IP Communicator (soft phone) outside the network without VPN

I need to know what is required to have a soft phone communicate with my UC520 when I am outside the network. There are a number of hotels that block VPN protocols.

I have tried opening ports 2000-2002 and the RTP ports, as well as creating a 1-1 NAT and the proper access-lists and unable to communicate with the UC520.

Thanks,
Mario

0
Your rating: None

.

.

The UC520 box includes an

The UC520 box includes an SSL VPN. This supports a number of options, including a thin-clent port forwarding solution. You might be able to use the SSL VPN to connect to your main site via port 443 and then forward the rest of your VoIP ports with the thin-client service, all encapsulated in port 443 packets of course.

I haven't labbed this exact scenario yet, but it is on my to-do list.

Cisco IP Communications Express Specialist
www.ketchumits.com

ttrentler's picture

SSL VPN on UC520

Interesting . . . .
To Bad the CCA does not yet help you configure an SSL VPN and the Cisco's SDM tool does not work with the UC500.
I do see in the data sheet that SSL VPN is supported on the product. I gues it just has to be configured from the CLI.

If a hotel blocks vpn traffic....

don't you think they will block other ports as well? So no matter what you do on your end, its not going to change the fact that you can only use outbount ports 80 and 443 from the hotel. Not only that, but do you really wnat to send unencrypted/secured voice traffic through the internet? Too much of a risk for me and my clients to even consider.

Personally, i have never stayed in a hotel in which they perma banned all VPN connections. Normally if you call to the front desk, they will give you what you need to create the vpn tunnel. Howeve,r i haven't stayed in all Hotels, so I am sure there are some that do.

The only way to get voice working across the internet withouth using a VPN is to have remote teleworker setup using ASA or 800 series firewalls on each remote endpoint. (which you can't use as you are at a hotel) I am not even sure if you can even use this feature with CME as i beleive its goin to be a new thing with CM 7.

Best course of action: plan your itenerary accordingly and ask before booking if your room has VPN capabilities.

HTH

- Brugh

I got the IPC to connect and

I got the IPC to connect and ring. The only problem I have is that when a call is connected, I cannot hear the caller and the caller cannot hear me.

What port needs to be open for this?

jnikolatos's picture

That may be a gateway issue.

That may be a gateway issue.

I would not suggest doing what you are trying (disabling the firewall) only becuase your phone system is going to get hacked within a few minutes of you getting this to work.

John

NIKTEK

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.