- Joined
- Jul 3, 2017
- Messages
- 184
- Reaction score
- 12
Hello,
Let's assume the following simple setup:
Internal 3cx (RTP port 9000) - - - > Firewall - - > Internet - - > Provider (RTP port 10000)
The internal 3cx has a SIP trunk with the provider and UDP port 5060 is open on the local Firewall, so SIP negotiation is OK.
However, RTP port 9000 is NOT open.
Let's assume that the provider is calling towards 3cx and let's assume that in the SDP, 3cx has negotiated its port 9000 and the provider its port 10000.
If the provider starts sending media first from its port 10000, the first UDP packets towards 3cx's port 9000 will be blocked, as port 9000 is not open in the firewall.
However, a few milliseconds later 3cx will start sending media from its local port 9000 to the provider's port 10000 (as this was agreed in the 200 OK's SDP).
Thus, the Firewall's stateful inspection will allow backwards traffic from the provider's 10000 to the internal port 9000, even if the very first RTP packets were blocked.
At least, this is my understanding.
If this is the case, why do we even need to open UDP (RTP) ports on the firewall?
Hope my question is clear.
Regards,
George
Let's assume the following simple setup:
Internal 3cx (RTP port 9000) - - - > Firewall - - > Internet - - > Provider (RTP port 10000)
The internal 3cx has a SIP trunk with the provider and UDP port 5060 is open on the local Firewall, so SIP negotiation is OK.
However, RTP port 9000 is NOT open.
Let's assume that the provider is calling towards 3cx and let's assume that in the SDP, 3cx has negotiated its port 9000 and the provider its port 10000.
If the provider starts sending media first from its port 10000, the first UDP packets towards 3cx's port 9000 will be blocked, as port 9000 is not open in the firewall.
However, a few milliseconds later 3cx will start sending media from its local port 9000 to the provider's port 10000 (as this was agreed in the 200 OK's SDP).
Thus, the Firewall's stateful inspection will allow backwards traffic from the provider's 10000 to the internal port 9000, even if the very first RTP packets were blocked.
At least, this is my understanding.
If this is the case, why do we even need to open UDP (RTP) ports on the firewall?
Hope my question is clear.
Regards,
George