Download presentation
Presentation is loading. Please wait.
1
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 1 Intertex Data AB, Sweden IX66 Internet Gate A Firewall with SIP Support Prepared for:Voice On the Net, Spring 2001 By: Lars Berggren Research and Development Intertex Data AB lars.berggren@intertex.se
2
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 2 The Swedish ”Broadband to the People” Race What is going on?
3
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 3 The Swedish ”Broadband to the People” Race Price level: 20 USD/month flat rate Technologies: ADSL, Cable Modems, Apartment Building LAN Deployment: 8 % of households now 20 % of households end 2001 95 % of households in 5 years Key factors: Faster + Always-On
4
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 4 Services and Applications Killer applications? Today: Faster Surfing Coming: IP Telephony * Tomorrow: Home Appliances Control * * Requires access from the Internet to YOU and Always On!
5
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 5 The importance of SIP A protocol is needed for Session Initiation User/Device presence and location Event notification Use SIP! RFC2543, Proven compatibility Scalable, uses Internet services Extendable, Not limited to IP Telephony
6
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 6 The importance of SIP SIP for Presence and Instant Messaging See www.cs.columbia.edu/sip/drafts_presence.html SIP Already Provides Publication Capability Extended with Event Notification and Subscription Registrar Client
7
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 7 The importance of SIP Control your temperature, refrigerator, alarm, toaster and more… An extension to SIP in progress See www.research.telcordia.com/iapp/ http://search.ietf.org/internet-drafts/draft-moyer- sip-appliances-framework-01.txt Submitted to OSGi See http://www.osgi.org
8
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 8 Broadband in the Home – Firewall & NAT Do YOU want to be part of the public Internet? Always On Internet – You need a firewall! Firewall Outside worldHome Internal LAN Internet Private IP Addresses One public IP Address
9
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 9 Broadband in the Home – Firewall & NAT Why do we need SIP capable firewalls / NATs? Global end-to-end connectivity for SIP Privacy and protection of home devices Many SIP applications are typically used with Always-On access Several SIP devices, but only one public IP address
10
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 10 Accessing Protected Devices Firewall Problems: Sessions initiated from outside of the firewall - OK, open port 5060, but… Media streams on dynamically allocated port numbers - Ooops… ! Even with public IP addresses inside
11
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 11 Accessing Protected Devices NAT & PAT Problems: Where is the device? - Registration/location function Private IP addresses and ports in SIP messages - Rewrite with globally routable addresses IP address and port of media stream has to be modified - NAT engine has to be dynamically controlled Worse with private IP addresses inside
12
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 12 Adding SIP support to a firewall Important components: Dynamic Firewall Engine SIP Proxy Server, controlling the firewall SIP Registrar, user location information Communication between SIP Proxy and firewall SIP Proxy Registrar Firewall & NAT Firewall Control Protocol?
13
Internal LAN LACLAC Internet Firewall or NAT Accessing into the home... SIP Proxy Outside WorldIn Home Protection © 2000 Telcordia Technologies, Inc. All Rights Reserved
14
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 14 Global End-to-End Connectivity Now possible! karl@intertex.se LAN Gateway Internet PSTN SIP End-to-End to utilize the possibilities of advanced IP Telephony services! FIREWALL
15
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 15 Demo – Let’s make a call… LAN PSTN Gateway Internet PSTN Firewall SIP Proxy Registrar SIP Server GSM Gateway Dialling: lars@siplab.net Dynamic session setup siplab.net SIP forwarding RINGING!
16
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 16 Demo – Let’s turn the lamp on… DO sip:lars.home.apps@siplab.net lamp power on Internet (Ethernet) LAN (Ethernet) Internet SIP Server siplab.net SIP Home Appliances Controller SIP ENP
17
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 17 The Intertex IX66 Internet Gate As Internet Gate ”only” or with integrated ADSL modem The Intertex IX66 series OEM as: PowerBit Telia SurfinBird
18
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 18 The Intertex IX66 Internet Gate A closer look Firewall & NAT/PAT SIP Proxy and Registrar DHCP Server WEB Server for configuration SIP Appliance Control, LAC via expansion port
19
© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 19 The Intertex IX66 Internet Gate Goodies Two Ethernet and one USB port Expansion port, e.g. for appliance control Smart Card Reader Upgradeable Optional ADSL Built-in
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.