Mitel Forums - The Unofficial Source

Mitel Forums => Mitel Software Applications => Topic started by: Rixy on May 21, 2015, 09:46:33 AM

Title: Micollab Mobile/UCA mobile (rel 6.0) - a way to lock it down on the firewall
Post by: Rixy on May 21, 2015, 09:46:33 AM
Hi all,

Bit of a security based question here and wonder if anyone has any thoughts or has practiced this in real life.

Micollab mobile (or UCA mobile for the old skool) requires a fair amount of ports, effectively open to the world. Has anyone managed to lock down the amount of ports open for this application to work, or are we pretty much stuck with a larger hole in the firewall?

Cheers

Rixy
Title: Re: Micollab Mobile/UCA mobile (rel 6.0) - a way to lock it down on the firewall
Post by: dilkie on May 21, 2015, 10:07:52 AM
don't you front it with MBG?
Title: Re: Micollab Mobile/UCA mobile (rel 6.0) - a way to lock it down on the firewall
Post by: Rixy on May 21, 2015, 12:35:56 PM
Nope, we have the MBG in the DMZ.
Title: Re: Micollab Mobile/UCA mobile (rel 6.0) - a way to lock it down on the firewall
Post by: dilkie on May 21, 2015, 12:54:46 PM
and your uca clients are not accessing the uca server via your MBG?
Title: Re: Micollab Mobile/UCA mobile (rel 6.0) - a way to lock it down on the firewall
Post by: Rixy on May 22, 2015, 08:07:49 AM
yes they are, but the MBG is behind a firewall in a DMZ, and then the UCA server and the MBG can interact on the relevant ports between the DMZ and the internal network.
Title: Re: Micollab Mobile/UCA mobile (rel 6.0) - a way to lock it down on the firewall
Post by: bluewhite4 on May 22, 2015, 08:19:37 AM
yes they are, but the MBG is behind a firewall in a DMZ, and then the UCA server and the MBG can interact on the relevant ports between the DMZ and the internal network.

Then, no. You'll need all the ports open for remote UCA users to work correctly.
Title: Re: Micollab Mobile/UCA mobile (rel 6.0) - a way to lock it down on the firewall
Post by: dilkie on May 22, 2015, 09:10:58 AM
yes they are, but the MBG is behind a firewall in a DMZ, and then the UCA server and the MBG can interact on the relevant ports between the DMZ and the internal network.

Then, no. You'll need all the ports open for remote UCA users to work correctly.

Indeed.. At least the internet can only access MBG, which is locked down more and has better security/access control than the uca server itself.. But you do need those ports open for the product to operate.

Title: Re: Micollab Mobile/UCA mobile (rel 6.0) - a way to lock it down on the firewall
Post by: Rixy on May 26, 2015, 05:45:47 AM
Thanks Blue, pretty much confirmed my thoughts on it. The answer i discussed on a Mitel course recently was just to make sure that you have strong passwords in place!!!  :D

Thanks for your assistance to Dilkie.  :)