PDA

View Full Version : firewall traversal


bdldunworthy
10-11-2005, 04:12 PM
Hey,

I am trying to traverse 2 firewalls. I need to connect to a school with polycom video conferencing equipment. I use tandberg equipment and apparently that other school would need a tandberg gatekeeper for this to work; however i have no control over their end and I'm sure they aren't going to listen to me when i tell them they need to buy more equipment.

What about software to traverse the firewalls... or even opening ports?
Does anyone know of a solution or atleast somewhere I can research this?

thanks
Robert

trapehzoid
10-11-2005, 08:14 PM
Hey,

I am trying to traverse 2 firewalls. I need to connect to a school with polycom video conferencing equipment. I use tandberg equipment and apparently that other school would need a tandberg gatekeeper for this to work; however i have no control over their end and I'm sure they aren't going to listen to me when i tell them they need to buy more equipment.

What about software to traverse the firewalls... or even opening ports?
Does anyone know of a solution or atleast somewhere I can research this?

thanks
Robert


the other side doesn't need a tandberg gatekeeper.. but to really do things like firewall traversal you need gatekeepers or some sort or other proxy method. the systems behind the firewall are not directly accessible.. so you can set something up to allow outgoing only calls, but it is clunky.. and if you can't call into the other side because its also behind a firewall.. then you are catch-22. You both can't call outbound to reach each other.

the tandberg expressway solution is pretty cool, but you do need to be using gatekeeper technology. I suggest if you are not already, you start doing so now. You will constantly be chasing your tail if you do not.

If money is a concern, I'd consider looking at the GNU gatekeeper

Basically you can try setting up static rules through the firewall (not so bad if you only have one endpoint and it doesn't move), or look at firewall traversal methods. If you only have one system at each, as much as it sucks, money wise you are probably better off to try to work with static firewall rules allowing the 323 traffic.