ZyXEL ISG50 Application Note

ISG50
Application Note
Version 1.0
June, 2011
Scenario 1 - ISG50 is placed behind an existing ZyWALL
For companies with existing network infrastructures and demanding VoIP requirements, you can connect the ISG50 to the LAN or DMZ of the ZyWALL. The USG provides security services and the ISG50 acts as a pure IP PBX to provide VoIP services.
Goal to Achieve
IP phones from the Internet can register to ISG50 through USG’s WAN IP and can talk to another IP phone which is connected under ISG50’s LAN zone.
1.2 Configuration Guide Network Conditions
USG 20W:
- WAN IP: 59.124.163.156
- SIP server IP (ISG50): 172.16.1.10
ISG50:
- WAN IP: 172.16.1.10
USG 20W: Step 1. Click CONFIGURATION > Network > Interface > Ethernet to assign USG 20W a WAN IP.
Step 2. Assume ISG50’s WAN port is connected to LAN2 (port 4) of USG 20W. Configure an IP for this interface.
Step 3. For NAT setting, the user needs to configure the following:
- Rule’s name.
- Set Virtual Server type to let USG 20W do packet forwarding.
- Fill in the Original IP (WAN IP) address.
- Fill in the Mapped IP (ISG’s IP) address.
- Configure the Original Port and the Mapped Port; here we set the SIP signaling port 5060 and RTP port range 10000-20000. Make sure these ports setting are the same as those set in ISG50.
Step 4. The user can create an address object for ISG50 for further configuration usage. Click Create new object for this function.
Step 5. Click CONFIGURATION > Network >Firewall to open the firewall configuration screen. Click on the Add button to create a firewall rule to enable the VoIP service to pass from the WAN to LAN2.
Step 6. Disable SIP ALG.
ISG50: Step 1. Set the WAN IP of USG 20W in the Fake IP field.
Loading...
+ 21 hidden pages