Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 1 H.323 & Firewalls.

Slides:



Advertisements
Similar presentations
The German Research Landscape and current Developments in Science and Research IC Eriwan, German Academic Exchange Service (DAAD)
Advertisements

1 st December 2003, Milan Roundtable Discussion on the need for better co-ordinated actions at EU level Moderator: Hans-Werner Müller – UEAPME Secretary.
1 Nia Sutton Becta Total Cost of Ownership of ICT in schools.
1 UNIT I (Contd..) High-Speed LANs. 2 Introduction Fast Ethernet and Gigabit Ethernet Fast Ethernet and Gigabit Ethernet Fibre Channel Fibre Channel High-speed.
HELMHOLTZ ASSOCIATION
Pricing for Utility-driven Resource Management and Allocation in Clusters Chee Shin Yeo and Rajkumar Buyya Grid Computing and Distributed Systems (GRIDS)
Flexible Budgets, Variances, and Management Control: II
Copyright © 2003 Pearson Education, Inc. Slide 1 Computer Systems Organization & Architecture Chapters 8-12 John D. Carpinelli.
The Access Grid Ivan R. Judson 5/25/2004.
Cognitive Radio Communications and Networks: Principles and Practice By A. M. Wyglinski, M. Nekovee, Y. T. Hou (Elsevier, December 2009) 1 Chapter 12 Cross-Layer.
Career Technical Education Educating Californias 21 st Century Workforce Pacific Policy Research Foundation November 16, 2006.
1 Optical network CERNET's experience and prospective Xing Li, Congxiao Bao
National Computerization Agency (NCA) Future of KOREN/APII October 31, 2003 Byun, Sang-Ick / NCA
1 The Use of Videoconferencing and Webcasting at the Fundação para Computação Cientifica Nacional Rui Ribeiro Fundação para Computação Científica.
Caltech Proprietary VRVS 3.0 and VRVS AG GATEWAY Connect to AG Virtual Venues through VRVS from Anywhere World-Wide VRVS 3.0 and VRVS AG GATEWAY Connect.
Caltech Proprietary Videoconferencing Security in VRVS 3.0 and Future Videoconferencing Security in VRVS 3.0 and Future Kun Wei California Institute of.
Future Broadband Wireless Communication Mobility Testing Platform Ph.D, Prof. Fuqiang Liu, Xuefeng Yin Broadband Wireless Communication.
Submissions November 2007 Stephen McCann, NSNSlide 1 IEEE 802 Emergency Services (ES) Call for Interest (CFI) Date: Stephen McCann
Max-Planck-Institut für Plasmaphysik EURATOM Assoziation Interaction of nitrogen plasmas with tungsten Klaus Schmid, A. Manhard, Ch. Linsmeier, A. Wiltner,
SEWG Fuel Retention July 2008 © Matej Mayer Fuel retention in ASDEX Upgrade tungsten coatings M. Mayer, M. Balden, K. Krieger, S. Lindig, O. Ogorodnikova,
SEWG Gas Balance 2007 © Matej Mayer First results on deuterium depth profiling in W tiles M. Mayer 1, V.Kh. Alimov, V. Rohde 1, J. Roth 1, A. Herrmann.
Institute for Plasma Physics Rijnhuizen D retention in W and mixed systems in Pilot-PSI G. De Temmerman a, K. Bystrov a, L. Marot b, M. Mayer c, J.J. Zielinski.
and 6.855J Cycle Canceling Algorithm. 2 A minimum cost flow problem , $4 20, $1 20, $2 25, $2 25, $5 20, $6 30, $
An Alliance based Peering Scheme for P2P Live Media Streaming Darshan Purandare Ratan Guha University of Central Florida August 31, P2P-TV, Kyoto.
China and Germany Partners in Research State of the Art and new Perspectives Dr. René Haak, First Counsellor Science and Technology German Embassy Beijing,
What is valorisation ? Growth €
1 RA I Sub-Regional Training Seminar on CLIMAT&CLIMAT TEMP Reporting Casablanca, Morocco, 20 – 22 December 2005 Status of observing programmes in RA I.
"Reforms in Science and Development in Georgia - Activities of Georgia National Science Foundation" Natia Jokhadze Director of GNSF International Science.
1 1  1 =.
Year 6 mental test 10 second questions
ITPA Avilla January 2008 © Matej Mayer Surface modifications and blistering of tungsten exposed in ASDEX Upgrade M. Mayer, M. Balden, S. Lindig, J. Roth,
1 Presentation to the Overseas Development Institute Friday, 30 January 2004 London Development Cooperation Report 2003 Presentation by Richard Manning,
Summary of Projects Kai Hock. LHC Upgrade About the project LHC is a 27 km circular accelerator in CERN that produces 7 TeV protons. The project is to.
Using Telephone and Cable Networks for Data Transmissions
Using Telephone and Cable Networks for Data Transmission
CP2073 Networking Lecture 5.
Introduction to Cost Behavior and Cost-Volume Relationships
K. Stoeckigt, Secure real-time audio/video communication – H.350, Encryption & Gatekeeper/Proxy – using H.323 (…and a bit SIP) Tutorial/Workshop.
Unleashing Next-Generation Cable Puma5 and the gateway to DOCSIS ® 3.0.
Scopia Elite 6000 Next Generation Hybrid MCU
IP Multicast Information management 2 Groep T Leuven – Information department 2/14 Agenda •Why IP Multicast ? •Multicast fundamentals •Intradomain.
8.6 Linear Programming. Linear Program: a mathematical model representing restrictions on resources using linear inequalities combined with a function.
1 IU Campus GENI/Openflow Experience Matt Davy Quilt Meeting, July 22nd 2010.
Model and Relationships 6 M 1 M M M M M M M M M M M M M M M M
Equal or Not. Equal or Not
Slippery Slope
The PPPL Perspective on Ten Year Planning S. Prager Princeton Plasma Physics Laboratory.
Analyzing Genes and Genomes
Fractions Simplify: 36/48 = 36/48 = ¾ 125/225 = 125/225 = 25/45 = 5/9
Intracellular Compartments and Transport
Partial Products. Category 1 1 x 3-digit problems.
PSSA Preparation.
Essential Cell Biology
1 Chapter 13 Nuclear Magnetic Resonance Spectroscopy.
The Helmholtz Association „Joining forces – Achieving more together“ Walter Kröll Helmholtz Association of National Research Centres.
Key Concepts and Skills
Energy “Laws” Energy “Producers” Energy “Consumers” Next step: Panels Sustainable Energy: Complex problem that requires long term planning and government.
Nils P. Basse Plasma Science and Fusion Center Massachusetts Institute of Technology Cambridge, MA USA ABB seminar November 7th, 2005 Measurements.
Status and Prospects of Nuclear Fusion Using Magnetic Confinement Hartmut Zohm Max-Planck-Institut für Plasmaphysik, Garching, Germany Invited Talk given.
19.9 nuclear fusion  light nuclei combine to give a more stable heavy nucleus plus possibly several neutrons, and energy is released. Used in hydrogen.
K. Stoeckigt, E. Verharen, Secure real-time audio/video communication – H.350,
The European Face of Videoconferencing and other developments Egon Verharen SURFnet GDS: Former TF-STREAM chair,
H.350 Deployment Case Studies IETF Leveraging Middleware for Unified Campus Services: ITU-T H.350 and IETF RFC 3944 Jason Lynn (UAB) Frank Reinemer (Danet)
National Computational Science Ky PACS at the University of Kentucky April 2000 –Advanced Computing Resources –EPSCoR Outreach –SURA Liaison –John.
Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, H.350: Everything OpenSource and solving the H.323 problem.
CSMM Working Group Intermediate report. Christian Helft, LAL-IN2P3-CNRS CSMM Working Group Meeting 0 Feb 12, 2004 Some guidelines  Should contain only.
FUSION DEVICES AND THE HISTORY OF FUSION RESEARCH
FUSION DEVICES AND THE HISTORY OF FUSION RESEARCH
Automatic Analysis of Edge Pedestal Gradient Degradation during ELMs
Presentation transcript:

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 1 H.323 & Firewalls Experiences with an OpenSource solution for the H.323 Firewall issues Kewin Stoeckigt, Ulrich Schwenn Computing Center Garching (RZG), Max-Planck-Gesellschaft (MPG) & Max-Planck-Institut für Plasmaphysik (IPP) SURA/ViDe 6 th Annual Digital Video Workshop Indianapolis, Indiana, USA March 22-25, 2004

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 2 Outline of talk Introduction (MPG, IPP, RZG) VC infrastructure overview H.323 & Firewalls – The Problem An OpenSource solution –Why do we use it? –How it works –ViDe.Net –Authentication methods –Other features –Statistics/Experiences –QoS Activities Summary

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 3 Max-Planck-Society (MPG) Independent, non-profit research organization Promotes and supports research at its own institutes Institutes are organized in three sections with 80 institutes Budget for 2004: ~ US$ 1.66 billion # Inst: Chemistry, Physics and Technology section:29 Biological and medical section:35 Arts and human science:16

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 4 Institute of Plasmaphysics (IPP) Investigates physical principles underlying a nuclear fusion power plant, which – like the sun – will gain energy from the fusion of light atomic nuclei Member of the European Fusion Programme (EFDA) Member of Helmholtz Association of National Research Centers Budget in 2002: US$ 150 million

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 5 Institute of Plasmaphysics (IPP) Current Experiments –ASDEX Upgrade tokamak (Axially Symmetric Divertor EXperiment) Garching Confinement with external fields and plasma current Investigates crucial problems in fusion research under reactor- like conditions –Wendelstein 7-X Greifswald Confinement with external magnetic fields only Theoretically optimized magnetic fields to overcome difficulties due to genuine 3D topology

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 6 Computing Center (RZG) Located in Garching near Munich Since 1980 common computing center for IPP and MPG Offers different services of MPG institutes –General network access –High Performance Computing power (Clusters, vector machines, etc.) –Code optimization –Videoconferencing (since 1995) –… Fastest supercomputer in Germany – IBM Regatta (27 Nodes) (4.2 TFlops/s) # 31 of Top500 (11/2003)

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 7 VC infrastructure: IPP T500 T880T500 Garching Greifswald T500 3 T880 DFNVC T6000 MS T6000 MS 10 VV 15 VV DFNVC T6000 MS T500 2 T VS-EX T7000 Main Institute (700) in Garching; Branch Institute (300) in Greifswald 500 miles: Garching to Greifswald take longer than traveling from Garching to New York

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 8 VC infrastructure IPP: 3 lecture halls –2 in Garching: Tandberg 6000 systems –1 in Greifswald: Tandberg 6000 system 8 seminar rooms –4 Tandberg 550, 7 Tandberg 880, 2 Tandberg 1000 ~ 30 ViaVideo Multizone gatekeeper –Located in Garching –OpenSource (More about this later) Use of DFNVC service

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 9 VC infrastructure: IPP- EFDA DE GAR AUG 2 T6000 / 3 T880 T500 / 15 VV GnuGK-Proxy DFNVC VRVS VS128 VV VRVS VV IL UK DKFRCHFI HU IT VV VRVS 2 VV NM VV NM VV NM ES Aethra VS PT 8 Mbps VV T880 HGW W7-X T T500 T VV

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 10 H.323 & Firewalls – The Problem Complexity of media streams –Use of several sub-protocols for many channels per session Dynamic allocation of several information –Bandwidth/Bandwidth change –# data channel changes –Port allocation

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 11 H.323 & Firewalls – The Problem Dynamic port allocation –H.323 uses a few fixed ports, e.g (T.120), 1719, 1720 –Many dynamic allocated ports Port range: >2 10 & <2 16 Session-Management of H.323 client allocates ports randomly during setup (Phase C) Approx. 4 to 6 ports per videoconference –Dynamic negotiated ports cant be handled by firewall How do you open ports if you dont know them?

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 12 H.323 & Firewalls – The Problem The communication or….what happens if… Setup (often) can run thru firewall, data communication is blocked by firewall ( dynamic ports)

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 13 An OpenSource solution Former firewall solution –OpenFirewalling No videoconferencing client was secured by firewall Securityproblem: Desktops with special data on it are not protected Desired solution –Low-Cost solution –Easy to configure/administer –No network changes, e.g. rerouting, etc. We use GnuGK or TPFNAO (The Program Formally Known As OpenH323 Gatekeeper)

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 14 An OpenSource solution Why do we use it? –Costs GnuGK is free ( GPL) Runs on Linux…which is also free Just the hardware is necessary –Linux Approx 80% of all computer at RZG are Linux/Unix based Linux/Unix seem more reliable than other operating systems –OpenSource We can change the code whenever we want to, e.g. include afs support, etc.

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 15 An OpenSource solution GnuGK is gatekeeper/proxy combination ALL videoconferencing traffic runs over GnuGK The communication…or what happens if…

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 16 An OpenSource solution GnuGK works with ViDeNet –Neighbor principle If LRQ can not be answered by RZG-GK, LRQ I then send to German Country GK and so forth [RoutedMode] … AcceptNeighborCalls=1 … [RasSvr::Neighbor] CGK= :1719;*;

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 17 An OpenSource solution Authentication methods –Security and videoconferencing are getting more important –GnuGK supports several different authentication methods IP authentication Prefix authentication mySQL authentication LDAP authentication/H.350 authentication Radius authentication (includes billing) –It is possible to limit access of dedicated IPs, E.164 numbers, etc.

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 18 An OpenSource solution We use mySQL authentication on RRQ If host has valid DB entry, RCF is send, otherwise RRJ DBTable also used for phonebook

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 19 An OpenSource solution Other features –Port range can be limited (H.245, T.120, RTP ports) –LoadBalancing –T.120 proxy –Support for NATed endpoints –Calls can be queued –…

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 20 An OpenSource solution GnuGK is used in RZG & IPP for ALL videoconferences (internal external, internal internal, external external) Solution works fine in point-to-point environments as well as multipoint ((cascaded) internal/external MCUs) No problems with different speeds (minimum connections speed: 512kbit/s, maximum 3MBits/s) We were not able to force proxy down

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 21 An OpenSource solution What is meant by..is used for ALL videoconference…?

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 22 An OpenSource solution Some statistics (1) –GK system (until 03/2004): P3, 1.6 GHz, running SuSE Linux 7.3 –Used videoconferencing systems 3 Tandberg 6000, 7 Tandberg 550/880, 2 Tandberg 1000, 1 Tandberg 7000, 2 Viewstations EX, 30 ViaVideos We tested our GK with several Polycom systems, Sony PCS1, NetMeeting, GnomeMeeting, VCon, etc. Worked with exotic clients like VRVS-H.323 gateway, FVC Webconferencing server –System has been up and running for 169 days –More than 6000 calls were handled, approx 1500 coming from external institutions/organization

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 23 An OpenSource solution Some statistics (2) –Approx 1000 videoconference per month –Monthly data throughput: 120GB –Interrupts in 2003: 2 (System crashes)

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 24 An OpenSource solution Some statistics (3) –Current use: Directorates meetings IPP Meetings of RZG (Garching / Greifswald / Auckland) RZGs Users group (3-7 sites all over Germany) Monday Meetings ASDEX-Upgrade (Garching / several clients in Europe, e.g. UK, France, etc.) VC-Group meetings (almost every day) Regular meeting of MPG Presidents Project meetings Meeting of Viktas group …

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 25 Summary –Disadvantages Monitoring just via telnet (allowed IPs can be specified) –Advantages Its free OpenSource Proxy can be deactivated (completely or just for dedicated IP/subnets) Limitation of Port range Bunch of authentication methods Runs on Linux/Windows/Apple Support for NATed endpoints E.164 rewrite (important for password protected conferences were password is separated with * (new VV software cant handle *))

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 26 Summary H.323 & Firewall issue can be solved using OpenSource software

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 27 Further Activities: QoS –H.323 Beacon –DFN Projects (Erlangen) –Own Tools Greifswald – Garching HGW GAR

Computing Center of Max-Planck-Society and Institute of Plasmaphysics K. Stoeckigt, U. Schwenn – H.323 Opensource Firewall Solutions 28 Acknowledgement U. Schwenn, P. Pflueger, H. Soenke, Th. V. Weber, RZG J. Hornung, DFNVC F. Schulze et al., VCC Dresden H. Pfeiffenberger, Sybilla Bunne AWI Questions??