Download RedMax EXtreme EX-LRT Troubleshooting guide

Transcript
Note that in the case where the SIP traffic runs on a different IP/Subnet from media, then this
second security-policy for SIP signaling is not required.
In the security-policies configured below, note that SIP traffic is expected in 11.0.0.11 and port 5060,
using any transport-protocol (so both UDP and TCP SIP traffic is accepted), and SRTP traffic is also
configured for 11.0.0.11 (i.e. no signaling/media separation).
security-policy
name
network-interface
priority
local-ip-addr-match
remote-ip-addr-match
local-port-match
remote-port-match
trans-protocol-match
direction
local-ip-mask
remote-ip-mask
action
ike-sainfo-name
outbound-sa-fine-grained-mask
local-ip-mask
remote-ip-mask
local-port-mask
remote-port-mask
trans-protocol-mask
valid
vlan-mask
security-policy
name
network-interface
priority
local-ip-addr-match
remote-ip-addr-match
local-port-match
remote-port-match
trans-protocol-match
direction
local-ip-mask
remote-ip-mask
action
ike-sainfo-name
outbound-sa-fine-grained-mask
local-ip-mask
remote-ip-mask
local-port-mask
remote-port-mask
trans-protocol-mask
valid
vlan-mask

Both RTP/SRTP support
Oracle SBC Security Guide
signaling
M00:0
1
11.0.0.11
0.0.0.0
5060
0
ALL
both
255.255.255.255
0.0.0.0
allow
255.255.255.255
255.255.255.255
0
0
0
enabled
0xFFF
media
M00:0
2
11.0.0.11
0.0.0.0
0
0
UDP
both
255.255.255.255
0.0.0.0
srtp
0.0.0.0
255.255.255.255
0
65535
255
enabled
0xFFF