RTSP and H323 Support for Multimedia Applications
Cisco IOS classic firewall supports a number of protocols for multimedia applications that require delivery of data with real-time properties such as audio and video conferencing. This support includes the following multimedia application protocols:
■ Real-Time Streaming Protocol (RTSP) (for example, RealNetworks)
■ H.323 version 2 (H.323v2) (for example, Microsoft Windows NetMeeting (NetMeeting), Intel ProShare)
RTSP and H.323v2 inspection allows clients on a protected network to receive data associated with a multimedia session from a server on an unprotected network.
RTSP Support
RTSP is the Internet Engineering Task Force (IETF) standards-based protocol (RFC 2326) for control over the delivery of data with real-time properties such as audio and video streams. It is useful for large-scale broadcasts and audio or video on demand streaming, and is supported by a variety of vendor products for streaming audio and video multimedia, including Cisco IP/TV, RealNetworks RealAudio G2 Player, and Apple QuickTime 4 software.
RFC 2326 allows RTSP to run over either UDP or TCP, though Cisco IOS classic firewall currently supports only TCP-based RTSP. RTSP establishes a TCP-based control connection, or channel, between the multimedia client and server. RTSP uses this channel to control commands such as "play" and "pause" between the client and server. These control commands and responses are text-based and are similar to HTTP.
RTSP typically relies on a UDP-based data transport protocol such as standard Real-Time Transport Protocol (RTP) to open separate channels for data and for RTP Control Protocol (RTCP) messages. RTP and RTCP channels occur in pairs, with RTP being an even-numbered port, and RTCP being the next consecutive port. Understanding the relationship of RTP and RTCP is important for verifying session information using Cisco IOS classic firewall show commands.
© 2007 Cisco Systems, Inc. Adaptive Threat Defense 5-27
The RTSP client uses TCP port 554 or 8554 to open a multimedia connection with a server. The data channel or data control channel (using RTCP) between the client and the server is dynamically negotiated between the client and the server using any of the high UDP ports (1024 to 65536).
Cisco IOS classic firewall uses this port information along with connection information from the client to create dynamic ACL entries in the firewall. As TCP or UDP connections are terminated, Cisco IOS classic firewall removes these dynamic entries from the appropriate ACLs.
Cisco IOS classic firewall support for RTSP includes the following data transport modes:
■ Standard RTP: RTP is an IETF standard (RFC 1889) supporting delivery of real-time data such as audio and video. RTP uses the RTCP for managing the delivery of the multimedia data stream. This is the normal mode of operation for Cisco IP/TV and Apple QuickTime 4 software.
■ RealNetworks Data Transport (RDT): RDT is a proprietary protocol developed by RealNetworks for data transport. This mode uses RTSP for communication control and uses RDT for the data connection and retransmission of lost packets. This is the normal mode of operation for the RealServer G2 from RealNetworks.
■ Interleaved (tunnel mode): In this mode, RTSP uses the control channel to tunnel RTP or RDT traffic.
■ Synchronized Multimedia Integration Language (SMIL): SMIL is a layout language that enables the creation of multimedia presentations consisting of multiple elements of music, voice, images, text, video, and graphics. This involves multiple RTSP control and data streams between the player and the servers. This mode is available only using RTSP and RDT. SMIL is a proposed specification of the World Wide Web Consortium (W3C). The RealNetworks RealServer and RealServer G2 provide support for SMIL—Cisco IP/TV and Apple QuickTime 4 do not.
H.323 Support
Cisco IOS classic firewall support for H.323 inspection includes H.323v2 and H.323 version 1 (H.323v1). H.323v2 provides additional options over H.323v1, including a fast start option. The fast start option minimizes the delay between the time that a user initiates a connection and the time that the user gets the data (voice, video). H.323v2 inspection is backward-compatible with H.323v1.
With H.323v1, after a TCP connection is established between the client and server (H.225 channel), a separate channel for media control (H.245 channel) is opened through which multimedia channels for audit and video are further negotiated.
The H.323v2 client opens a connection to the server that is listening on port 1720. The data channel between the client and the server is dynamically negotiated using any of the high UDP ports (1024 to 65536).
Cisco IOS classic firewall uses this port information along with connection information from the client to create dynamic ACL entries in the firewall. As TCP or UDP connections are terminated, Cisco IOS classic firewall removes these dynamic entries from the appropriate ACLs.
Securing Networks with Cisco Routers and Switches (SNRS) v2.0
5-28
Continue reading here: Basic ACL Configuration
Was this article helpful?
Readers' Questions
-
LOUIS3 months ago
- Reply
-
daniela5 months ago
- Reply
-
raimondo7 months ago
- Reply
-
PRISCA7 months ago
- Reply
-
amy8 months ago
- Reply
-
Negisti8 months ago
- Reply