Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, H.350: Everything OpenSource and solving the H.323 problem.

Slides:



Advertisements
Similar presentations
Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 1 H.323 & Firewalls.
Advertisements

K. Stoeckigt, Secure real-time audio/video communication – H.350, Encryption & Gatekeeper/Proxy – using H.323 (…and a bit SIP) Tutorial/Workshop.
TANDBERG Video Communication Server March TANDBERG Video Communication Server Background  SIP is the future protocol of video communication and.
MVTS & PortaBilling Integration between MVTS (Mera VoIP Transit Softswitch) and PortaBilling100 Vancouver, BC July 2004 Porta Software
Voice over IP Fundamentals
Security in VoIP Networks Juan C Pelaez Florida Atlantic University Security in VoIP Networks Juan C Pelaez Florida Atlantic University.
Microsoft Windows Server 2008 Software Deployment Chris Rutherford EKU Technology: CEN/CET.
Red Hat Linux Network. Red Hat Network Red Hat Network is the environment for system- level support and management of Red Hat Linux networks. Red Hat.
Technology Steering Group January 31, 2007 Academic Affairs Technology Steering Group February 13, 2008.
Software Frameworks for Acquisition and Control European PhD – 2009 Horácio Fernandes.
Hands-On Microsoft Windows Server 2003 Networking Chapter 7 Windows Internet Naming Service.
Kalpesh Patel Ramprabhu Rathnam
Apache : Installation, Configuration, Basic Security Presented by, Sandeep K Thopucherela, ECE Department.
SEEM4570: XAMPP, Eclipse, Summary of Html Kangfei Zhao Room 711,ERB
Proprietary and Confidential 1. College Registration 2. College as Receiver 3. College as Sender Postsecondary Demonstrations.
taskbar Notification area Start To change size of taskbar: RMC- uncheck Lock the taskbar Changing Properties : RMC- Properties.
Object Oriented Databases by Adam Stevenson. Object Databases Became commercially popular in mid 1990’s Became commercially popular in mid 1990’s You.
31/10/2000NT Domain - AD Migration - JLab 2000 NT DOMAIN - ACTIVE DIRECTORY MIGRATION Michel Jouvin LAL Orsay
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
BASIC NETWORK CONCEPTS (PART 6). Network Operating Systems NNow that you have a general idea of the network topologies, cable types, and network architectures,
Clarity Educational Community Get the Results You Need When You Need Them Transitioning to CA PPM On Demand Presented by: Joshua.
Kuali Rice at Indiana University Rice Setup Options July 29-30, 2008 Eric Westfall.
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
K. Stoeckigt, E. Verharen, Secure real-time audio/video communication – H.350,
Chapter 9: Novell NetWare
CIS 375—Web App Dev II Microsoft’s.NET. 2 Introduction to.NET Steve Ballmer (January 2000): Steve Ballmer "Delivering an Internet-based platform of Next.
GROUP POLICIES AND SECURITY USING WINDOWS SERVER 2008 Raymond Ross EKU, Dept. of Technology, CEN.
Windows 2000 Operating System -- Active Directory Service COSC 516 Yuan YAO 08/29/2000.
K. Stoeckigt, E. Verharen, Secure real-time audio/video communication – H.350,
VOMS Alessandra Forti HEP Sysman meeting April 2005.
SMS 2003 Deployment and Managing Windows Security Rafal Otto Internet Services Group Department of Information Technology CERN 26 May 2016.
H.350 Case Study: University of Alabama at Birmingham Jason L. W. Lynn IT Academic Computing University of Alabama at Birmingham.
1 FlexTraining in a Nutshell Welcome to a brief introduction of the FlexTraining Total e- Learning Solution. This short sample course will outline the.
Introduction to PHP and MySQL Kirkwood Center for Continuing Education By Fred McClurg, © Copyright 2015, Fred McClurg, All Rights.
Riva Managed Identity Integration for Active Directory and Novell ® GroupWise ® Aldo Zanoni CEO, Managing Director Omni Technology Solutions
© Copyright AARNet Pty Ltd Peering H.323 Networks for Voice and Video Collaboration APAN 2004 GDS Dial scheme International Root H.323 Gatekeepers “ViDe.Net”
Professional video communications Outlook/Exchange Scheduler for Codian.
SONIC-3: Creating Large Scale Installations & Deployments Andrew S. Neumann Principal Engineer, Progress Sonic.
Module 11 Upgrading to Microsoft ® Exchange Server 2010.
Towards a Global Service Registry for the World-Wide LHC Computing Grid Maria ALANDES, Laurence FIELD, Alessandro DI GIROLAMO CERN IT Department CHEP 2013.
Sample School Website. What is wrong with the existing School Webspace Site? Can only host static pages – no dynamic content possible. Can not be edited.
K. Stoeckigt, E. Verharen, Secure real-time audio/video communication – H.350,
ASP.NET in Definition: 1.ASP.NET is a web application framework developed and marketed by Microsoft to allow programmers to build dynamic web sites,
WCL303 Business Desktop Deployment (BDD) 2007: Part 2, Deploying the 2007 Office system Michael Niehaus Systems Design Engineer Microsoft
Jill Gemmill 2004 NMI Component: commObject ITU-T H.350 Directory Services for Multimedia Jill Gemmill University of Alabama at Birmingham
Meeting Scheduling System Capstone Project - Team#5 Fall2007.
Configuring and Deploying Web Applications Lesson 7.
H.350 Deployment Case Studies IETF Leveraging Middleware for Unified Campus Services: ITU-T H.350 and IETF RFC 3944 Jason Lynn (UAB) Frank Reinemer (Danet)
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
Plug-In Architecture Pattern. Problem The functionality of a system needs to be extended after the software is shipped The set of possible post-shipment.
SSH. 2 SSH – Secure Shell SSH is a cryptographic protocol – Implemented in software originally for remote login applications – One most popular software.
2-December Offline Report Matthias Schröder Topics: Monte Carlo Production New Linux Version Tape Handling Desktop Computers.
Customizing the Browser Deploying IE10 Browser Management App Compat.
Cofax Scalability Document Version Scaling Cofax in General The scalability of Cofax is directly related to the system software, hardware and network.
Control Room Logbook Status September 28, 2007 Suzanne Gysin.
Stress Free Deployments with Octopus Deploy
System Center 2012 Configuration Manager
Cisco Exam CCNP Collaboration
Call to Fix QuickBooks Error
Moving from a PHP Flat-File Electronic Resources Manager to Drupal 6 Views Image courtesy of USFSW Mountain Praire (Flickr User) Under Creative Commons.
Cisco Exam Study Material - Cisco Exam Dumps Dumps4download.co.in
Tailor slide to customer industry/pain points
Getting Started.
Getting Started.
Unit 36: Internet Server Management
In-house Developed Library Solutions
The site to download BALBES:
GnuGk – The GNU Gatekeeper
SBS 2008 – One year on David Overton
Presentation transcript:

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, H.350: Everything OpenSource and solving the H.323 problem Internet2 Spring Member Meeting Arlington, USA May 2005

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, Outline The environment How does it work? Integration in the existing environment Problems What about the future? Are other systems already in place? References/Further information

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, The environment A ‘more or less’ mixed environment –Room based systems: Tandberg –Desktop based systems: Polycom ViaVideo, PVX –MCUs: Codian, Tandberg (courtesy of Codian & Tandberg) –Gatekeeper: Multi-zone GnuGK (Linux based) Two zones Running in full proxy mode to overcome the H.323 firewall issue –H.350 Directory Service: OpenLDAP

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, The environment Images: © Polycom, © Tandberg

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, The environment All VC endpoints are registered in their zone at the Gatekeeper –Registration requires a matching ‘IP-Alias-E.164’ combination (Even a typo in the Alias causes a rejection) Does not work well with DHCP (Workaround possible) –Authentication/Authorization is essential to ensure a high quality/availability/reliability of service (not QoS!!) → Part of our security concept (very restrictive)

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, How does it work? Endpoint Gatekeeper/ProxyH.350 RRQ ( , Kewin, 1234) Ldapsearch( , Kewin, 1234) Ldapsearch: Success RCF 1.Endpoint sends RRQ (Registration request) to the Gatekeeper 2.The Gatekeeper sends an LDAP search using the ‘IP-Alias-E.164’ combination to the H.350 Directory Service 3.H.350 confirms search with success 4.The Gatekeeper sends a RCF (Registration confirm) to the endpoint

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, Advantages In this way we can support H.350 authentication even though the endpoints do not support H.350 (unfortunately only a few systems have this feature already) This setup works with future developments –SIP –Integration of Management Tools E.g. the Management Tools can use the H.350 Directory Service to manage phonebooks, etc. –It scales well, since we do not rely on ‘Corporate licenses’ for 20 endpoints, etc. (we can have as many as we want to )

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, Integration in the environment Only a few changes are necessary (Changes are currently applied) –Install and configure OpenLDAP according to the H.350 cookbook ( –Recompilation and reconfiguration of the Gatekeeper/Proxy (I prefer GnuGK for many reasons…) –Conversion of the current mysql database entries into H.350 Directory Service entities (Script almost done) –Update of status webpages at Phonebook, Call status, Registered endpoints, etc. –Update of our management webpages Add new systems, etc.

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, Problems Most of the problems were discovered during the GnuGK-H.350 workshop at the 19 th APAN Meeting in January 2005 ( Understand and install OpenLDAP, including the configuration of the H.350 Directory Service –It looked easier than it was… Underlying library for GnuGK had to be compiled differently, otherwise the Gatekeeper crashes while initializing the LDAP support Fixing the ldaplink.cxx file of GnuGK

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, Problems Why going through all the problems? –Its worth it!! H.350 is the way to go –We wanted to have everything up and running using OpenSource software → we have a quite a few smaller Institutes who can not afford a commercial solution –We chose GnuGK as our main Gatekeeper about 3 years ago; running the system in full proxy mode to overcome the H.323 Firewall issue The system works very reliable –In 2004 the system handled more than calls with way more than 2TB of data –From time to time we run > 60Mb/s through the proxy The system is OpenSource → free –We were not keen to replace a reliable system (‘Never touch a running system’)

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, What about the Future? Are other systems in place already? I hope many of you will use H.350 –In combination with GnuGK, because the combination of OpenLDAP and GnuGK is free, easy to use and very reliable Other systems already in place: –Flinders University (Adelaide, Australia), 3/2005 GnuGK 2.0.8, Novell LDAP (Schema files were adjusted and will be made available for the cookbook soon) –Max Planck Institute of Plasmaphysics (Greifswald, Germany), Test-Setup since 12/2004 GnuGK 2.0.8, OpenLDAP (Full migration to the ‘production’ server in 5/6/2005 –Australian public and national (Canberra, Australia), Systems will be deployed in 5/6/2005 Future plans –Install more H.350 Directory Services in combination with GnuGK –Implement ‘all’ aspects of H.350 in GnuGK

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, References/Further Information Installation and configuration will be made available for the next version of the H.350 cookbook Webpage of the APAN Workshop – At the next QUESTNet (July 2005) –there will be a full day ‘hands-on’ workshop on how to setup H.350 with GnuGK Send me an or

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, Acknowledgement Dr. U. Schwenn, MPG Dr. E. Verharen, SURFnet D. Schroeder, Flinders University J. Lynn, J. Gemmill, UaB S. Kingham, AARNet