Cisco PIX 525 Especificaciones Pagina 350

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 604
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 349
21-24
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 21 Applying Application Layer Protocol Inspection
Managing H.323 Inspection
seq_tpdu_up: 0 seq_tpdu_down: 0
signal_sequence: 0
upstream_signal_flow: 0 upstream_data_flow: 0
downstream_signal_flow: 0 downstream_data_flow: 0
RAupdate_flow: 0
The PDP context is identified by the tunnel ID, which is a combination of the values for IMSI and
NSAPI. A GTP tunnel is defined by two associated PDP contexts in different GSN nodes and is
identified with a Tunnel ID. A GTP tunnel is necessary to forward packets between an external packet
data network and a MS user.
You can use the vertical bar (|) to filter the display, as in the following example:
hostname# show service-policy gtp statistics | grep gsn
Managing H.323 Inspection
This section describes how to enable H.323 application inspection and change the default port
configuration. This section includes the following topics:
H.323 Inspection Overview, page 21-24
How H.323 Works, page 21-24
Limitations and Restrictions, page 21-25
Enabling and Configuring H.323 Inspection, page 21-26
Configuring H.225 Timeout Values, page 21-28
Verifying and Monitoring H.323 Inspection, page 21-28
H.323 Inspection Overview
The inspect h323 command provides support for H.323 compliant applications such as Cisco
CallManager and VocalTec Gatekeeper. H.323 is a suite of protocols defined by the International
Telecommunication Union for multimedia conferences over LANs. The security appliance supports
H.323 through Version 4, including H.323 v3 feature Multiple Calls on One Call Signaling Channel.
With H323 inspection enabled, the security appliance supports multiple calls on the same call signaling
channel, a feature introduced with H.323 Version 3. This feature reduces call setup time and reduces the
use of ports on the security appliance.
The two major functions of H.323 inspection are as follows:
NAT the necessary embedded IPv4 addresses in the H.225 and H.245 messages. Because H.323
messages are encoded in PER encoding format, the security appliance uses an ASN.1 decoder to
decode the H.323 messages.
Dynamically allocate the negotiated H.245 and RTP/RTCP connections.
How H.323 Works
The H.323 collection of protocols collectively may use up to two TCP connection and four to six UDP
connections. FastConnect uses only one TCP connection, and RAS uses a single UDP connection for
registration, admissions, and status.
Vista de pagina 349
1 2 ... 345 346 347 348 349 350 351 352 353 354 355 ... 603 604

Comentarios a estos manuales

Sin comentarios