Because I can't find H.323 service in static service list, if I want to establish a H.323 session, Need I add the service? If I need, I should how to add the service? thanks.
ah ok, I understand, my advice would be to open a new thread in that forum asking for a working H.323 rule-set, and also explain what exactly you are trying to setup (e.g. MCU in DMZ, or just Outbound NetMeeting Connection).
But be careful H.323 can be a total nightmare! H.323 is not one service it is a complex set of protocols:
Like: Q.931 Call Signaling H.245 Call Control T.120 Data Protocols H.225 Packetization
Sorry, but right now I can not give you a working firewall config, I have not worked with H.323 in the last 2 years :-(. And I only used it over VPN.
H.323 setups are a general issue with firewalls, it is not specific for ASL, so if you search the web for H.323 and firewall you may find more information.