Topologies Requiring H.225 Configuration; H.225 Map Commands - Cisco 7604 Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

H.323 Inspection

Topologies Requiring H.225 Configuration

Some additional H.225 configuration may be required in a topology where call control happens between
H.323 endpoints connecting through an FWSM (see
Figure 22-8
Cisco Catalyst 6000
In this topology, call signaling occurs between the Cisco CallManager and the HSI on one side of the
FWSM and between the HSI and the Cisco CallManager endpoint on the other side. Afterwards, call
control happens directly between the Cisco CallManager and the Cisco CallManager endpoint. When
the HSI and one endpoint is on a network protected by the FWSM and the other endpoint is on another
network, the call control may not go through without additional H.225 configuration.
The FWSM is not aware of the existence of the Cisco CallManager in this topology. With only the packet
flows that happen through the security appliance, the FWSM cannot open a proper pinhole to allow such
a call to be successful. For this reason, some additional H.225 configuration is required in this scenario.
To provide the necessary configuration, you identify an HSI and its associated endpoints within an HSI
group. After this configuration is completed, when the FWSM sees the HSI as one of the communicating
hosts in an H.225 connection, it opens H.245 holes between the endpoints in the HSI group. The actual
H.245 connection will match one of these pinholes and will go through properly.

H.225 Map Commands

The H.225 map allows the FWSM to open dynamic, port-specific pinholes for an H.245 connection when
an HSI is involved in H.225 call-signalling. The H.225 map provides information about the HSI and its
associated endpoints, which is required to establish this connection without compromising the security
of the network protected by the FWSM.
The h225-map command lets you create an H.225 map. One H225 map can contain a maximum of five
HSI groups.
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
22-50
Topology Requiring H.225 Configuration
IP Core
10.10.212.1
10.10.212.0
FWSM 3.1
NAT enabled
10.3.6.1
M
CME
Table 22-5
lists the commands available in H.225 map configuration mode.
Chapter 22
Figure
22-8).
PGW
EISUP
HSI
10.10.15.11
H.323
10.10.25.5
H.245
M
CCM IPCC
Applying Application Layer Protocol Inspection
OL-20748-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents