Configuring remote offices for h.323 – Amer Networks E5Web GUI User Manual
Page 437

•
Comment: Allow communication from the Gateway to H.323 phones on lan_net
3.
Click OK
1.
Go to: Policies > Add > IPRule
2.
Now enter:
•
Name: BranchToGW
•
Action: Allow
•
Service: H323-Gatekeeper
•
Source Interface: vpn-branch
•
Destination Interface: dmz
•
Source Network: branch-net
•
Destination Network: ip-gatekeeper, ip-gateway
•
Comment: Allow communication with the Gatekeeper on DMZ from the Branch
network
3.
Click OK
1.
Go to: Policies > Add > IPRule
2.
Now enter:
•
Name: BranchToGW
•
Action: Allow
•
Service: H323-Gatekeeper
•
Source Interface: vpn-remote
•
Destination Interface: dmz
•
Source Network: remote-net
•
Destination Network: ip-gatekeeper
•
Comment: Allow communication with the Gatekeeper on DMZ from the Remote
network
3.
Click OK
Example 6.12. Configuring remote offices for H.323
If the branch and remote office H.323 phones and applications are to be configured to use the
H.323 Gatekeeper at the head office, the Clavister Security Gateways in the remote and branch
offices should be configured as follows: (this rule should be in both the Branch and Remote
Office security gateways).
Chapter 6: Security Mechanisms
437