You are here: hacking technology > firewall > Content
Hot Articles
Recommend Articles
New Articles
How the pronunciation and do the video frequency communication pass through the firewall and NAT
  Add date: 07/09/2008   Publishing date: 07/09/2008   Hits: 111
Total 4 pages, Current page:1, Jump to page:
 
How the pronunciation and do the video frequency communication pass through the firewall and NAT

  Answer: Actually the solution firewall and a NAT question's simple the means avoid using them, to the majority organizations, this method too take risks, the network security had not guaranteed, moreover must obtain enough many may route's IP address perhaps be difficult, expensive.

  Therefore the majority hopes will carry on the multimedia communications using IP the organizations inevitable facing the firewall or the NAT challenge. In fact, the majority organizations simultaneously have used the firewall and NAT, therefore solely solves a question is also insufficient. The existing some solution is as follows:  

  1. uses the PSTN gateway  

  If not too cares outside the local area network whether based on the IP correspondence, then may use gateway's local area network on IP pronunciation and the video switch for the public circuit switching on-line PSTN pronunciation and the video frequency. Used this kind of gateway not to use the care network firewall's penetration question, because did not have the data packet to pass the firewall. This has also solved the NAT problem, possesses to the local area network in the terminal call is may the route, because enters local area network's call through the gateway is may the route. Today the majority IP telephones are carry on the communication through a gateway and the non-IP telephone. The gateway method is a partial solution, the request all participation caller after last NAT and the firewall must have a corresponding gateway.  

  2.DMZ MCU  

  Some organizations through place MCU the so-called DMZ region to solve the firewall and the NAT traversing question. The DMZ region usually is located at exterior Internet and between the internal network firewall, the wish provides their Internet service outward (e.g. the web service, the ftp service, the email service and domain name service) the organization places generally these services the DMZ region, like this may protect their private network well.  

  Places DMZ region MCU to install two network cards, the network card provides the visit private network like this together the entrance, in addition the network card provides visit public network Internet together the entrance. This solution's biggest shortcoming is even if is carries on the point-to-point call also to need to use MCU, if and has many NAT equipment in the call way, then needs in each NAT equipment's position to lay aside MCU.  

  3.H.323 proxy  

  The H.323 agent can use for to solve the NAT question or simultaneously solves NAT and the firewall question, how is this decided in acts is disposed. The proxy is one special type gateway actually, but is not the IP protocol conversion for other, what in acts nearby two to use is the same agreement. The proxy causes the terminal to look like the elephant two separation calls to the terminal call process: One is from the private on-line terminal to the proxy, another is from acts to the public on-line terminal, acted through carries on the relay to this call to solve the NAT problem.  

 
Other pages: : 1 * 2 * 3 * 4 * Next>>
Prev:Discusses the firewall classification and the application shallowly Next:Lets Vista network security (figure) with the firewall

Comment:

Category: Home > firewall