Velocity Reviews

Velocity Reviews (http://www.velocityreviews.com/forums/index.php)
-   VOIP (http://www.velocityreviews.com/forums/f35-voip.html)
-   -   Re: how to block VOIP on cisco routers? (http://www.velocityreviews.com/forums/t234667-re-how-to-block-voip-on-cisco-routers.html)

Henry Cabot Henhouse III 01-11-2006 04:54 AM

Re: how to block VOIP on cisco routers?
 
We have the same problem with voip boxes...

I'll assume that when you plug in an adapter running H.323, it establishes a
nailed up connection to a server, which is why they seem to work behind
firewalls. As an outbound connection, you dont need to map ports. (I've
seen 5 Linksys/Vonage boxes sitting on a Linksys BEFSX41 with a static on
the WAN side, all work fine for both in and outbound).

So... how would you go about blocking H.323 traffic? If not possible, how
about blocking the fqnd or ips of the servers that the major players -
Vonage, Packet8, etc - use? (Someone must have a list of the servers). And
with SIP (5060) and IAX (4569), can't the ports they use be blocked cutting
off the signalling path?

Ideas? Help?

Thanks in advance
Dave






"John Agosta" <j_agosta@remove_wideopenwest.kom> wrote in message
news:R5mdnRL9MLNFH1nenZ2dnUVZ_s2dnZ2d@wideopenwest .com...
>
> "Jason" <jasonjm2005@hotmail.com> wrote in message
> news:z6qdnZje7dFl71neRVn-rg@giganews.com...
>> my network is being bogged down by "junk"
>>
>> number one on the hitlist : VOIP phones - anyone got any idea how to
>> block them?
>>
>> 2nd problem is streaming radio, people just chewing up bandwidth the
>> whole day! how to kill those?
>>
>> any ideas?
>>
>>
>>

>
> Access lists to permit what you consider non-junk perhaps ?
>
>
>




Jason 01-11-2006 06:41 PM

Re: how to block VOIP on cisco routers?
 
yes lets fogure out how to block this: I have the following info, I am going
to try and block all these ports mentioned below this weekend, and I'll see
what happens

Anyone else feel free to comment







a.. IAX is not the result of a standards group, rather a collaborative,
community based effort
a.. IAX uses a single UDP port 4569, and thus works well in NAT environments
(the obsolete IAX1 protocol used port 5036). IAX uses ONLY one udp port for
both control and data traffic. As outlined in point 4 of the IAX versus SIP
topic with IAX you will always have audio if the control connection can be
established.

a.. SIP is a text-based protocol that uses UTF-8 encoding
a.. SIP uses port 5060 both for UDP and TCP. SIP may use other transports


1718 H.323 RAS (Multicast Discovery)
1719 H.323 RAS (Unicast)
1720 H.323 Call Signaling (TCP)
2099 H.501 Border Element Signaling (H.225.0 Annex G)
2427 MGCP
2517 H.323 Call Signalling (UDP, H.323 Annex E)
2944 H.248
5060 SIP


"Henry Cabot Henhouse III" <sooper_chicken@hotmail.com> wrote in message
news:2-WdnadhXegAElneRVn-pQ@comcast.com...
> We have the same problem with voip boxes...
>
> I'll assume that when you plug in an adapter running H.323, it establishes
> a
> nailed up connection to a server, which is why they seem to work behind
> firewalls. As an outbound connection, you dont need to map ports. (I've
> seen 5 Linksys/Vonage boxes sitting on a Linksys BEFSX41 with a static on
> the WAN side, all work fine for both in and outbound).
>
> So... how would you go about blocking H.323 traffic? If not possible, how
> about blocking the fqnd or ips of the servers that the major players -
> Vonage, Packet8, etc - use? (Someone must have a list of the servers). And
> with SIP (5060) and IAX (4569), can't the ports they use be blocked
> cutting
> off the signalling path?
>
> Ideas? Help?
>
> Thanks in advance
> Dave
>
>
>
>
>
>
> "John Agosta" <j_agosta@remove_wideopenwest.kom> wrote in message
> news:R5mdnRL9MLNFH1nenZ2dnUVZ_s2dnZ2d@wideopenwest .com...
>>
>> "Jason" <jasonjm2005@hotmail.com> wrote in message
>> news:z6qdnZje7dFl71neRVn-rg@giganews.com...
>>> my network is being bogged down by "junk"
>>>
>>> number one on the hitlist : VOIP phones - anyone got any idea how to
>>> block them?
>>>
>>> 2nd problem is streaming radio, people just chewing up bandwidth the
>>> whole day! how to kill those?
>>>
>>> any ideas?
>>>
>>>
>>>

>>
>> Access lists to permit what you consider non-junk perhaps ?
>>
>>
>>

>
>





--------------------------------------------------------------------------------







All times are GMT. The time now is 09:40 AM.

Powered by vBulletin®. Copyright ©2000 - 2013, vBulletin Solutions, Inc.
SEO by vBSEO ©2010, Crawlability, Inc.


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57