LifeSize Icon Video System Guide 6
Firewall Settings for Ports
At a minimum, block external or inbound access to the following ports:
• 22 (SSH)
• 80 (HTTP)
• 443 (HTTPS)
LifeSize recommends that these ports remain open for internal administrator access. Ensure that you
change the default administrator password to be secure. Change the administrator password in
Preferences > Passwords.
You can disable SSH and web access on the system in Preferences > Security.
Call Setup and Media Ports
To place calls to other systems through the firewall, you must configure your firewall to allow incoming and
outgoing traffic to the system through the following:
Restricting Reserved Ports
To place calls to other devices through a firewall, you must configure your firewall to allow incoming and
outgoing traffic to the LifeSize system through the reserved ports. Users placing calls through a firewall to
systems with public IP addresses may experience one-way audio or video if the firewall is not properly
configured to allow two-way audio and video traffic.
By default, LifeSize systems communicate through TCP and UDP ports in the range 60000 - 64999 for
video, voice, presentations, and camera control. LifeSize systems use a subset of these ports during a call.
NOTE The minimum number of required ports is 100.
To minimize the number of UDP and TCP ports that are available for communication, restrict the range by
changing values in Preferences > Network > Reserved Ports. LifeSize recommends that the range you
choose, if other than a subset of the default range, begins with a port number greater than 49151. The
range must start with an even number and end with an odd number to include an even number of total
ports. For a range that starts at 62000, set the lower end to 62000 and the upper end to 62099 to allocate
a range of 100 ports, the minimum.
UDP port 1719
TCP port 1720
Gatekeeper registration.
H.323 call negotiation.
UDP port 5060 SIP call negotiation.
TCP port 5060 SIP call negotiation if TCP signaling is enabled for SIP calls.
TCP port 5061 TLS signaling in SIP calls if TLS signaling is enabled.
Required TCP and
UDP ports
Range specified in Preferences > Network > Reserved Ports.