ZyXEL Communications ZyWALL 1000 User Manual

Page of 780
Chapter 18 ALG
ZyWALL USG 1000 User’s Guide
266
You could also have a trunk with one interface set to active and a second interface set to 
passive. The ZyWALL does not automatically change ALG-managed connections to the 
second (passive) interface when the active interface’s connection goes down. When the active 
interface’s connection fails, the client needs to re-initialize the connection through the second 
interface (that was set to passive) in order to have the connection go through the second 
interface. VoIP clients usually re-register automatically at set intervals or the users can 
manually force them to re-register.
18.1.3  FTP
File Transfer Protocol (FTP) is an Internet file transfer service that operates on the Internet and 
over TCP/IP networks. A system running the FTP server accepts commands from a system 
running an FTP client. The service allows users to send commands to the server for uploading 
and downloading files. The FTP ALG allows TCP packets with a port 21 destination to pass 
through. If the FTP server is located on the LAN, you must also configure NAT port 
forwarding and firewall rules if you want to allow access to the server from the WAN.
18.1.4  H.323
H.323 is a standard teleconferencing protocol suite that provides audio, data and video 
conferencing. It allows for real-time point-to-point and multipoint communication between 
client computers over a packet-based network that does not provide a guaranteed quality of 
service. NetMeeting uses H.323.
18.1.5  RTP
When you make a VoIP call using H.323 or SIP, the RTP (Real time Transport Protocol) is 
used to handle voice data transfer. See RFC 1889 for details on RTP.
18.1.5.1  H.323 ALG Details
• The H.323 ALG supports peer-to-peer H.323 calls.
• The H.323 ALG handles H.323 calls that go through NAT or that the ZyWALL routes. 
You can also make other H.323 calls that do not go through NAT or routing. Examples 
would be calls between LAN IP addresses that are on the same subnet.
• The H.323 ALG allows calls to go out through NAT. For example, you could make a call 
from a private IP address on the LAN to a peer device on the WAN. 
• The H.323 ALG operates on TCP packets with a port 1720 destination.
• The ZyWALL allows H.323 audio connections. 
• The ZyWALL can also apply bandwidth management to traffic that goes through the 
H.323 ALG.
The following example shows H.323 signaling (1) and audio (2) sessions between H.323 
devices A and B.