• No results found

Security & Reliability in VoIP Solution

N/A
N/A
Protected

Academic year: 2021

Share "Security & Reliability in VoIP Solution"

Copied!
18
0
0

Loading.... (view fulltext now)

Full text

(1)

Security & Reliability in VoIP Solution

July 19th, 2006

(2)

• Founder, Ranch Networks

• 20 years experience in the telecom industry

• Part of of architecture team that built the

prestigious IP and ATM switches

• Recipient of the 1998 Bell Laboratories

President’s Gold Award

(3)

 Ranch manufactures Network appliances built to

advance VoIP telephony deployments

 The RN series of products provide security,

reliability, and scalability to VoIP applications

The only PBX controlled VoIP Appliance

 The only integrated Asterisk security solution  Per-call QoS – rate limiting & BW guarantee  Protocol and Encryption independence

 Scales PBX to handle a lot more calls

(4)

• Ranch agent code is integrated into

Asterisk

• VoIP appliances that enable service

providers to secure, scale and

provide reliable VoIP

– RN300

– RN20L

– RN20

– RN40

– RN41

(5)

• Seamless Connectivity

 Call should succeed irrespective of the locations of caller & called party

• High Call Quality

 No Voice Clipping & call drops

• Security

 Prevent attacks on PBX, phones and the rest of the network  Prevent Eavesdropping of VoIP signaling / media

• High Availability

 Minimal interruption or downtime

• Scalability

 Dynamically increase capacity with minimal impact

(6)

Enterprise Challenges

VoIP Security & Data Security

Call Quality & Data Traffic

Scalability

(7)

• Educating COIs/CTOs - security threats are real • Picking the appropriate security appliances

– Future proofing (encryption, protocol changes) – Security enforcement methodologies

• Traditional firewalls • SIP firewalls

• SBCs

• PBX controlled appliances

– VoIP & data traffic on the same physical cable – Preventing voice quality/call drops due to

viruses/worms

(8)

• Eaves dropping

– Media (Sensitive Information Revelation) – Signaling (Identity Revelation)

• Man in the middle attack

• Denial of Service attack

• Limitations of traditional firewalls

• Non-awareness of above issues

(9)

• Robustness

• Scalability

• Future Proof

(encryption, protocol changes)

• Easily Manageable

• Agnostic to Vendor/Protocol revisions

• Reliability

(10)

• Traditional Firewalls

• VoIP Protocol aware firewalls

• Session Border Controllers

• PBX Controlled appliances

(11)

• Security appliance MUST be able to

segregate & prioritize voice/data traffic

• ALL access to IP PBX MUST go through the security appliance

• Security appliance MUST raise alerts for ANY unauthorized access

• Security appliance MUST have the ability to mirror traffic to an IDS system

• Look for the solutions being promoted by the IP PBX vendor

• Allocate guaranteed BW for VoIP traffic

(12)

• Choose the solution(s) that meet the

objectives

• Use VPN for encrypting VoIP traffic

• Educate the Network Admins on VoIP

security

(13)

SIP issues in a Typical Deployment

Internet Asterisk IP PBX and Media Gateway PSTN

*

Residential Corporate firewall L2 Switch Branch VoIP phones Internal VoIP phones L2 Switch

Connectivity Issue: SIP is NAT unfriendly Security Issue: Media is firewall unfriendly Quality Issue: Bandwidth contention with data

(14)

SIP Phone A

Ranch – Asterisk solution

Internet

 Call Setup: SIP Invite & Authenticate

 Forward invite, Receive 200 OK and finish call setup

 Asterisk (NetSec) applies real-time POLICIES to RN:  Security policies – what “pin holes” to open  NAT policies – how to provide NAT

 Bandwidth policies – what “Pipe width” to use  Bridging policies – how to “connect” the phones

 Call in progress.

 Default: SIP allow with rate limit & RTP deny

NetSec

PSTN

(15)

1+1 High Availability (HA)

Internet

Single public IP address for Asterisk serversSIP based health check will initiate switchover

Central Office Single Public IP Branch RN20 Firewall

ALL SIP messages forwarded to current Active PBXSwitchover does not terminate current conversations

(16)

Internet Asterisk PSTN Asterisk

*

Enterprise Network L2 Switch VoIP Service Provider

*

Ranch RN300 Ranch RN 20/40 SIP Ranch benefits:

• RN20 initiates the Asterisk fail over within the service provider network

• Single IP public address for Asterisk servers in service provider network

• RN300 initiates the fail over from service provider to local Asterisk

• Local Asterisk provides local PSTN backup

Hosted PBX with local fail over to PSTN

PSTN

*

(17)

Clustering

Allows one or more Asterisk IP PBXs to be grouped (Cluster) as a single

IP PBX

Cluster visible to the user as a single public IP and PBX have private IPsA PBX can be added or removed from a cluster at any time

When a PBX is removed from the cluster current active calls should not

be dropped, at a minimum conversations should go on

Health checks determine if a PBX should handle new callsNew calls should be sent to a PBX if-and-only-if

PBX is accessible (ex: SIP based pings)

PBX has access to critical resources such as an data base, external auth server

such as RADIUS/LDAP

(18)

*

*

*

*

Low Cost Large Scale PBX Solution

Registrars-A

Heartbeat

Redundant, Carrier Class

Large Scale PBX Clusters

Low cost Asterisk Proxies

Gigabit interfaces

SIP based health check

*

*

*

*

*

*

Highly scalable solution

SIP based health check determines if an Asterisk within a cluster is active or notEach Asterisk cluster is accessible using single public IP address

Supports multiple Asterisk clusters

 Making a server inactive server does not terminate current conversations

Each registrar and proxy cluster share a single public IP

Ranch RN40

Proxies-A Proxies-B

*

*

References

Related documents

IP PBX Appliances IP Multimedia Phones Enterprise IP Phones Small Business IP Phones Analog Telephone Adapters Analog VoIP Gateways DECT IP Phone. VoIP

The Mediatrix 1204 provides PSTN access for various VoIP endpoints such as IP phones, FXS devices, softphones and IP-based PBX and Key Systems.. It is an efficient solution

The following VoIP terminals are supported: ▪ VoIP softphones: a software for VoIP telephony ▪ VoIP phones:.. ▫ SIP phone: a phone that is suitable

board size, board meeting, board ethnicity, board gender diversity, board independence, and chairman dual role, are associated with the likelihood of fraudulent financial reporting.

Hence, although the proportion of Profile 1 subjects was the same for both treatments, the subjects given the loss treatment more often belonged to Profile 3 (extreme

Residential VoIP Business VoIP Retail Residential VoIP Business VoIP Wholesale Wholesale IP Centrex VoIP VPN IP Trunking Hosted PBX IP Centrex VoIP VPN IP Trunking Hosted PBX End

" started trading %inary options in 311 and loved this new way to trade the $nancial markets. " now dedicate my time to my we%site and help provide valua%le information

Welcome to the online exhibitor service kit for the upcoming Saltwater Fishing Expo being held at the Garden State Exhibit Center on March 18-20, 2016.. This letter