Re: [GnomeMeeting-list] working through restrictive firewall



Hi Morris,

Am Do, den 29.04.2004 schrieb Morris Beverly um 19:58:
> Hi,
> 
> I guess this is beating a dead horse, but I'm going to ask anyway since the 
> reason is to help isolated medical patients (in this case bone marrow 
> transplant recipients) communicate with their families.

usually, where there's hope, there's a way (at least in un*x there
almost everywhere is a way) ;)

> I know that the best way to get through a firewall is to open up the 
> required ports, or to change to a gatekeeper, or SIP gateway.  However, the 
> people I'm trying to help have no real technical expertise themselves at 
> the home side and the hospitals' IT staff generally have bigger/other fish 
> to fry or are simply too swamped to find time to work on it.

well, depends on the net they're running. OpenH323 1.13.5/PWLib 1.6.6
have capabilities to transparently tunnel NAT if the calling side is
behind and the called side is on public IP. That way you could try "just
calling".. Maybe it'll work out of the box. (For which distro you're
targetting?)

> Is it possible to set up a vpn or something similar to tunnel all network 
> traffic through a single port (preferably port 80 since it's almost always 
> open) so that all the h323 ports are "open" between both computers?  I'm 
> sorry if this is a dumb/unworkable/already dismissed idea, but I'm stumped 
> and would really like to be able to help these folks.

VPN on single port may be an idea.. but aswell you could setup a
gatekeeper and assign a port-range to it.. Same goes for a gateway and
all other means.. even the VPN will most likely need a free port for
each client. Remember you're running real-time communication, so you
want to have UDP and allow packet loss or at least throw away late
packets.. So if your VPN will wait for the missing piece before
continuing, you'll have a bad GM experience due to high latency.. (150ms
and below is counted as low-latency or real-time for usual PSTN
services, your VPN should preferrably not go above that, at least not
above 300ms for my personal choice)

maybe for your live-cd you're lucky trying debix, which is a
"i-want-to-have-some-knoppx-style-cd-with-my-personal-choice-of-software"..
then you just need to tailor a meta-package to grab your VPN settings
for that user (or you have one CD per client) and off you go ;)

-- 
Best regards,
 Kilian

Attachment: signature.asc
Description: Dies ist ein digital signierter Nachrichtenteil



[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]