1 SIP Trunking
What is SIP Trunking? Termination of SIP calls directly to Service Provider(s) via IP. For Session Initiation Protocol (SIP) based IP-PBXs For legacy PBXs with a gateway to SIP. Benefits for the Enterprise No need to have local PSTN Gateways on the LAN. No need to pay expensive monthly fees for PRI/BRI lines Flexible growth in # of lines up to the capacity of the link No need to invest in more capacity in PSTN Gateways. No need to add another BRI/PRI just to get one more line. Benefits for the Service Provider Able to deliver both data and voice services in same link. More services means lower churn. Compelling and competitive offering.
Ingate SIP Proxy firewall SIP TLS S I P SIP Ingate Firewall ® Normal Firewalls With SIP-Proxy and -Registrar
No Need to Replace your Firewall! Ingate SIParator ® DMZ SIP-enables any firewall Ports that need to be open: -SIP Signaling port Range of UDP/TCP ports Normal Firewalls SIP
Ingate takes care of the Interoperability issues Service providerEnterprise SIP Trunk Ingate SIParator -or- Ingate Firewall Confirmed IP-PBX interoperability: 3Com Asterisk Avaya Broadsoft Cisco Call Manager Mitel Pingtel SER Shoretel Sphere Swyx More in pipeline.... SIP Connect compliant Click here for more Technical details
Assumptions Return On Investment Calculations Customer have already a SIP compliant IP-PBX SIP Trunking + Ingate replaces existing PRI + PSTN Gateway Only additional - not existing PSTN Gateways – are regarded as a cost All figures are based on monthly cost Subscriptions are monthly fees. Investment in HW/SW are distributed over 36 months. Hardware and Software prices are list prices in Sweden The prices are converted from SEK to USD Subscription fees are taken from Tele2 (Swedish SP) Offers both TDM and SIP Trunking Same minute rates for calls in both TDM and SIP Trunking The call volume is not meeting the qualifying limit for free PRI USD per month and PRI Prices and currency as of September 2006
Return On Investment 10,6 months Investment PSTN Gwy Vega 50 – 8 lines USD Divided by ROI example SMB Existing TDM Internet 2 Mbit 253 USD BRI x 4 – 8 lines 165 USD Total per month 418 USD 8 lines with G.711, 80 Kbit/s per line 14 employees, average 64 Kbit/s Internet Internet overcapacity, only 0,9 Mbit/s used Replace with SIP Trunk SIP/Data trunk 2 Mbit253 USD Total per month253 USD Monthly savings 165 USD Investment Ingate Firewall ® USD SIP Trunking module 250 USD QoS module 300 USD 5 extra traversals 300 USD Total investment1 750 USD USD saving on the initial investment 0 If new installation!
Internet 2 Mbit/s TDM 4 x BRI = 512 Kbit/s Dedicated TDM - Waste of Bandwidth Number of calls Min Max Bought capacity Needed capacity Data Mbit/s Min Max Realtime critical Peak hour Data can often wait! Often bursty traffic Wasted bandwidth Share of time
TDM 4 x BRI = 512 Kbit/s Dedicated SIP and Data Trunk 2 Mbit/s Convergence – Optimal Bandwidth Internet 2 Mbit/s Lowest Peak TDM - Waste of Bandwidth Share of time
SIP and Data Trunk 2 Mbit/s Bought capacity Needed capacity Convergence – Optimal Bandwidth Number of calls Mbit/s Flexibility to use extra capacity Data uses free capacity with the help of QoS settings VoIP Data
Return On Investment 5,3 months Investment 2 x Cisco 2811 – 60 lines USD Investment Ingate Firewall ® USD SIP Trunking module 500 USD QoS module 810 USD 25 extra traversals1 400 USD Total investment6100 USD Divided by ROI example Enterprise Existing TDM Internet 100 Mbit/s USD 4 x PRI – 30 lines USD Total per month USD Replace with SIP Trunk SIP/Data trunk 100 Mbit/s USD Total per month USD Monthly savings USD USD saving on the initial investment All figures based on Swedish operator Tele 2 offering September Not good enough? Please WAIT! 550 employees, average 40 Kbit/s data That is 22 Mbit/s for data 1) More economical with one 100 Mbit/s than 2x lines with G.711, 80 Kbit/s per line 2) More economical with 4xPRI than 3xPRI + 10xBRI If new installation!
What about growth in lines? SIP Trunk TDM All figures based on Swedish operator Tele 2 offering September 2006 WAIT! All investments distributed over 36 month. More Invest. ac# Cisco lines Upgrade to Traversals Subscr. ac# PRI Internet 100 M SIP/Data 100 M Growth this much over 3 years costs USD more with TDM 14
Use the SIP Trunk flexibility and QoS to handle peaks What about line utilization? WAIT! Allows the use of cheaper SIParator
What about branch offices? The TDM way Centralized PRI Trunks HQ Service Provider PSTN WAIT! The SIP Trunking way VPN to HQ PSTN Gateways HQ SIP & Data trunk from each office Exactely the capacity you need when you need it! Single point of failure Heavy Load PBX
What if You could use codecs with compression ? You could get cheaper minutes from SIP SP ? You could support remote users ? Transfering x% of your mobile calls to VoIP calls For remote users with PCs and softphone SIP clients. For remote users with dual handsets WiFI/SIP and mobile. Terminating calls at the most cost effective operator Terminate calls directly in the destination country Global calls to local fees. Improve communication and collaboration with Video, IM, Precense, File sharing, Filetransfer etc WAIT! We have been very conservative in the ROI calculations! What would the ROI then be ?
DMZ SIP-unaware Firewall IP-PBX Connect to multiple Service Providers Swedish office Service Provider Japan Service Provider France Service Provider B USA PSTN Ingate SIParator ® SIP Trunking Module Swedish Office Service Provider A USA Authentication Least cost routing Fail over to secondary
Authentication with Service Providers TLS Authentication with SP Prevent unauthorized use of your SIP Trunk Register the Ingate box at single user accounts Let all users use the single user account service for outgoing calls. Useful for example as a low cost back-up “SIP Trunk”.
Call From: Call From: Different Service levels for different users DMZ SIP-unaware Firewall IP-PBX PSTN Ingate SIParator ® SIP Trunking Module Service Provider B Service Provider A Call Center Back Office to Numbers: to
Call to: ENUM Call to: DMZ SIP-unaware Firewall IP-PBX PSTN Ingate SIParator ® SIP Trunking Module IP-clients and IP-PBXs SIP: ENUM Any entry for: e164.arpa ? Yes: No ! Service Provider Any entry for: e164.arpa ? ENUM emulates the DNS hierarchy by reversing the phone number including the country code with a dot between each digit and adding “e164.arpa” as the top domain. x.x.x.x.x.x.x.x.e164.arpa Top domain for US is 1.e164.arpa
Now you dare to connect over Internet The basic architecture of all Ingate products is an enterprise firewall. SIP specific Security features includes Topology hiding of private IP addresses information Validation of the SIP signalling with strict SIP parser Prevents admission of malformed and possibly malicious packets Dynamically open media ports Only for the duration of the session Only between the parties of the call Termination, transcoding and pass-through of TLS (signaling) and SRTP (media) To encrypt some or all sessions to insure privacy. Extensive SIP filtering Extensive SIP logging
The Ingate family Firewall ® 1180 & SIParator ® 18 Firewall ® 1900 & SIParator ® Calls* 30 Mbit/s Firewall ® 1450 & SIParator ® 45 Firewall ® & SIParator ® Calls* 120 Mbit/s 240 Calls* 310 Mbit/s Calls* Mbit/s Possible to SW upgrade 500 Calls* 385 Mbit/s Firewall ® 1600 & SIParator ® 60 *) Calls = Concurrent RTP Sessions
The function of Ingate SIP Proxy Ingate SIP Proxy SIP Proxy/Registrar SIP Signaling 10.x.xx168.x.xx 1.Check the SIP signaling, packet inspection - Full flexibility to handle future threats 2.Rewrite for the different address spaces 3.Forward the signaling to the correct SIP proxy or client 4.Open ports (UDP/TCP) in the firewall for the media -Only for the duration of the call -Only between the exact endpoints 5.Media flows through the ports Media 6.Close ports after the call
Ingate SIP Trunking module solves this problem ! What if the Service Provider can’t handle domains ? Most Service Providers can’t handle domain names IP-PBX Ingate SIParator ® IP IP IP DMZ IP with SIP Trunking Module SIP-unaware Firewall With domain name, no problem ! Can only address the known public IP-address of the SIParator. Rewrites the domain part DNS record pbx.ingate.com resolves to IP DNS override pbx.ingate.com
Without Support for OP With Support for OP Default Gwy: Outb. Proxy: - Default Gwy: Outb. Proxy: - Default Gwy: Outb. Proxy: Many IP-PBXs can’t handle outbound Proxy SIP-unaware Firewall IP-PBX Ingate SIParator ® IP Outbound Proxy IP IP IP DMZ Default Gateway IP with IP-packets to destinations outside the logical network is sent to the Default Gateway for routing. Outbound Proxy is the equivalence to Default Gateway, but for SIP SIP Trunking Module Configure IP-PBX to ”pretend” that Ingate is the Service Provider Rewrites the domain part Click here to go back