Manual

35
X. Information for IT Managers
About EarShot IFB IFB
Mainframe
EarShot IFB mainframe is an embedded Linux-based device with dual 10/100/1000Base-T Ethernet ports. The
device contains an optimized version of the Linux kernel (at this writing, 3.12). The IP parameters are set using a
GUI that requires attachment of a keyboard and VGA monitor to the device.
Alternately, during the first five minutes of power up, the IP parameters may be set by a PC on the local LAN using
a proprietary broadcast UDP protocol. Comrex provides the Device Manager software to perform this function
on the local PC. After five minutes of operation, this function is disabled.
The device runs several services on different ports, outlined here:
Incoming Services
The device hosts a combined HTTP/XML service on TCP 80. If this service is needed outside the firewall, the port will
need to be routed to the mainframe.
Firmware updates to the device are installed using the Device Manager. This update process is password
protected and done via XML over TCP port 80. In addition to the password protection, the update data itself must
have a valid cryptographic signature from Comrex, or else it is rejected. In order for the unit to be remotely
updated, TCP port 80 must be forwarded to the device. Alternately, updates can be initiated from any local PC
using the Device Manager software.
The device can support connection to a SIP trunking service, which would require incoming service on a single
UDP SIP port (usually 5060) and two UDP RTP ports in the range of 16384-16432.
The device can support connection to a registered SIP service. In this case, the UDP SIP connection will be outgoing
and the two UDP RTP ports will be incoming in the range of 16384-16482.
Typically, SIP services rely on the presence of a SIP ALG within the firewall to open RTP ports.
The device will host a SIP connection to its control surface accessories over UDP 5070 and RTP streams in the range
of UDP 16384-16482. Connection to control surfaces outside the LAN subnet is not currently supported.
If Comrex support is required, we may ask for access to the SSH host on the mainframe on TCP 22. SSH service
is protected by a private keypair which is not delivered to customers. SSH service can be disabled in the setup
menu.