Presentation is loading. Please wait.

Presentation is loading. Please wait.

© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 1 Intertex Data AB, Sweden IX66 Internet Gate A Firewall with SIP Support Prepared for:Voice.

Similar presentations


Presentation on theme: "© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 1 Intertex Data AB, Sweden IX66 Internet Gate A Firewall with SIP Support Prepared for:Voice."— Presentation transcript:

1 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 1 Intertex Data AB, Sweden IX66 Internet Gate A Firewall with SIP Support Prepared for:Voice On the Net, Spring 2001 By: Lars Berggren Research and Development Intertex Data AB lars.berggren@intertex.se

2 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 2 The Swedish ”Broadband to the People” Race What is going on?

3 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 3 The Swedish ”Broadband to the People” Race Price level: 20 USD/month flat rate Technologies: ADSL, Cable Modems, Apartment Building LAN Deployment: 8 % of households now 20 % of households end 2001 95 % of households in 5 years Key factors: Faster + Always-On

4 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 4 Services and Applications Killer applications?  Today: Faster Surfing  Coming: IP Telephony *  Tomorrow: Home Appliances Control * * Requires access from the Internet to YOU and Always On!

5 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 5 The importance of SIP A protocol is needed for  Session Initiation  User/Device presence and location  Event notification Use SIP!  RFC2543, Proven compatibility  Scalable, uses Internet services  Extendable, Not limited to IP Telephony

6 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 6 The importance of SIP SIP for Presence and Instant Messaging See www.cs.columbia.edu/sip/drafts_presence.html  SIP Already Provides Publication Capability  Extended with Event Notification and Subscription Registrar Client

7 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 7 The importance of SIP Control your temperature, refrigerator, alarm, toaster and more… An extension to SIP in progress  See www.research.telcordia.com/iapp/  http://search.ietf.org/internet-drafts/draft-moyer- sip-appliances-framework-01.txt Submitted to OSGi  See http://www.osgi.org

8 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 8 Broadband in the Home – Firewall & NAT Do YOU want to be part of the public Internet? Always On Internet – You need a firewall! Firewall Outside worldHome Internal LAN Internet Private IP Addresses One public IP Address

9 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 9 Broadband in the Home – Firewall & NAT Why do we need SIP capable firewalls / NATs?  Global end-to-end connectivity for SIP  Privacy and protection of home devices  Many SIP applications are typically used with Always-On access  Several SIP devices, but only one public IP address

10 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 10 Accessing Protected Devices Firewall Problems: Sessions initiated from outside of the firewall - OK, open port 5060, but… Media streams on dynamically allocated port numbers - Ooops…  ! Even with public IP addresses inside

11 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 11 Accessing Protected Devices NAT & PAT Problems: Where is the device? - Registration/location function Private IP addresses and ports in SIP messages - Rewrite with globally routable addresses IP address and port of media stream has to be modified - NAT engine has to be dynamically controlled Worse with private IP addresses inside

12 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 12 Adding SIP support to a firewall Important components: Dynamic Firewall Engine SIP Proxy Server, controlling the firewall SIP Registrar, user location information Communication between SIP Proxy and firewall SIP Proxy Registrar Firewall & NAT Firewall Control Protocol?

13 Internal LAN LACLAC Internet Firewall or NAT Accessing into the home... SIP Proxy Outside WorldIn Home Protection © 2000 Telcordia Technologies, Inc. All Rights Reserved

14 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 14 Global End-to-End Connectivity Now possible! karl@intertex.se LAN Gateway Internet PSTN SIP End-to-End to utilize the possibilities of advanced IP Telephony services! FIREWALL

15 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 15 Demo – Let’s make a call… LAN PSTN Gateway Internet PSTN Firewall SIP Proxy Registrar SIP Server GSM Gateway Dialling: lars@siplab.net Dynamic session setup siplab.net SIP forwarding RINGING!

16 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 16 Demo – Let’s turn the lamp on… DO sip:lars.home.apps@siplab.net lamp power on Internet (Ethernet) LAN (Ethernet) Internet SIP Server siplab.net SIP Home Appliances Controller SIP ENP

17 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 17 The Intertex IX66 Internet Gate As Internet Gate ”only” or with integrated ADSL modem  The Intertex IX66 series  OEM as: PowerBit Telia SurfinBird

18 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 18 The Intertex IX66 Internet Gate A closer look  Firewall & NAT/PAT  SIP Proxy and Registrar  DHCP Server  WEB Server for configuration  SIP Appliance Control, LAC via expansion port

19 © 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 19 The Intertex IX66 Internet Gate Goodies  Two Ethernet and one USB port  Expansion port, e.g. for appliance control  Smart Card Reader  Upgradeable Optional ADSL Built-in


Download ppt "© 2001 Intertex Data AB, All Rights Reserved Moderator Sandy Teger 1 Intertex Data AB, Sweden IX66 Internet Gate A Firewall with SIP Support Prepared for:Voice."

Similar presentations


Ads by Google