Page 13 IT Administrators Guide
Note:
Don’t worry if Skype establishes a large number of connections.
2.2.3 HTTPS/SOCKS5 proxies
Many large organizations have rewalls that don’t meet these NAT requirements or
employ other restrictive security policies, such as closing off high TCP or UDP ports.
If this is the case, you can congure Skype to work through a SOCKS5 or HTTPS proxy.
These proxies relay trafc from applications inside the network (like Skype) to the
internet and vice versa from the internet into the local network, based on congured
policies (certain trafc can be passed or blocked). SOCKS5 proxies use a handshake
mechanism that works across TCP or UDP socket connections. HTTPS proxies use the
proxy connect method to connect to a remote client through TCP port 443.
A few important notes when deploying Skype across a proxy:
˚
We recommend SOCKS5 proxies rather than HTTPS as they support UDP, which
allows better media quality than TCP. If you can’t use a SOCKS5 proxy, clients can
send TCP trafc across an HTTPS proxy while still attempting to connect to the
other node directly.
˚
Proxies can be congured as the primary or backup means of reaching external
networks. You can manually congure your clients to make the proxy a backup
or make it primary by altering your GPO and Admin templates. For more
information, please see 2.4.2 Group policies.
˚
Don’t implement NAT between clients and your SOCKS5 proxy. We also don’t
recommend applying NAT between SOCKS5 and the internet.
2.2.4 Relays
If a Skype client can’t communicate directly with another client, it will nd the appropriate
relays for the connection and call trafc. The nodes will then try connecting directly to
the relays. They distribute media and signalling information between multiple relays for
fault tolerance purposes. The relay nodes forward trafc between the ordinary nodes.
Skype communication (IM, voice, video, le transfer) maintains its encryption end-to-end
between the two nodes, even with relay nodes inserted.
As with supernodes, most business users are rarely relays, as relays must be reachable
directly from the internet. Skype software minimizes disruption to the relay node’s
performance by limiting the amount of bandwidth transferred per relay session.
Kommentare zu diesen Handbüchern