Streaming Media Supplement sa2150 and sa2250

76
Chapter 7 Configuring Media-IXT for RealNetworks
To allow the media player to play through the firewall:
1. Configure your router to allow packets that are bound for the following ports to pass to the inner network:
o TCP port 7070 for PNA connections to G2 RealServers or pre-G2 RealServers
o TCP port 554 for RTSP connections to G2 RealServers
o TCP port 7802 for Media-IXT’s connection to the HP caching plugin on the origin RealServer
o TCP port 3030 for RealProxy’s splitting of live streams
o UDP ports 6970 through 7170, inclusive, for incoming traffic only
o TCP port 7802
To set other firewall configuration options:
1. Choose one of the following options according to the design parameters of your network:
o Open ports 6970 - 7170 in your firewall for UDP
o Open ports 7070 - 7071 and 554 in your firewall for TCP and instruct players to use TCP for all content;
note that this option degrades playback quality
o Configure your firewall to receive UDP through only one port and instruct players to use UDP with the
port you chose
o Tell users to configure RealPlayer to request that RealServer send all media in HTTP format; note that
this creates more overhead on your network than any of the other options.
An alternative procedure used in some deployments follows.
To make your firewall even more secure:
1. Configure the firewall's access control list to allow TCP connections on port 7070 and/or port 554 to be
initiated from the inside network exclusively
2. Allow incoming traffic only if it is part of an ongoing connection
NOTE As of this writing, the current version of RealPlayer is RealPlayer G2. If you are
configuring according to the second option above, and your clients exclusively have the
older versions 4.0 or 5.0 RealPlayers, it is not necessary to open port 554. This is a
relatively unlikely scenario; and it is worth keeping in mind that if you have even one
client using RealPlayer G2, that client can not function properly unless port 554 of the
firewall is open, under the second option above.