Link to home
Start Free TrialLog in
Avatar of AMtek
AMtekFlag for United States of America

asked on

Allow ports for VoIP on a cisco router and QoS

per the ISP I have to allow certain traffic into our cisco router for VoIP traffic, was wondering what the best approach might be?

for example i need to allow tcp/udp ports 5060 - 5061, 2427 and 2727, etc.
then they mention a QoS template and recommend queuing method C or B.

going through a lot of info i'm just getting lost and hoping someone could help
i'm guessing inbound ACLs on the external interface, but don't know what the best way to accomplish?

thanks,
Avatar of alltechdenny
alltechdenny
Flag of United States of America image

I usually tend to define rules for STUN and SIP based on the sockets required and bound to the static of the carrier and for instance Carrier X requires 3478 to PBX internal 192.168.X.10 so create rule to allow ONLY 3478 from Carrier X. Are you provisioning phones externally are all behind firewall? What PBX are you using?
Avatar of AMtek

ASKER

thx for the reply, it's not a PBX it's a 'hosted' solution from the ISP.

they said i just needed to make sure certain ports are open on the router and set up QoS
the phones are on their own VLAN/Subnet, routing is good, DHCP is set and confirmed, L3 routing with a switch is working perfect, just not sure about if there is any nat or a combo of nat and acl to open ports

i'm really out of practice for acls and have never configured QoS so i'm at a loss how to attack
What I personally would do then is verify ports ( usually 3478,5000,5060,5061,9000-9049) and create a rule for traffic to the ISP provided source. The QOS should be in the internal page. What model Switch? SG200?
Avatar of AMtek

ASKER

i have a list of the ports, no ISP source as of yet
TCP ports 5060 and 5061 (for SIP)
UDP ports 5060 and 5061 (for SIP)
TCP ports 2427 and 2727 (for MGCP)
UDP ports 2427 and 2727 (for MGCP)
UDP ports 16384-32767 (for RTP)1
TCP port 123 and UDP port 123 (for NTP)
TCP port 69 and UDP port 69 (for TFTP)
TCP port 80 and UDP port 80 (for HTTP)
TPC port 2208 and UDP port 2208 (for HTTP)
TPC port 443 and UDP port 443 (for HTTP)

two switches, a 2960XR is doing the routing, phones are connected to voice vlan 10 on a 2960X switch
the 2960XR is connected to a 1941 router
What kind of speed from ISP?
Avatar of AMtek

ASKER

100Mb
I have a client with 24 phones (External) @ 100/100 and zero issues with no QOS so you MAY not even need it depending on what else they do there but I would begin with defining the source "all traffic" rule to VLAN sub and see how it sounds...may be a breeze!
Avatar of AMtek

ASKER

do you have an example? i'm not even sure of the syntax
ASKER CERTIFIED SOLUTION
Avatar of alltechdenny
alltechdenny
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Did you try? Mark as answer if all set Please.
Avatar of AMtek

ASKER

thanks, ended up going a totally different way. but i appreciate the responses.
Absolutely!