Author Topic: Micollab Mobile/UCA mobile (rel 6.0) - a way to lock it down on the firewall  (Read 2132 times)

Offline Rixy

  • Jr. Member
  • **
  • Posts: 50
  • Karma: +0/-0
    • View Profile
Hi all,

Bit of a security based question here and wonder if anyone has any thoughts or has practiced this in real life.

Micollab mobile (or UCA mobile for the old skool) requires a fair amount of ports, effectively open to the world. Has anyone managed to lock down the amount of ports open for this application to work, or are we pretty much stuck with a larger hole in the firewall?

Cheers

Rixy


Offline dilkie

  • Global Moderator
  • Sr. Member
  • *****
  • Posts: 324
  • Karma: +11/-0
    • View Profile
don't you front it with MBG?

Offline Rixy

  • Jr. Member
  • **
  • Posts: 50
  • Karma: +0/-0
    • View Profile
Nope, we have the MBG in the DMZ.

Offline dilkie

  • Global Moderator
  • Sr. Member
  • *****
  • Posts: 324
  • Karma: +11/-0
    • View Profile
and your uca clients are not accessing the uca server via your MBG?

Offline Rixy

  • Jr. Member
  • **
  • Posts: 50
  • Karma: +0/-0
    • View Profile
yes they are, but the MBG is behind a firewall in a DMZ, and then the UCA server and the MBG can interact on the relevant ports between the DMZ and the internal network.

Offline bluewhite4

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 1041
  • Country: us
  • Karma: +20/-0
    • View Profile
yes they are, but the MBG is behind a firewall in a DMZ, and then the UCA server and the MBG can interact on the relevant ports between the DMZ and the internal network.

Then, no. You'll need all the ports open for remote UCA users to work correctly.

Offline dilkie

  • Global Moderator
  • Sr. Member
  • *****
  • Posts: 324
  • Karma: +11/-0
    • View Profile
yes they are, but the MBG is behind a firewall in a DMZ, and then the UCA server and the MBG can interact on the relevant ports between the DMZ and the internal network.

Then, no. You'll need all the ports open for remote UCA users to work correctly.

Indeed.. At least the internet can only access MBG, which is locked down more and has better security/access control than the uca server itself.. But you do need those ports open for the product to operate.


Offline Rixy

  • Jr. Member
  • **
  • Posts: 50
  • Karma: +0/-0
    • View Profile
Thanks Blue, pretty much confirmed my thoughts on it. The answer i discussed on a Mitel course recently was just to make sure that you have strong passwords in place!!!  :D

Thanks for your assistance to Dilkie.  :) 


 

Sitemap 1 2 3 4 5 6 7 8 9 10