> Source: [sk20371](https://support.checkpoint.com/results/sk/sk20371)

# sk20371 - What is the difference between "H323" and "H323_any" services?

| Property | Value |
|----------|-------|
| Solution ID | sk20371 |
| Date Created | 2003-06-09 |
| Last Modified | 2020-06-22 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Solution

When the network topology is known, the "**H323** " service should be used in the Rule Base.   
That means, if there is a known group of IP phones that uses the GateKeeper, there is a need to define them in this GateKeeper domain (related Endpoint domain) and use the "`H323`" service.

If we do not know the IP addresses of these phones and it can be *any* phone, there is a need to use "`Any`" in the rule (either in the source or the destination) and use the "**H323_any**" service.

The "`H323_any`" service is less restrictive when it comes to redirection (handover) of the H323 session.   
Redirection means that if the session started A -\> B at some stage of the call it becomes C -\> B.   
So, we need to allow redirection from A to C.   
There is a set of rules to allow/disallow this redirection which involves a few kernel tables.

If A is defined as a GateKeeper/Gateway for some group of IP phones that does not include C :

* The redirection will not be allowed in any case.

If A is not defined as a GateKeeper/Gateway for any group of phones then:

* If the service is H323, the redirection is not allowed.

* If the service is H323_any, it is allowed if both A and C are on the external network.

**Related solution:** [sk95369 - ATRG: VoIP](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk95369)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
