Download presentation
Presentation is loading. Please wait.
Published byLillian Poole Modified over 9 years ago
1
Enabling SIP to the Enterprise Steve Johnson, Ingate Systems Security: How SIP Improves Telephony
2
Managed SIP Trunk Connected to Separate Enterprise VoIP LAN in Operator’s Space PSTN Public Internet SIP Trunking Provider Network GWGW SIP System Data LAN Firewall IP-PBX Managed SIP Trunk No Remote Users! VoIP LAN? No Soft or Multimedia Clients! Operator: Security Warning! Enterprise: Security Warning!
3
SIP Trunking Provider Network Managed SIP Trunking with SBC Adapting SIP to NAT:ed Space of the Enterprise LAN PSTN Public Internet GWGW SIP System VoIP& Data LAN Firewall IP-PBX No Remote Users! Managed SIP Trunk Enterprise: Can we trust having our LAN pulled to the operator? Other customers
4
SIP Trunking Provider Network Ingate Firewall ® Creating a Common Data and VoIP LAN for Managed SIP Trunking Service PSTN Public Internet GWGW SIP System Data & VoIP LAN IP-PBX Demarcation point and SIP communication via both WAN pipes. Soft Clients and Multimedia Terminals Remote Users Managed SIP Trunk Ingate Firewall®
5
Data LAN NAT/Firewall Traversal Problem when SIP Trunking over the Internet PSTN Public Internet SIP Trunking Provider GWGW IP-PBX Firewall SIP Trunking does not pass a SIP unaware NAT/firewall! … and the firewall cannot even be opened enough to make it work. SIP System
6
Data LAN Ingate SIParator ® Used with Existing Firewall for SIP Trunking Service over Internet PSTN Public Internet SIP Trunking Provider GWGW SIP System IP-PBX Firewall Soft Clients and Multimedia Terminals Demarcation point and bringing SIP communication to the LAN Data & VoIP LAN SIP Trunk over Internet Ingate SIParator® Remote Users
7
The Function of a Full Featured SIP Proxy Ingate SIP Proxy SIP Proxy/Registrar SIP Signaling 10.x.xx168.x.xx 1.Check the SIP signaling, packet inspection - Full flexibility to handle future threats 2.Rewrite for the different address spaces 3.Forward the signaling to the correct SIP proxy or client 4.Open ports (UDP/TCP) in the firewall for the media -Only for the duration of the call -Only between the exact endpoints 5.Media flows through the ports Media 6.Close ports after the call ITSP IP-Phone
8
SPIT, DoS – Filter, IDS/IPS Internet ITSP IP-PBX Mobile user Spammer Dynamically allow authenticated users Block non authenticated users Monitor traffic and block end-points with a un-normal behavior
9
Encryption Encrypted SIP signalling –Support for TLS Encrypted media –Support for SRTP (Sdescriptions) IP-Phone Ingate Firewall or SIParator IP-PBX / SIP Server SRTP In the clear RTP Termination TLS __SRTP__ SRTP, Pass through TLS or Transcoding SRTP In the clear
10
Branch Office and Partner Interconnect Swedish office Ingate Firewall ® US office Internet IP-PBX DMZ Connecting branch offices Customers & Partners Securing with TLS and Encrypted Media SRTP Ingate SIParator ® SIP-unaware Firewall IP-PBX
11
Enabling SIP to the Enterprise Ingate Systems Steven J. Johnson 603-883-6569 steve@ingate.com www.ingate.com
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.