Re: [GnomeMeeting-list] Gnomemeeting and firewall rules?



le mar 05-03-2002 à 16:22, Jonathan A. Davis a écrit :
> On 5 Mar 2002, Jeffrey Bell wrote:
> 
> > 
> > What is everybody else doing with reguards to gm behind a firewall?
> > 
> > 
> 
> I'm doing pretty much the same thing.  The only thing is, although I'm
> running 2.4.17 on the NAT box, I shoehorned the (for 2.4.13)  
> newnat-suite from http://www.kfki.hu/%7Ekadlec/sw/netfilter/newnat-suite.
> Mainly as I didn't know there *was* a CVS lurking around with something
> newer.  :-)
> 
> In any case, I have basically the identical entries such as:
> 
> $IPTABLES -A PREROUTING -i $GATEWAY -p tcp -m tcp --dport 1720 -j DNAT 
> --to-destination athena
> 
> One difference might be that I'm not summarily DROPping ports above 1023, 
> but only selected ones.
> 
> If memory serves, net/gnomemeeting uses the following:
> 
>  389/TCP     ILS
>  522/TCP     ULS
> 1503/TCP     T.120

You do not need the above port with GnomeMeeting.

> 1720/TCP     H.323 & H.225 (video and call setup)
> 1731/TCP     Audio

You do not need the 1731 port with GnomeMeeting
>  Dyn/TCP     H.245

If you use H.245 Tunneling, you do not need it.
But I think that Netmeeting doesn't support Tunneling, so perhaps that
the module do not support it neither. Im not sure of what happens.

Paul will certainly describe his config here, it works for him.

Perhaps that you could also try to install openh323gk (do a search on
google) and enable the proxy mode for that gatekeeper.

>  Dyn/UDP     RTCP/RTP
> 
> Thus you may need to check and open a hole for 1731...
> 
> -- 
> 
> -Jonathan <davis jdhouse org>
> 
> _______________________________________________
> Gnomemeeting-list mailing list
> Gnomemeeting-list gnome org
> http://mail.gnome.org/mailman/listinfo/gnomemeeting-list
> 
-- 
 _	Damien Sandras
(o-	GnomeMeeting - H.323 Video-Conferencing application -
//\		web:  http://www.gnomemeeting.org/
v_/_	FOSDEM 2002  - Free Software and Open Source Developers Meeting -
		web:  http://www.fosdem.org/

Attachment: signature.asc
Description: This is a digitally signed message part



[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]