <span style="font-size:11px;">needed if you want to offer myApps</span>''<br>
''&bull; <span style="font-size:11px;">please also allow wss/ws (websocket) connections</span>''
''&bull; <span style="font-size:11px;">please also allow wss/ws (websocket) connections</span>''
|| HTTPS (tcp/<your custom port>)<br>
|| HTTPS (tcp/<your custom port>)<br>
Line 52: Line 52:
|-
|-
| H.323 (tcp/1300)<br>
| H.323 (tcp/1300)<br>
''&bull; <span style="font-size:11px;">optionally HTTP (tcp/1720) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">optionally H.323 (tcp/1720) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">needed if you want offer Phone registrations</span>''  
''&bull; <span style="font-size:11px;">needed if you want to offer Phone registrations</span>''  
|| H.323 (tcp/1300)<br>
|| H.323 (tcp/1300)<br>
''&bull; <span style="font-size:11px;">optionally HTTP (tcp/1720) if you need plaintext or username/password auths with invalid certificates</span>''<br>
''&bull; <span style="font-size:11px;">optionally H.323 (tcp/1720) if you need plaintext or username/password auths with invalid certificates</span>''<br>
''&bull; <span style="font-size:11px;">needed if you want offer Phone registrations</span>''  
''&bull; <span style="font-size:11px;">needed if you want to offer Phone registrations</span>''  
|| /  
|| /  
|| /  
|| /  
Line 62: Line 62:
|-
|-
| SIPS (tcp/5061)<br>
| SIPS (tcp/5061)<br>
''&bull; <span style="font-size:11px;">optionally LDAP (tcp/5060) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">optionally SIP (tcp/5060) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">needed '''only''' if you want to accept SIP registers</span>''
''&bull; <span style="font-size:11px;">needed '''only''' if you want to accept SIP registrations</span>''
|| SIPS (tcp/5061)<br>
|| SIPS (tcp/5061)<br>
''&bull; <span style="font-size:11px;">optionally LDAP (tcp/5060) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">optionally SIP (tcp/5060) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">needed '''only''' if you want to accept SIP registers</span>''
''&bull; <span style="font-size:11px;">needed '''only''' if you want to accept SIP registrations</span>''
|| /  
|| /  
|| /
|| /
|| SIPS (tcp/5061)<br>
|| SIPS (tcp/5061)<br>
''&bull; <span style="font-size:11px;">optionally LDAP (tcp/5060) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">optionally SIP (tcp/5060) if you need plaintext</span>''<br>
''&bull; <span style="font-size:11px;">needed if you want to register a SIP Trunk from the RP to Provider and your Provider doesn't Support TURN</span>''
''&bull; <span style="font-size:11px;">needed if you want to register a SIP Trunk from the RP to Provider and your Provider doesn't support TURN</span>''
|-
|-
| / || / || / || RTP (udp/16384-32767)<br>
| / || / || / || RTP (udp/16384-32767)<br>
''&bull; <span style="font-size:11px;">needed if you want to register a SIP Trunk from the RP to Provider and your Provider doesn't Support TURN</span>''  
''&bull; <span style="font-size:11px;">needed if you want to register a SIP Trunk from the RP to Provider and your Provider doesn't support TURN</span>''  
|| RTP (udp/16384-32767)<br>
|| RTP (udp/16384-32767)<br>
''&bull; <span style="font-size:11px;">needed if you want to register a SIP Trunk from the RP to Provider and your Provider doesn't Support TURN</span>''
''&bull; <span style="font-size:11px;">needed if you want to register a SIP Trunk from the RP to Provider and your Provider doesn't Support TURN</span>''

Revision as of 15:39, 20 August 2019

Applies To

This information applies to

V13 and up

Scenario: Reverse Proxy in a DMZ

Here we would like to give an overview of the necessary ports and protocols for a reverse proxy in a DMZ.

The scenario would be that a reverse proxy is used in a DMZ. The DMZ has a link to the WAN and LAN.

Configuration


WAN ⇒ DMZ (Reverse Proxy) DMZ (Reverse Proxy) ⇒ inside (PBX) DMZ (Reverse Proxy) ⇒ inside (Application Platform) inside ⇒ DMZ (Reverse Proxy) DMZ (Reverse Proxy) ⇒ WAN
STUN/TURN (udp/tcp/3478) / / STUN/TURN (udp/tcp/3478) /
LDAPS (tcp/636)

optionally LDAP (tcp/389) if you need plaintext
needed if you want to offer LDAP lookups

LDAPS (tcp/636)

optionally LDAP (tcp/389) if you need plaintext
needed if you want to offer LDAP lookups

LDAPS (tcp/636)

optionally LDAP (tcp/389) if you need plaintext
needed if you want to offer LDAP lookups

/ /
HTTPS (tcp/443)

optionally HTTP (tcp/80) if you need plaintext
needed if you want to offer myApps
please also allow wss/ws (websocket) connections

HTTPS (tcp/443)

optionally HTTP (tcp/80) if you need plaintext
needed if you want to offer myApps
please also allow wss/ws (websocket) connections

HTTPS (tcp/443)

optionally HTTP (tcp/80) if you need plaintext
needed if you want to offer myApps
please also allow wss/ws (websocket) connections

HTTPS (tcp/<your custom port>)

Advanced UI admin access

/
H.323 (tcp/1300)

optionally H.323 (tcp/1720) if you need plaintext
needed if you want to offer Phone registrations

H.323 (tcp/1300)

optionally H.323 (tcp/1720) if you need plaintext or username/password auths with invalid certificates
needed if you want to offer Phone registrations

/ / /
SIPS (tcp/5061)

optionally SIP (tcp/5060) if you need plaintext
needed only if you want to accept SIP registrations

SIPS (tcp/5061)

optionally SIP (tcp/5060) if you need plaintext
needed only if you want to accept SIP registrations

/ / SIPS (tcp/5061)

optionally SIP (tcp/5060) if you need plaintext
needed if you want to register a SIP Trunk from the RP to Provider and your Provider doesn't support TURN

/ / / RTP (udp/16384-32767)

needed if you want to register a SIP Trunk from the RP to Provider and your Provider doesn't support TURN

RTP (udp/16384-32767)

needed if you want to register a SIP Trunk from the RP to Provider and your Provider doesn't Support TURN

Related Articles