Download presentation
Presentation is loading. Please wait.
Published byDerek Martin Modified over 9 years ago
1
Intertex Data AB, Sweden Firewall and NAT Traversal Bringing SIP the LAN Prepared for:International SIP 2003 By: Karl Erik Ståhl President Intertex Data AB Chairman Ingate Systems AB karl.stahl@intertex.se © 2003 Intertex Data AB 1
2
2 Is there a next big steps in Internet usage? World Wide Web Email Will there be Real Time Communication Person-to-Person?
3
© 2003 Intertex Data AB 3 VoIP as we have seen it… Internet PC Wanna talk to me? Remember how it started in 95? Now it is coming back in a most useful form!
4
© 2003 Intertex Data AB 4 VoIP as we have seen it… Gateway Internet Gateway STO LA Then this service was offered to end users? Nowdays long distance VoIP minutes are bought by the established telcos. Your normal international calls often run over the public Internet!
5
© 2003 Intertex Data AB 5 VoIP as we have seen it… VoIP between branch offices Gateway PSTN Europe IP Internet VPN US Gateway IP - But NOT globally to others!
6
© 2003 Intertex Data AB 6 VoIP as we see it… MGCP often used to phones PSTN FW Internet Phones get locked to operator SOFT SWITCH
7
© 2003 Intertex Data AB 7 Hmm, didn’t we pass this stage… Paper was a very compatible media - So is POTS today… But we need to move beyond! PSTN emai l printer fax Organization 1 Email system 1 emai l Organization 2 Email system 2 fax
8
© 2003 Intertex Data AB 8 What about universal connectivity? Wouldn’t that be fine? Black Phone RJ45 LAN Intranet Internet IP Phone PSTN RJ11
9
© 2003 Intertex Data AB 9 “We need QoS of PSTN…” 3 kHz bandwith? Video? Presence? draft-ietf-simple-presence-07.txt Instant Messaging? RFC3428, December 2002 And more… Is black telephony all we want?
10
© 2003 Intertex Data AB 10 Is the protocol part of the game? HTTP Created the Web SIP Can Create IP Communication Person-to-Person! SMTP Created Email
11
Voice & Video (XP).NET Server will include SIP server, with API (3Q2) Applications will arise Windows Messenger 4.6 and later has SIP-mode Presence & IM 10:s of millions of RTC (SIP) users within a year 4255551212 Dial to phone Rich SIP APIs Microsoft is pushing – New RTC is SIP-based
12
IAP IP Phone Connect to PSTN when required! PSTN SIP /PSTN Gateway Internet Home LAN Business LAN Let SIP clients talk to each other! XP PIM SIP Server
13
IP Phone PSTN SIP /PSTN Gateway Internet Home LAN Business LAN SIP Server IAP XP PIM Firewall/NAT problems! DSL Cable MTU Operator network with NAT NAT Firewall NAT Status until recently: SIP is the Protocol for IP Communication Person-to-Person, BUT IT DOES NOT REACH THE EDGE! But there is a problem…
14
© 2003 Intertex Data AB 14 What is the difference? Typical Internet protocol (SMTP, HTTP…) Internet HOST SERVER SIP (and H.323…) connects person-to-person Internet PERSON Locate the person - Set up a session - Open real time media streams
15
© 2003 Intertex Data AB 15 SIP Firewall Problems Firewall Problems: Sessions initiated from outside the firewall - OK, open port 5060, but… Media streams on dynamically allocated port numbers - Ooops… ! Even with public IP addresses inside
16
© 2003 Intertex Data AB 16 SIP NAT/PAT Problems NAT & PAT Problems: Where is the device? - Registration/location function Private IP addresses and ports in SIP messages - Rewrite with globally routable addresses IP address and port of media stream has to be modified - NAT engine has to be dynamically controlled Worse with private IP addresses inside
17
© 2003 Intertex Data AB 17 Suggested Solutions Dynamically controlled Firewall/NATs Midcom: By Firewall Control Proxy [Dynamicsoft…] uPnP: By the client (Windows) [Microsoft] SIP aware Firewall/NATs (SIP Proxy + Registrar) [Intertex (SOHO), Ingate (enterprise), …] SIP aware Firewall/NATs (SIP ALG) [Cisco,… TLS not possible] Making SIP NAT friendly - Drafts in progress: draft-ietf-sipping-nat-scenarios-00.txt draft-ietf-midcom-stun-02.txt draft-ietf-sip-nat-02.txt draft-ietf-sip-symmetric-response-00.txt
18
© 2003 Intertex Data AB 18 Adding SIP Support to a Firewall Important components: Firewall & NAT Dynamic Firewall Engine SIP Proxy SIP Proxy Server, controlling the firewall User Location SIP Registrar, user location information Firewall Control Protocol Communication between SIP Proxy and firewall
19
Firewall/NAT problems! Firewall/NAT SIP transparency! Office or home LAN IP Phone SIP Server PSTN SIP /PSTN Gateway Operator network with NAT Internet NAT Firewall NAT Enterprise LAN DSL Cable MTU DMZ inGate SIParator SIP Enabling the Private Networks inGate Firewall IP Phone IX66 IAP
20
IX66 Home User USA Sweden Internet Just Another Internet Service… IX66 IAP Home LAN Enterprise LAN XP inGate Firewall SOHO LAN IX66 XP Helsinki PSTN SIP /PSTN Gateway DNS SRV DMZ inGate SIParator XP Ingate Linköping LAN IX66 Intertex Stockholm LAN Sweden
21
IP Communications Using IP Networks Intranet IP VPN with IP communications Domestic and global IP communications PBX and PSTN – E.164 resolution Customer Premises PBX PSTN Phone Managed Services Router Vmail OSS SIP Phone WorldCom PSTN Dialing Plans Network GWY Conf PSTN Phone IM IN Enterprise Gateway SIP Routing Firewall SIP Server IP VPN Global IP Comm Intranet IP Comm …other… Many call routing options: Private/Public IP address DNS and DNS SRV records SIP aware NAT/PAT servers Henry Sinnreich 4/10/2002 WorldCom Public IP Network
22
IP Communications Using IP Networks PBX PSTN Phone Managed Services Router Vmail OSS SIP Phone WorldCom PSTN Dialing Plans Network GWY Conf PSTN Phone IM IN Enterprise Gateway SIP Routing Firewall SIP Server IP VPN Global IP Comm Intranet IP Comm …other… Integration with existing phones SIP Capable Firewall Ingate and Intertex First through SIT Customer Premises No IP PBX Needed! Enhanced Functionality Enterprise LAN WorldCom Public IP Network
23
© 2003 Intertex Data AB 23 Product Examples – Ingate Systems AB A Complete Firewall An add-on to an Existing Firewall DMZ Existing Firewall Firewall & NAT/PAT SIP Proxy SIP Registrar Enterprise Products Firewall 1400SIParator 40
24
© 2003 Intertex Data AB 24 Product Examples – Intertex Data AB IX66 Internet Gate with or without ADSL modem built-in OEM as: Telia SurfinBird Gate PowerBit SafeGate Review at: www.adslguide.org.uk/hardware/reviews/2002/q1/intertex_ix66-edflc.asp SOHO Products
25
© 2003 Intertex Data AB 25 The Intertex IX66 Internet Gate A closer look Firewall & NAT/PAT Router SIP Proxy and Registrar DHCP Server and Client WEB Server for configuration Smart Card Reader for security applications Optional 802.11b Wireless Lan SIP Appliance Control, LAC via expansion port Optional ADSL and Splitter Built-in
26
© 2003 Intertex Data AB 26 SIP-capable firewalls! Ingate Systems AB www.ingate.com Box 10013, Slakthusplan 4 SE-121 26 Stockholm, Sweden VD Olle Westerberg olle.westerberg@ingate.com Tel +46 8 6007750 Intertex Data AB www.intertex.se Rissneleden 45 SE-174 44 Sundbyberg, Sweden VD Karl Erik Ståhl karl.stahl@intertex.se Tel +46 8 6282828
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.