Specifications

MBG Engineering Guidelines, Release 8.0
TCP 6800,
6801 and
6802
Server -> LAN
Server -> ICP(s)
MiNet Call Control. Allow incoming and outgoing packets for TCP ports
6801 (MiNet-SSL) and 6802 (MiNet-Secure V1) between the server and the
Internet. Allow incoming and outgoing packets for TCP ports 6800
(unencrypted MiNet), 6801 and 6802 between the server and the LAN and
the server and the ICP(s). The LAN rule can be omitted if there are no IP
sets on the LAN, but ensure that the ICP(s) can communicate with the
servers public address.
TCP 6801
and 6802
Internet -> Server
MiNet Call Control. Same as above. Port 6800 should not be used on the
Internet as it is unencrypted. Port 6802 is not required with an Enhanced
Security deployment.
TCP 3998,
6881
Internet -> Server
SAC Connection Support. Allow incoming TCP from the Internet to the MBG
server, on ports 3998 and 6880, to support applications and web browsing,
respectively, on the 5235, 5330, 5340 and Navigator sets. There is an
additional LAN rule that follows this to complete the support.
TCP 3998,
3999 and
6880
Server -> ICP(s)
SAC Connection Support. Allow bidirectional TCP traffic on port 3999
to/from the ICP(s). This is to support the applications on the 5235, 5330,
5340 and Navigator sets. Note: 3998 and 6880 require an additional, MBG
server on the LAN to which the Internet-facing server is daisy-chained.
TCP 80
Server -> LAN
Server -> Internet
SAC Connection Support (Optional). Allow TCP port 80 from the server to
the Internet, and to the LAN, to support web browsing on the 5235, 5330,
5340 and Navigator sets. Also required to the Internet to allow browsing of
the Internet from the set.
TCP 6806 Internet -> Server IP Console Support (Optional).
TCP 1606 Server -> LAN IP Console Support (Optional).
TCP 6807 Internet -> Server IP Console Support (Optional).
TCP 443 Server -> LAN IP Console Support (Optional).
UDP Port
20001
Server -> ICPs
HTML application autopopulation support (Optional). To permit MBG to
autopopulate HTML applications from the ICPs, bidirectional traffic from a
random UDP port on MBG to UDP port 20001 on the ICPs must be
permitted.
UDP 5060
Server <-> LAN
Server <-> Internet
SIP Support. If the SIP connector is enabled, then this port is required for
SIP signaling between MBG and the set, and MBG and the ICP, and for SIP
trunking support.
UDP 5064
Server <-> LAN
Server <-> Internet
Legacy SIP Trunk Support (Optional). This connector is deprecated and
should no longer be used. All SIP should be handled via UDP port 5060.
TCP 5060 Server <-> Internet
UCA SIP TCP Support (Optional). If SIP UDP is enabled and UCA is
enabled then a tcp-udp bridge connector will be enabled. This port is
required for SIP signaling over TCP between MBG and UCA clients that
have been configured for TCP.
TCP 5061 Server <-> Internet
UCA SIP TLS Support (Optional). If SIP UDP is enabled and UCA is
enabled then a tls-udp bridge connector will be enabled. This port is
required for SIP signaling over TLS between MBG and UCA clients that
have been configured for TLS.
TCP 5269
Server <-> LAN
Internet <-> Server
UC Advanced Support. To permit the UCA server to connect to another
UCA server using the XMPP protocol. Failure to do so will result in the
federation features failing to function.
56