ETExamTower
Q13Security

What occurs to a collaboration device’s encrypted signaling traffic when it is placed behind a firewall with private IP addresses and an IP call is attempted without any collaboration infrastructure?

← → navigate · a answer
Community votes
C
83% (5)
A
17% (1)
B
0% (0)
D
0% (0)
Discussion · 8
8
The signaling never gets back to the endpoint because the firewall cannot inspect encrypted traffic.
A 5
Selected Answer: A Don't really like this question. However, the key point is that we're talking about signaling that is encrypted. That means TLS over TCP/IP. Since the station is starting the connection to the outside over TCP/IP (with TLS on top), the signaling traffic will pass through, and return traffic will come back through the dynamic NAT from the firewall. This has nothing to do with the traffic being "always trusted" though. The media is a different story. Media exchange would fail as the device would not be reachable from the outside without additional collaboration ifnrastructure unless you are using some form of static NAT. So, the best answer here is A.
C 2
Selected Answer: C Answer C, because firewall cannot inspect the encrypted traffic and is not able to rewrite ip addresses
C 2
Selected Answer: C If the signaling flows do not go through the firewall so that the firewall can inspect the signaling traffic, the RTP streams could be blocked because the firewall will not know which ports need to be opened to allow the RTP streams for a conversation. https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/srnd/collab12/collab12/security.html
1
The signaling does not get back.
1
A NAT ALG is similar to a firewall ALG, but a NAT ALG actually changes (maps) the addresses and ports in the signaling messages. The NAT ALG cannot inspect the contents of encrypted signaling messages. Answer C
C 1
Selected Answer: C C. The signaling does not get back to the endpoint because the firewall cannot inspect encrypted traffic. Here's why: When a collaboration device sits behind a firewall with a private IP, it cannot be reached directly from the outside world unless NAT traversal or a specific collaboration infrastructure is in place. If the signaling is encrypted (e.g., SIP over TLS), the firewall cannot inspect or modify the payload to help with NAT traversal. That makes C the most technically accurate and complete explanation.
C 1
Selected Answer: C C. The signaling does not get back to the endpoint because the firewall cannot inspect encrypted traffic.