Firewall Wizards mailing list archives

Re: H.323


From: Laurent LEVIER <llevier () argosnet com>
Date: Sat, 27 Feb 1999 10:00:45 +0100

Hi,

The H.323 voice on IP protocol is evaluated in our area (Sophia-Antipolis)
by a site called ETSI.

They have a private network (from France to US) used for evaluation (people
from Vocaltec, Microsoft, White Pine, ... comes at this occasion) &
compatibility checks and they should know all about this protocol.

I have no name to give you for information, but you maybe will find info on
their site :
http://www.etsi.fr

At 10:20 26/02/99 -0500, you wrote:
Hi,

I am interested in obtaining "lessons learned" from those of you who may
have implemented H.323 (especially if you used NetMeeting).  Specifically, I 
am interested in the following:

1. Does your firewall support H.323 via an application proxy?
2. If so, WRT "dynamic port allocation", how exactly does your firewall
    handle the process?
3.  What type of firewall do you have (circuit, stateful filtering, etc)?
4.  Any security issues?  Note, H.323 v2 has enhanced security to include 
    authentication, integrity, privacy, and non-repudiation, although we may 
    be using NetMeeting... In reviewing last year's thread (Jun-Sep), I
saw a 
   concern about the "shared application execution facility enabling remote 
   users to execute unintended program on other participant's workstations" 
   but I never really saw anything specific. 
5.  Any performance issues (relative to the amount of bandwidth made
available 
    for H.323)? 
6.  What would you have done differently? 7.  What did you do that 
   you were glad you did?

I will post a summary to the list, so if you reply off-line I will not use 
your 
name, unless you specifically grant me permission.

Thanks,

Joe

Laurent LEVIER
Systems & Networks
Security Specialist

Argosnet Security Server : http://www.Argosnet.com
"Le Veilleur Technologique", "The Technology Watcher"



Current thread: