We have relaunched: What's new at ZDNet Asia?

Set up secure anywhere video conferencing

Summary

Now that video conferencing is portable, and it now exists on your computer network, a number of concerns arise--one of which is security.

Events

The 2nd InfoSecurity Summit HK 2010
17 Mar 2010

Hong Kong Convention and Exhibition Centre, Hong Kong

IT Architect Regional Conference Singapore 2010
20 - 21 Apr 2010

Singapore Management University, Singapore

The Internet Show 2010
21-22 Apr 2010

Suntec Singapore

Video conferencing has become a powerful and diverse method of communication. Even though it was once thought of as an expensive method of communication for organizations with large budgets, that's no longer the case.

Video conferencing can be implemented at home, in the workplace, and even at school. Friends and family can communicate visually, business people can collaborate visually. And students can visit places (and learn from professionals) across the world.

In the past, video conferencing was done over special communication lines (such as ISDN) and was usually located in a designated room or location. With the recent move to IP-based video conferencing these limits have been removed. With the significant increase in Internet bandwidth content has also been enhanced.

Now that video conferencing is portable, and now exists on your computer network, a number of concerns arise--one of which is security. How can you set up secure anywhere IP video conferencing?

For the bulk of this article we are going to assume that we are working with a Polycom ViewStation EX (http://www.polycom.com) video conferencing unit. Polycom makes a variety of portable and PC-based video conferencing devices. However, the information applies to Tandberg, and other video conferencing software/hardware vendors.

Initial setup
The initial setup process is a rather simple one. The PolycomViewStation EX requires power, a network connection, and a display (either a TV or a projector). The configuration can be completed by using the supplied remote control. Once an IP address, subnet mask, and default gateway is assigned, the rest of the configuration can be done by using the web interface. It would be ideal to set a unique DNS name for the device so that it can easily be recognized. If there is NAT/PAT in use for Internet access, the ViewStation will automatically detect what its external IP address is (if for some reason it doesn't, it can be set manually).

NOTE: Instead of assigning a static IP address, it would be best to configure a DHCP reservation for each LAN/VLAN to make the unit more easily portable.

There are other advanced settings that can be adjusted. However, at this point the device setup is complete. If there is another video conferencing device on your private network, you can connect the two. The next step is to set up the connection to the outside world.

Internet (external) connectivity
Setting up the network to allow the video conferencing unit access to the outside world is quite a bit more difficult than the initial setup. Keeping the connectivity and access secure can be complex as well. The below information assumes that a Cisco PIX firewall is used to secure the internal network from the outside wall. However, the concepts apply to other scenarios as well.

It's necessary to configure the Cisco PIX with a NAT entry to link the video conferencing unit's internal IP to its assigned external IP. The commands are as follow:

static (inside,outside) 50.50.52.52 10.90.7.254 netmask 255.255.255.255 0 0

Depending on the version of code on the PIX this command may be needed as well:

alias (inside) 10.90.7.254 50.50.52.52 255.255.255.255

Additionally, the Cisco PIX (by default on all code versions) attempts to control H.323 traffic (video and audio for conferencing) in a way that conflict with most, if not all, video conferencing systems other than Microsoft NetMeeting. To fix that, enter the follow command:

nofixup protocol h323 1720
  • The above commands assume a private IP address of 10.90.7.254 and a public IP address of 50.50.52.52
  • All of the above commands must be entered in Global Configuration Mode
  • There must be one NAT entry per unique IP used internally

The next step is to open the required ports on the Cisco PIX. Primarily the video conferencing unit uses the H.323 protocol. However, there are a number of ports that must be opened:

Port Number

Port Name

Description

80 (TCP)

HTTP

Optional for external administration

389 (TCP)

LDAP

ILS registration

1503 (TCP)

T.120

1720 (TCP)

H.323

H.323 call setup

1731 (TCP)

H.323

H.323 audio call control

1024-65535 (UDP)

H.245, RTP, RTCP

Various audio/video controls

As the above list shows, opening the required ports can leave a number of large "holes" in the firewall. Polycom and Tandberg video conference units do give you the option to set a predetermined range instead of opening up the entire range of 1024-65535 (UDP). However, there is one caveat with this: Whatever port range is chosen, it must be set to exactly the same range on both units that are connecting. This can be a challenge especially when both devices are not managed by the same department or organization. Additionally, some devices will not work with the manual configuration of ports (especially if they are from different manufacturers). That being said, the recommended configuration is to open up the full port range (1-65535) for TCP and UDP:

access-list 101 permit tcp any host 50.50.52.52 range 1 65535 access-list 101 permit udp any host 50.50.52.52 range 1 65535
  • The above commands assume that the external IP address is 50.50.52.52
  • The above commands assume an access list 101 exists and is configured inbound on the external interface of the Cisco PIX firewall

Although this may seem excessive and risky; it's necessary for consistent functionality with similar and dissimilar device connectivity. Since the Polycom ViewStation EX (or Tandberg unit) is a solid state device there are not the same security risks as with a workstation or server operating system.

Here are some additional steps you can take to secure the device:

  1. Disable HTTP access from the Polycom unit
  2. Disable FTP access from the Polycom unit
  3. Disable TELNET access from the Polycom unit

Therefore, even if left unattended, the only level of access to the unit would be for someone to video conference in to it. Since video conference units are only used for short periods of time, the security risk (if any) is minimal to null.

Conclusion
Video conferencing has found a place in many environments; not only in the corporate conference room. Anywhere video conferencing is only a matter of locating a CAT5 connection. Setting up video conferencing securely is merely a matter of balancing security and usability following the steps found in this article.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
Transform your business interactions with real-time voice, video and telepresence solutions.
Tech Vendor: Cisco

ZDNet Asia Live

#Cisco #Cloud Aussie university joins Cisco cloud - Hardware - News: Curtin University of Technology working w... http://bit.ly/bnsSsA #TCN

23 minutes ago by thetechgang on topsy

#Cloud #News Google making it easier to leave Exchange - Zd Net Asia.com: Google's bid to get businesses on it... http://bit.ly/9rabRB #TCN

1 hour 4 minutes ago by thetechgang on topsy

it is not to good for china.
Proactol

1 hour 15 minutes ago by nathonastle on Chinese ad partners beg Google for information

Salesforce opens up Chatter developer preview - Zd Net Asia.com: Salesforce.com is giving 5,000 developers access ... http://bit.ly/9nOR0G

1 hour 23 minutes ago by collabotweet on topsy

RT @zdnetasia: HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6

For those with a computer science background, or interested in the high performance computing scene: http://bit.ly/9vFC3i

HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6

RT @VivianZDNetAsia: HP touts new products & management & productivity tools to address business computing pain points. http://bit.ly/dudgA6

2 hours 27 minutes ago by liruchan on topsy

** S'pore govt launches traffic Web app. http://www.zdnetasia.com/s-pore-...

the new look site is very nice @zdnetasia @zdnetaustralia

Big up to my peeps at www.ZDNet.com.au (and www.ZDNetasia.com and www.ZDNet.com.uk). Loving the redesign!

McAfee steps up cloud assurance - Zd Net Asia.com
http://www.zdnetasia.com/mcafee-...

Interesting take on social analystics. http://www.zdnetasia.com/blogs/w...

Singapore govt (LTA) wants to provide live parking data to third parties. http://bit.ly/90Fc0m

RT @jay_ro: Loving the new site and unified design! www.zdnet.com.au (also www.zdnetasia.com and www.zdnet.co.uk) /via @pastawoua

ZDNet Australia, Asia and UK re-launch on a unified platform - looking good. www.zdnet.com.au www.zdnetasia.com www.zdnet.co.uk

Loving the new site and unified design! www.zdnet.com.au (also www.zdnetasia.com and www.zdnet.co.uk) /via @pastawoua

RT @pastawoua: The new ZDNet is live, www.zdnet.com.au (also www.zdnetasia.com and www.zdnet.co.uk) yay for unified design

RT @zdnetasia: We've cut over to a new design. Check out www.zdnetasia.com!

RT @pastawoua: new ZDNet is live zdnet.com.au (also zdnetasia.com & zdnet.co.uk) yay for unified design / Congratulations, it's a milestone

Very good explanation of JMX

23 hours 20 minutes ago by Babith B on Managing applications with JMX

The reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.

1 day 23 minutes ago by lonemavericks on diggs

Another ZTE story....

1 day 25 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G license

We at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.

1 day 59 minutes ago by sarah Jane on Companies' outsourcing spend to increase

I agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...

1 day 29 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV instead

hermm... he deserved it.. he shud not talk abt sensitive things like tat, well, he shud think twice before saying all those things, event...

1 day 7 minutes ago by ... on Facebook user charged in Malaysia

Password manager tools are potential security threat. Criminals who hack into the computer can use the password manager to log onto any s...

1 day 7 minutes ago by ohanae on What defaults should random password generators use?

I've found the cross platform utility unetbootin to be rather handy for this kind of thing as well.

1 day 41 minutes ago by Jim on Use Live USB Creator to install Fedora 12 from a USB stick

Thanks for the article. I think the debug command has an "\" after "C:" it should say w32tm /debug /enable /file:C:\l...

1 day 42 minutes ago by Roger Biefer on Manage time accuracy with W32Tm

available in singapore now
http://www.portablemall.com.sg/goods-71-Microsoft+Zune+HD+32GB+-+Platinum.html

1 day 19 minutes ago by steve on Microsoft coy on apps for Zune HD

How about just using http://www.random.org/strings/? It is very configurable, satisfies all of the flexibility requirements you have ment...

1 day 24 minutes ago by Varun V Nair on What defaults should random password generators use?

Wi-Fi as the "Rodney Dangerfield of wireless", is a catchy metaphor, but it's already been used. In fact, it was the title of a...

2 days 23 minutes ago by Martin Suter on Selina Lo: Wired up for Wi-Fi in Asia

Dear Sir/Madam, I am Narasimha Rao.L. From bangalore India , i searching job in abroad , in electronics field, i have 6+ years exp....

3 days 25 minutes ago by Anonymous on Hot tech jobs in Singapore

Good article, computational aspect of acquired knowledge from the social platform is really questionable, given that there are a lot of p...

3 days 31 minutes ago by JN on What will social analytics say about your company?

The worlds most popular browser Firefox which has remained a stable trustworthy and secure product for many years now was today broken by...

4 days 42 minutes ago by Mitchell Krog on Mozilla aggressively asks older Firefox users to update