| Author |
Message |
jvel7
New Forum Member


Joined: Jun 08, 2006
Posts: 2
|
I am planning on getting the Vonage service with a Linksys WRT54G for use at home with my lan and pix firewall. Which is the optimal configuration: 1) setup the Linksys behind the firewall and open the port(s) or 2) set it up outside the pix?
Now if I put it inside, which port(s) need to be opened or forwarding? From a security stand point, I know this is the least preferred but will the service operate better in this configuration?
Presently, my pix outside NIC is setup to yank DHCP from the ISP so I can setup the Linksys to provide DHCP to the pix but I don't know how that will affect the DHCP server on the inside already. So I figured I can NAT the Linksys to the Pix outside and then NAT again to the Pix inside.
I don't want to use the Linksys as an access point nor will I be hanging computers or other lan devices off of it. It will strictly be used for Voip.
Will this work or is it over kill?
All suggestions welcomed...
jvel7 |
|
|
|
|
 |
EzCo
Vonage Forum Evangelist


Joined: Jul 21, 2005
Posts: 533
Location: Southeastern PA
|
| jvel7 wrote: | I am planning on getting the Vonage service with a Linksys WRT54G for use at home with my lan and pix firewall. Which is the optimal configuration: 1) setup the Linksys behind the firewall and open the port(s) or 2) set it up outside the pix?
Now if I put it inside, which port(s) need to be opened or forwarding? From a security stand point, I know this is the least preferred but will the service operate better in this configuration?
Presently, my pix outside NIC is setup to yank DHCP from the ISP so I can setup the Linksys to provide DHCP to the pix but I don't know how that will affect the DHCP server on the inside already. So I figured I can NAT the Linksys to the Pix outside and then NAT again to the Pix inside.
I don't want to use the Linksys as an access point nor will I be hanging computers or other lan devices off of it. It will strictly be used for Voip.
Will this work or is it over kill?
All suggestions welcomed...
jvel7 |
I recommend you keep the PIX on the outside, that's what you have it for. Put the WRT54G behind it. You don't need to permit any traffic inbound to the WRT, everything is outbound with Vonage. The only thing I recommend you add is:
icmp permit 216.115.16.0 255.255.240.0 echo outside
This will allow Vonage to ping the outside interface of your PIX, which, because you'll NAT everything to the address of that interface, they think it's your ATA.
Also, you may want to change your sip udp fixup to be:
fixup protocol sip udp 5061
since Vonage uses 5061 instead of 5060. I don't use my PIX anymore, but I was just flipping through my old config and noticed that. I actually never changed it, but you may want to.
Hope that helps. |
_________________ Comcast 6M/384K -> Cisco 1711 -> RTP300, Juniper 5GT Wireless "Does anybody remember forests?" |
|
|
|
 |
jvel7
New Forum Member


Joined: Jun 08, 2006
Posts: 2
|
EzCo....thanks for your comments and suggestion. I will certainly give it a shot. |
|
|
|
|
 |
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum |
All times are GMT - 5 Hours | |