Configuration method of H323 Protocol under Voip in checkpoint Firewall
Description of phenomenon:
Checkpoint firewall is used as the security protection gateway. The network is normal, but Voip (H323) service is not available.
The solution is as follows:
IP of each terminal of Voip is summarized and set up as source address and destination address, as shown in Figure 1.
Protocol selection H323_ras, H323_any and UDP high port, TCP61440-61444, see Figure 2
The H323_ras and H323_any protocols are configured as follows (must be noted)
H323_ras means binding H323_RAS protocol when opening port 1720
H323_any means that only port 1720 is opened, and no protocol information is included.
Note: In some specific programs, protocol information needs to be bound when defining ports, such as H323, Sip protocol, etc.