> It's been a minute since I've set this up in a corp/campus wifi scenario, but my notes for Verizon
> VoWiFi from the last time I did say that you need outbound udp/500 and udp/4500 IPSec protocol
> (IKE and ESP) permitted out the firewall. Tunnel endpoints live in 141.207.0.0/16,
so hopefully that
> lets you scope the rule enough to please your ISO.
Alex, thanks for the netblock info. ISO's accepted an 'any' scoped to a destination of just this new network; I already land it via GRE on a separate zone from the rest of the campus network. They would, however like me to tighten it up as much as possible
so the VZW netblock is a massive help.
John C. Lyden
Hey gang.
We’re setting up a unified wireless network for the students here, and to get around the issues with Nintendo and NAT we devoted a large chunk of public IP space to them.
We’re aware that this is causing issues with wifi calling on Verizon, TMo etc because it appears they initiate the SIP session inbound.
Does anybody have a handy list of IP blocks and ports? T-Mobile had a decent page but other providers just said “open up 4500 and 500” and our ISO guys don’t like that.
Thanks if someone can help.
John C. Lyden
Manager of Network Infrastructure, Infrastructure Services
Division of Information Resources & Technology, Rowan University
Alex Buie |
Associate Network Engineer |
Datto, Inc. |
475-288-4550 (o) 585-653-8779 (c) |
www.datto.com |
Join the conversation! |