
5-15
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 5 Configuring Application Inspection (Fixup)
Voice Over IP
• CTIQBE application inspection does not support configurations using the alias command, which is
deprecated after the introduction of outside NAT with PIX
Firewall Version 6.2.
• Stateful Failover of CTIQBE calls is not supported.
• Using the debug ctiqbe command may delay message transmission, which may have a performance
impact in a real-time environment. When you enable this debugging or logging and
Cisco
IP SoftPhone seems unable to complete call setup through the PIX Firewall, increase the
timeout values in the Cisco TSP settings on the system running Cisco IP SoftPhone.
• CTIQBE application inspection does not support CTIQBE message fragmented in multiple TCP
packets.
The following summarizes special considerations when using CTIQBE application inspection in specific
scenarios:
• If two Cisco IP SoftPhones are registered with different Cisco CallManagers, which are connected
to different interfaces of a PIX Firewall, calls between these two phones will fail.
• When Cisco CallManager is located on the higher security interface compared to
Cisco
IP SoftPhones, if NAT or outside NAT is required for the Cisco CallManager IP address, the
mapping must be static as Cisco IP SoftPhone requires the Cisco CallManager IP address to be
specified explicitly in its Cisco TSP configuration on the PC.
• When using PAT or Outside PAT, if the Cisco CallManager IP address is to be translated, its TCP
port 2748 must be statically mapped to the same port of the PAT (interface) address in order for
Cisco IP SoftPhone registrations to succeed. The CTIQBE listening port (TCP 2748) is fixed and is
not user-configurable on Cisco
CallManager, Cisco IP SoftPhone, or Cisco TSP.
To display information regarding the CTIQBE sessions established across the PIX Firewall, enter the
following command:
show ctiqbe
For further information about using this command to troubleshoot CTIQBE application inspection
issues, refer to the show ctiqbe command in the Cisco PIX Firewall Command Reference.
CU-SeeMe
With CU-SeeMe clients, one user can connect directly to another (CU-SeeMe or other H.323 client) for
person-to-person audio, video, and data collaboration. CU-SeeMe clients can conference in a mixed
client environment that includes both CU-SeeMe clients and H.323-compliant clients from other
vendors.
Behind the scenes, CU-SeeMe clients operate in two very different modes. When connected to another
CU-SeeMe client or CU-SeeMe Conference Server, the client sends information in CU-SeeMe mode.
When connected to an H.323-compliant videoconferencing client from a different vendor, CU-SeeMe
clients communicate using the H.323-standard format in H.323 mode.
CU-SeeMe is supported through H.323 inspection, as well as performing NAT on the CU-SeeMe control
stream, which operates on UDP port 7648.
Comentarios a estos manuales