Presentation is loading. Please wait.

Presentation is loading. Please wait.

ITEXPO 2015 Khris Kendrick Vice President Business Development +1 978-290-0001 Ingate’s mission is to enable the best access for telephony,

Similar presentations


Presentation on theme: "ITEXPO 2015 Khris Kendrick Vice President Business Development +1 978-290-0001 Ingate’s mission is to enable the best access for telephony,"— Presentation transcript:

1 ITEXPO 2015 Khris Kendrick Vice President Business Development Khris@ingate.com +1 978-290-0001 Ingate’s mission is to enable the best access for telephony, global real-time and unified person-to-person communication for everyone.

2 Solutions for SIP The SIP enabler We enable SIP communication for business The Role Of The E-SBC

3 Who Are We?Ingate Systems – Quick Facts Founded 2001 with Intertex heritage from the 1980s Headquarters in Stockholm, Sweden North American subsidiary in New Hampshire, USA Japanese liaison office Leader in real-time SIP communications with more than 50,000 small and 10,000 business and enterprise installations in 50+ countries Leading innovator with patents registered and pending First SIParator® (SIP Proxy-based firewall & E-SBC) delivered in 2001 First E-SBC certified by the ICSA Labs for VoIP SIP security firewall Ingate’s SIP Trunking Seminars at ITEXPO since 2006 – Bringing SIP to the Enterprise https://www.ingate.com/itexpo_miami_2015.php https://www.ingate.com/itexpo_miami_2015.php

4 Why—E-SBC Growth? Gartner Market Direction Enterprises are moving to SIP trunking to reduce their telecom expenses by 30 to 50% The Enterprise Session Border Controller (E-SBC) market based on SIP trunking is estimated to grow by 20% per year 2014 – 2018. 80% of enterprises in North America have some SIP trunks but only 10% of them have fully completed their migration to SIP trunking New UC solutions / technologies such as WebRTC will add to this growth Gartner June 2014: Market Guide for Enterprise SBC

5 “SIP Trunking is no longer a Nicety, it’s a Necessity” - Jonah Fink SIP is an important and beneficial component of the evolution of business communication Lower cost--ROI Single network Centralized call management with local numbers Evolution to global connectivity Revolutionary use of video and other media Faster recovery from disasters Implementation requires an E-SBC

6 Question: Would you ever drive your business into a storm?

7 Would you ever do this? PSTN Data LAN Public Internet or MPLS

8 Factoid: Unsecure network/PBX exposure to the Internet will hurt your business…not if, but when

9 Case Study Nationwide Processing Case: Nationwide provides outsourced mortgage production services to leading institutions. Problem: Initially connected their PBX to the Internet and continuously got Brute Force Registrations, Toll Fraud, Denial of Service (DoS) and SIPVicious attacks Solution: SIParator E-SBC installed by eTechHelp

10 PBX Exposed: Not Recommended PSTN Data LAN Firewall IP- PBX SIP Trunking Provider Network GW Public Internet or MPLS

11 NAT Breaks SIP: Not Possible PSTN Public Internet or MPLS Data LAN Firewall IP-PBX SIP Trunking Provider Network GW

12 E-SBC Resolves Firewall Traversal allowing the PBX to be on the LAN Public Internet or MPLS Data & VoIP LAN IP-PBX SIP Trunk Firewall SIP Trunking Provider Network GW

13 What is an E-SBC Device that: Installed at the border between an enterprise and the Wide Area Network

14 The Border: Where is the E-SBC installed? 14

15 How the E-SBC Role Has Evolved And Why First-Gen E-SBCs Can’t Keep Up

16 Old World PSTN--- New World IP

17 Delivering Higher Order of Services Selling bare pipes is a race to zero Service providers (SP) must transform revenue stream to compete

18 UC Couldn’t Happen For the Masses Without an E-SBC  Mobility  Remote office  Collaboration--WebRTC  Presence  Etc.

19 What is an E-SBC? A edge device that is inserted into the signaling and media path between devices to provide session interworking. “Session Traffic Cop” An E-SBC provides: Connectivity- NAT Transversal, session aware firewall, IPv4 to IPv6 Security- DoS, IPSec and TLS origination and termination Quality of Services- Policing, rate limiting Media Services- DTMF Normalizes Protocols Policy Control HA Resiliency and Redundancy Ingate E-SBC VM Soft E-SBC

20 What is an E-SBC Device that: Is installed at the border between an enterprise and the Wide Area Network Similar to a data firewall but for SIP and related media

21 What’s a session A M2M connection between two (devices) parties A bi-directional phone call A bi-directional video connection A chat session

22 What is controlled? Dynamic and trusted pinholing Far-END NAT traversal Security Routing Quality Statistics SIP protocol normalization Far-END diagnostics

23 What is an E-SBC Device that: “SIP Traffic COP” Is installed at the border between an enterprise and the Wide Area Network To control how sessions are managed Between two end-points Between enterprise and service provider Between remote user and enterprise Similar to a data firewall but for SIP and related media

24 Why does the Enterprise need an E-SBC? Deep SIP Packet Inspection To keep the PBX secure Intrusion Detection / Prevention To prevent Denial of Service Attacks Toll Fraud prevention Authentication processes Encryption To enable private communications An E-SBC Simplifies, Secures and Strengthens any SIP Implementation Firewall traversal Enables placement of the PBX behind the firewall Normalization of SIP signaling To insure interoperability with the service provider Far End NAT Traversal Support for Remote Workers Disaster recovery To address multiple PBXs or providers Quality of Service To prioritize voice Demarcation Point MOS scores Logging and Wire Shark traces

25 E-SBC Features 1 SBC FeaturesBrief DescriptionSBC DoS/DDoS PreventionBlocks attackers from taking down the network Topology Hiding“Hides” IP devices in the network from attackers Rogue RTP ProtectionPrevents thieves from stealing long-distance service Media EncryptionKeeps private communications private Signaling EncryptionEnsures only authorized users send/receive communications NAT TraversalEnables SIP sessions with NAT-protected devices High Availability OperationsEnsure no loss of active sessions or session state during SBC failover Protocol InterworkingTranslate dissimilar signaling (SIP, transport (UDP, TCP) & encryption protocols (none, TLS, IPsec, SRTP) Call Admission & Overload ControlEnsure continuous service availability and quality, even under adverse traffic loads and/or attack. SIP Message Manipulation (SMM)Allows an enterprise or service provider to manually or automatically change the contents of a SIP message to provide consistent communications between devices Media transcoding Supports for multimedia, multi-device communications

26 E-SBC Features 2 SBC FeaturesBrief DescriptionSBC IPv4 and IPv6 InterworkingAllows IPv4 and IPv6 networks to work together seamlessly Data and Fax InterworkingWhen a data call is detected and routed DTMF interworkingSupports interworking between different DTMF Relay methods B2BUA Software Architecture The B2BUA application completely terminates signaling and media transport connections on one side and relays only specific information onto new transport connections on another interface Lawful InterceptSupports for lawful Intercept functionality Robust SIP Interoperability Provides robust SIP interworking, offering both dynamic and static SIP normalization between a multitude of enterprise IP devices Radius / CDR BillingSupport for Radius accounting record and generation of CDR file Embedded Routing/Policy EngineProvide route prioritization, call screening and blocking

27 E-SBC Features 3 SBC FeaturesBrief DescriptionSBC ENUM lookupsPerforms ENUM queries to an external DNS to map E.164 telephone numbers to SIP trunk URIs and then performs SIP routing based on the service URIs Direct Media Allows the SBC to set up calls between two endpoints so that media can be exchanged directly without consuming bandwidth to and from the SBC Media PinholesPreserves this privacy and security SIP DTMF Trigger DetectionLooks for specific DTMF trigger patterns and to notify an external SIP entity when such patterns are detected Registration RelayRelays SIP endpoint registration information between these endpoints and the Registrar

28 E-SBC Features 4 SBC FeaturesBrief DescriptionSBC SIP Peer Overload ControlTraffic throttling towards a SIP peer is done based on receipt of 503 response from the SIP peer. Codec Policy Supports setting the media (including codec) policy on a call-by-call basis. The configurable are as follow: allowed codecs (ordered list) packetization parameters fax handling modem handling DTMF handling Digit ManipulationAllows you to modify digits in called party and calling party Parameter ManipulationAllows you to modify the values of important SIP parameters Username/SIP URI RoutingUsername/SIP URI routing allows routing of requests based on the username and/or domain name in the SIP Request-URI

29 The Ingate Product Family

30 Benefits of Ingate E-SBC Functionality – All capabilities needed to deliver SIP to the enterprise Security – Inspection, control, IDS / IPS, and more Interoperability – Tested with most PBXs and SIP Trunking operators Flexibility – six deployment options; hardware and software deliverables Scalability – Products supporting up to 20,000 sessions Simplicity – Start-up wizard reduces installation time Affordability – Price competitive Reliability – MTBF in excess of 10 plus years; failover option available Experience – First E-SBC delivered in 2001 Service – Commitment to customer success

31 Please contact me at any time: Khris Kendrick Vice President Mail & SIP: Khris@ingate.com Direct: +1 978-290-0001


Download ppt "ITEXPO 2015 Khris Kendrick Vice President Business Development +1 978-290-0001 Ingate’s mission is to enable the best access for telephony,"

Similar presentations


Ads by Google