EasyManuals Logo

Grandstream Networks GXV3370 Security Guide

Grandstream Networks GXV3370
27 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #26 background imageLoading...
Page #26 background image
P a g e | 25
GXV3370 Security Guide
SECURITY GUIDELINES FOR GXV3370 DEPLOYMENT
Often times the GXV3370s are deployed behind NAT. The network administrator can consider following
security guidelines for the GXV3370 to work properly and securely.
Turn off SIP ALG on the router
On the customer’s router, it’s recommended to turn off SIP ALG (Application Layer Gateway). SIP ALG
is common in many routers intending to prevent some problems caused by router firewalls by inspecting
VoIP packets and modifying it if necessary. Even though SIP ALG intends to prevent issues for VoIP
devices, it can be implemented imperfectly causing problems, especially in some cases SIP ALG
modifies SIP packets improperly which might cause VoIP devices fail to register or establish calls.
Use TLS and SRTP for SIP calls
On the GXV3370, it’s recommended to use TLS for SIP transport with “sipsin SIP URL scheme for
SIP signaling encryption, and use SRTP for media encryption. Below table lists all the SIP ports and
RTPs port used on the GXV3370 if the network administrator needs to create firewall rules.
SIP
Account x
Default Local SIP
Port
Audio RTP/RTCP
Port
Video RTP/RTCP
Port
FEC RTP/RTCP
Port
BFCP Protocol Port
BFCP RTP/RTCP Port
Account 1
5060 for UDP/TCP
5061 for TLS
RTP: 50040
RTCP: 50041
RTP: 50042
RTCP: 50043
RTP: 50044
RTCP: 50045
BFCP Protocol: 50046
RTP: 50048
RTCP: 50049
Account 2
5062 for UDP/TCP
5063 for TLS
RTP: 50050
RTCP: 50051
RTP: 50052
RTCP: 50053
RTP: 50054
RTCP: 50055
BFCP Protocol: 50056
RTP: 50058
RTCP: 50059
Account 3
5064 for UDP/TCP
5065 for TLS
RTP: 50060
RTCP: 50061
RTP: 50062
RTCP: 50063
RTP: 50064
RTCP: 50065
BFCP Protocol: 50066
RTP: 50068
RTCP: 50069
Account 4
5066 for UDP/TCP
5067 for TLS
RTP: 50070
RTCP: 50071
RTP: 50072
RTCP: 50073
RTP: 50074
RTCP: 50075
BFCP Protocol: 50076
RTP: 50078
RTCP: 50079
Account 5
5068 for UDP/TCP
5069 for TLS
RTP: 50080
RTCP: 50081
RTP: 50082
RTCP: 50083
RTP: 50084
RTCP: 50085
BFCP Protocol: 50086
RTP: 50088
RTCP: 50089
Account 6
5070 for UDP/TCP
5071 for TLS
RTP: 50090
RTCP: 50091
RTP: 50092
RTCP: 50093
RTP: 50094
RTCP: 50095
BFCP Protocol: 50096
RTP: 50098
RTCP: 50099
Account 7
5072 for UDP/TCP
5073 for TLS
RTP: 50100
RTCP: 50101
RTP: 50102
RTCP: 50103
RTP: 50104
RTCP: 50105
BFCP Protocol: 50106
RTP: 50108
RTCP: 50109

Table of Contents

Other manuals for Grandstream Networks GXV3370

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Grandstream Networks GXV3370 and is the answer not in the manual?

Grandstream Networks GXV3370 Specifications

General IconGeneral
BrandGrandstream Networks
ModelGXV3370
CategoryIP Phone
LanguageEnglish

Related product manuals