|
| ||
|
May 20, 2010 | ||
| Ingate Knowledge Base - a vast resource for information about all things SIP – including security, VoIP, SIP trunking etc. - just for the reseller community. Drill down for more info! |
| |
|
The introduction of SIP brings the challenge of protecting the network from an untrusted network, and the opportunity to manage the routing of calls to a degree not possible with traditional telephony. This installment of our continuing Knowledge Base will review how an Ingate Enterprise Session Border Controller (E-SBC) can address both the challenges and opportunities. |
||
|
The Role of an E-SBC | ||
|
There has been a vigorous debate sparking up the Internet recently about the efficacy of an Enterprise Session Border Controller (E-SBC) in SIP deployments. E-SBCs such as the Ingate SIParator sit at the edge of the network to provide control over the SIP traffic. Traditionally they were seen as just providing firewalling protection – the security – for SIP-based voice networks. Today’s E-SBCs do indeed provide that security, which is absolutely a critical function, but have evolved to serve as a crucial element in enabling SIP deployments. An E-SBC will: Normalize the SIP signaling so that the IP-PBX at the customer site and the service provider’s network are fully compatible. While SIP is a standard, each implementation can be slightly different, and the service providers may each require a different level of authentication from the business. With the Ingate in place, these requirements can be met.
Additionally, normalization of the SIP signaling allows service providers to support more IP-PBXs, or those IP-PBXs that are not yet certified by the ITSP. In this manner the ITSP can provide a wider array of options for their customers and expand their business without the need for extensive interoperability certification with each IP-PBX. Resolve NAT traversal issues to enable the adoption of SIP, SIP trunking and full Unified Communications by securely permitting SIP signaling and related media to traverse the firewall. Without this function, most companies will have one-way audio only.
Provide control through authentication – Many service providers require authentication of the user with their network. Some IP-PBXs do not
Provide Intrusion Detection/Prevention. The Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) in Ingate’s Enhanced Security software module enables the Ingate to detect DoS attacks based on SIP, and to block malicious SIP signaling packets designed to attack certain SIP phones, servers or other devices on the enterprise LAN. This secures the enterprise network as the E-SBC handles the attacks while the servers and other SIP devices in the network can still be used.
We will address this issue more in upcoming Knowledge Bases, and at the SIP Trunk Summit in October at the ITEXPO. |
| |
|
We would like to hear from you. | ||
|
Want more information |
| |
| Follow the links to find out more: Solving Firewall NAT Traversal | ||
|
Ingate Systems Inc. l Ph: +1-603-883-6569 l info@ingate.com l www.ingate.com To be removed from the newsletter distribution, click here. | ||