PBXtech.info  
\'\'

Go Back   PBXtech.info > Avaya > IP Office

Reply
 
LinkBack Thread Tools Display Modes
Old March 3rd, 2005, 04:27 AM   #1 (permalink)
ajshaikh
PBXtech SILVER 25+ posts
 
Join Date: Feb 2004
Posts: 71
ajshaikh is on a distinguished road
Firewall & Atominc Clock

I use Chameleon Clock which is supposed to sync with atomin clock server but the IP Office Firewall does not allow the connection.

Chameleon Clock suggests the following config changes on a firewall:

[i]Not all firewalls are configured to allow SNTP protocol messages by default.
This prevents Chameleon Clock from contacting Internet time servers.
If so, you will need to get your firewall administrator to allow IP/UDP outbound packets to port 123,
and inbound IP/UDP packets from port 123. The following firewall incoming packet filter rule will allow
Chameleon Clock operate using the SNTP protocol while maintaining the security of your site.

Source Protocol = UDP
Destination Protocol = UDP
Source IP Address = Any
Destination IP Address = Any
Source Port = 123
Destination Port = >1023
Source Action = Permit
Destination Action = Permit


Please let me know what I need to change on the IP Office Firewall for this to work.

Thanks.
ajshaikh is offline   Reply With Quote
Old March 4th, 2005, 11:36 AM   #2 (permalink)
DaveA
PBXtech SILVER 25+ posts
 
DaveA's Avatar
 
Join Date: Jul 2004
Posts: 37
DaveA is on a distinguished road
Re: Firewall & Atominc Clock

You could try the following for UDP port 1023:

Notes : Clock (or whatever)
IP protocol = 17
Match Offset = 20
Match Length=4
Match Data = 000003FF
Match Mask = 0000FFFF

Leave the rest blank
For UDP Port 123 change Match data to 0000007B
Not sure if you need to set for port 123 or 1023, try both!
I think you have to re-boot after changing a firewall profile.

have fun!
__________________
------------------------------------------------------------------------------------
Click -->UK IP Office Forum. A new UK based IP Office User Group.
DaveA is offline   Reply With Quote
Advertisement
 
Advertisement
Sponsored links

Old March 4th, 2005, 11:39 AM   #3 (permalink)
DaveA
PBXtech SILVER 25+ posts
 
DaveA's Avatar
 
Join Date: Jul 2004
Posts: 37
DaveA is on a distinguished road
Re: Firewall & Atominc Clock

having re-read your post, I think 1023 may have been a typo,
so use 7B in the match data.
For direction you will need either Out or Bothway.
Out should do it, dont know why the time server would want to contact your server
without a request.

Cheers
__________________
------------------------------------------------------------------------------------
Click -->UK IP Office Forum. A new UK based IP Office User Group.
DaveA is offline   Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Phone Manager through a Firewall PSNZ IP Office 6 December 1st, 2005 04:31 PM
S8700 Firewall questions. fataldata Definity Servers 0 November 19th, 2004 12:27 PM
firewall and bcms vu casfung Definity Servers 7 October 28th, 2004 11:10 AM
Using network as Clock source dlgouse Definity Servers 2 October 15th, 2004 11:30 AM
TN2181 Tone Clock tele234 Definity Servers 14 July 22nd, 2003 04:39 PM


All times are GMT -6. The time now is 10:54 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0 RC6
Copyright ©2002 - 2007, PBXtech LLCAd Management by RedTyger

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37