节点文献
H.323数据穿越NAT和防火墙的设计与实现
Design and Realization of H.323 Data Through NAT and Firewall
【摘要】 H.323标准的视频会议系统和IP电话在实际应用中有一个非常棘手的问题:NAT(网络地址转换)与防火墙的穿透问题。H.323协议动态分配端口并产生和维护多个UDP数据流是这个问题的根源所在。绝大部分企业部门出于网络安全的考虑配置了专用防火墙,但H.323很难通过传统防火墙。IPv4地址空间的严重匮乏产生了网址转换(NAT),但NAT后的IP语音和视频设备仅有私有IP地址,在公众网上这些地址是不可路由的,所以NAT严重阻碍了H.323多媒体通讯的开展。文中提出了一种方案来解决这个问题,该方案无需对现有的防火墙系统做任何改动。
【Abstract】 There is a very knotty problem for H.323 conference system and IP telephone in practical usage. This problem is about the penetrations of NAT and firewall. The reason of this problem is that H.323 protocol allocates UDP port dynamicly and manages many UDP data stream.Considering the Internet safeness,most of departments equipped with a special firewall,however,this will induce a difficulty for H.323 to pass through the traditional firewall. Serious lack of IPv4 address space results in NAT ,but IP audio and vedio equipment only have private IP addresses.And these addresses cannot be routed in the public Internet,so NAT hampers the development for multi-media communication system seriously.At last,gives a very subtle solution for this problem, the solution does not need to change existent firewall system anything.
- 【文献出处】 微机发展 ,Microcomputer Development , 编辑部邮箱 ,2005年09期
- 【分类号】TP393.08
- 【被引频次】3
- 【下载频次】130