User's Manual

Pepwave MAX and Surf User Manual
http://www.pepwave.com
116
Copyright @ 2015 Pepwave
19.5 Service Passthrough
Service passthrough settings can be found at Advanced>Misc. Settings>Service
Passthrough.
Some Internet services need to be specially handled in a multi-WAN
environment.Pepwave routerscan handle these services such that Internet applications
do not notice being behind a multi-WAN router. Settings for service passthrough support
are available here.
Service Passthrough Support
SIP
Session initiation protocol, aka SIP, is a voice-over-IP protocol. The Pepwave routercan
act as a SIP application layer gateway (ALG) which binds connections for the same SIP
session to the same WAN connection and translate IP address in the SIP packets
correctly in NAT mode. Such passthrough support is always enabled, and there are two
modes for selection: Standard Mode and Compatibility Mode. If your SIP server’s
signal port number is non-standard, you can check the box Define custom signal ports
and input the port numbers to the text boxes.
H.323
With this option enabled, protocols that provide audio-visual communication sessions will
be defined on any packet network and passthrough the Pepwave router.
FTP
FTP sessions consist of two TCP connections; one for control and one for data. In a
multi-WAN situation, they must be routed to the same WAN connection. Otherwise,
problems will arise in transferring files. By default, the Pepwave routermonitors TCP
control connections on port 21 for any FTP connections and binds TCP connections of
the same FTP session to the same WAN. If you have an FTP server listening on a port
number other than 21, you can check Define custom control ports and enter the port
numbers in the text boxes.
TFTP
The Pepwave routermonitors outgoing TFTP connections and routes any incoming TFTP
data packets back to the client. Select Enable if you want to enable TFTP passthrough
support.
IPsec NAT-T
This field is for enabling the support of IPsec NAT-T passthrough. UDP ports 500, 4500,
and 10000 are monitored by default. You may add more custom data ports that your
IPsec system usesby checking Define custom ports. If the VPN contains IPsecsite-to-