List of questions
Related questions
Question 393 - 350-801 discussion
Which actions required for a firewall configuration on a Mobile and Remote Access through Cisco Expressway deployment?
The traversal zone on Expressway-c points to Expressway-e through the peer address field on the traversal zone, which specifies the Expressway-e server address. For dual NIC deployments, set the Expressway-e address using an FQDN that resolves the IP address of the internal interface
The external firewall must allow these inbound connections to Expressway: SIP: TCP 5061; HTTPS: TCP 8443; XMPP TCP 5222; media: UDP 36002 to 59999
Do not use a shared address for Expressway-e and Expressway-c, as the firewall cannot distinguish between them. If static NAT for IP addressing on Expressway-e is used, ensure that any NAT operation on expressway-c does not resolve the same traffic IP address. Shared NAT IS not supported
The internal firewall must allow these inbound and outbound connections between expressway - c and Expressway-e :sip;HTTPS(tunneled over SSH between C and E. TCP 2222: TCP 7001: Traversal Media: UDP 2776 to 2777(or 36000 to 36011 for large VM/appliance); XMPP:TCP 7400
0 comments
Leave a comment first