Presentation is loading. Please wait.

Presentation is loading. Please wait.

Solutions for SIP Trunking

Similar presentations


Presentation on theme: "Solutions for SIP Trunking"— Presentation transcript:

1 Solutions for SIP Trunking
The SIP trunking enabler Solutions for SIP Trunking

2 Benefits of Ingate SIP Trunking Products for Service Providers
Support for all SIP PBX’s in the market Expansion of Service Provider market of opportunity Service Provider Demarcation Point Clear point of demarcation towards customer Resolution of NAT traversal issues Security and Control Easy expansion to support Unified Communications Ingate Element Management System Efficient provisioning and monitoring

3 SIP Trunking and Beyond
Core Functionality: NAT/Firewall traversal Interoperability between PBX and Service Provider Networks Quality of Service (QoS)` Security Service Provider Demarcation Point An Ingate solution can also enable: Connecting remote users to the PBX Secure interoffice connection WiFi mobile phone communication Multimedia communication

4 Benefits of SIP Trunking
Monthly cost savings Single network for all communications Lower cost of Moves, Adds and Changes Disaster Recovery / Business Continuity User provisioning First step in achieving Unified Communications Voice, Video, IM, Presence, etc. Remote workers WiFi mobile phone communication SIP is the future of Telecommunications

5 The Ingate Products Enabling General NAT/firewall Traversal for SIP
Complete Firewalls Add-on to Existing Firewalls DMZ Existing Firewall SIParator® Firewall & NAT/PAT SIP Proxy SIP Back to Back User Agent SIP Registrar

6 The Ingate Family 1 500 Calls* 650 Calls* 300 Calls* 150 Calls*
Firewall® 1900 or SIParator® 90 Firewall® 1650 or SIParator® 65 1 500 Calls* 2 600 Mbit/s Packets/s Possible to SW upgrade Firewall® 1550 or SIParator®55 650 Calls* 385 Mbit/s Packets/s Firewall® 1500 or SIParator®50 300 Calls* 380 Mbit/s 75000 Packets/s Firewall® 1190 or SIParator® 19 Both the Ingate Firewall and SIParator line of products comes in different hardware platforms. It is the same software on each of them, the only different is the capacity in concurrent calls and hardware related things like number and type of interfaces and redundant power supplies that comes in the top model. Ingate’s smallest model can handle up to 40 concurrent calls while the top model can handle simultaneous calls. If SRTP is terminated or decoded in the Ingate the capacity will decrease with 50-60%. <Next> The medium model can be software upgraded from a capacity of 150 concurrent calls to 300 and 650 calls. 150 Calls* 330 Mbit/s 28500 Packets/s 50 Calls* 50 Mbit/s 4500 Packets/s *) Calls = Concurrent RTP Sessions = SIP Trunks

7 Confirmed Interoperability
IP-PBXs 3Com Aastra Digium / Asterisk Avaya Cisco Call Manager Ericsson MX-One Fonality Innovaphone Interactive Intelligence Iwatsu Microsoft Mitel NEC / Sphere Nortel Objectworld SER Shoretel Siemens SIP-Gear Swyx More in pipeline.... 360 Networks Airespring AT&T BandTel Bandwidth.com Broadvox Cbeyond Cellip Cordia Corporation Excel Switching Gamma Global Crossing IP-Only Juma Networks Service providers Ingate SIParator® -or- Ingate Firewall Level 3 Netlogic Nexvortex Nuvox O1 Paetec Primus RNK Telecom TDC Tele2 Toplink VoEX VoIP Unlimited Voxbone More in pipeline..... SIP Trunk Compliant with As Ingate have interoped with many IP-PBX vendors like <Repeat the one in the list> we will also guarantee interoperability for the Service Provider. The Service Provider only have to ensure interop with Ingate and then a number of different IP-PBXs will automatically be supported. <Next slide> Carrier Equipment Acme Packet Broadsoft NexPoint Sonus Sylantro See:

8 The Live IP Communication Problem of the Decennium
A common Network and common Protocols changed our lives: SMTP gave us global ! HTTP gave us the WEB! SIP is the Internet standard for Live IP Communication: The next step of Internet usage! Find each other and do something in real time. Telephony being just one application. IMS (SIP based) Internet web However, SIP does not traverse the common NATs and firewalls* separating the LANs from the Internet . * Live IP Communication Requires: Locate the person Set up a session Open real time media streams FW FW FW FW LAN LAN

9 The Ingate SIP Architecture
Firewall & NAT Router Dynamic NAT & Firewall Engine SIP Proxy SIP Proxy Server, capable of routing to/from various address spaces (NAT) The routing SIP Proxy Server controls the media through the NAT & Firewall User Location SIP Registrar for user location information

10 Extensive SIP Feature Set
Security Far-End NAT Traversal and STUN SIP Trunking Tool Set Sol. for Remote Workers Encryption Termination / Transcoding Authentication SIP Filtering Flexible Control IP-Centrex Backup OEM Toolset SIP-ALG-only Firewalls can only do this much SIP Proxy, ALG, B2BUA, Registrar Near-End Traversal Firewall & NAT SIP Proxy, ALG, B2BUA, Registrar QoS, Taffic Mgmt ENUM Support IP-PBX Compatibility Service Provider Compatibility SIP Trunking

11 IP-PBX Trunk Must Meet Service Provider Trunk
PSTN SIP Trunking Provider Network GW SIP System Why may Ingate be required to connect a PBX? NAT/Firewall Traversal – Must NAT to same address space! Basic SIP and Network Interoperability - E.g. Authentication, Registrations, UDP/TLS/TCP, Dynamic IP address, etc. SIP Repair - E.g. Call Transfer, Fragmented packets, Bugs, etc. Features - E.g. Remote Users, Administration (remote and local) Security - E.g. Will LAN be opened? Is the PBX designed to be public? SIP Trunk 1) 2) 3) 4) 5) 2) 3) 4) 5) 2) 3) 4) 5) VoIP & Data LAN IP- PBX PBX Type 1 Modern IP-PBXs are of this type. Media goes directly between phone and SIP Trunk.  SIP Trunk Interface  Signaling: Media: Data LAN only PBX with system phones PBX Type 1.5 VoIP & Data LAN PBX Type 2 IP- PBX Few PBXs are of this type. Asterisk with firewall (IPtables /NETfilter) can be compiled and configured this way, but requires a lot.

12 NAT/Firewall Traversal Problem when SIP Trunking over the Internet
SIP Trunking Provider Public Internet PSTN GW SIP System SIP Trunking does not pass a SIP unaware NAT/firewall! …and the firewall cannot be opened enough to make it work because of NAT. Firewall IP-PBX Data LAN

13 With a SIP Trunk over the Internet, it is not really an option to just connect it to a VoIP LAN.
SIP Trunking Provider Public Internet PSTN GW SIP System SIP Trunk Over the Internet Severe Security Warning! No one wants the whole Voice LAN exposed to the Internet. Any extra firewall here needs to be SIP aware or widely open. Firewall IP-PBX In enterprises where the VoIP LAN is logically separated from data LAN, it is possible to directly connect to a managed SIP Trunking service over a separate pipe (Nobody would even consider connecting such VoIP LAN directly to a SIP Trunking Service Provider offering his service on open Internet!). There are however security issues in addition to the restrictions in features a separate VoIP LAN introduces… (no PC softphones, no multimedia handsets, etc.) Data LAN VoIP LAN Who will issue a public white IP addresses to every Phone? No Soft or Multimedia Clients! ?? UC?

14 Ingate Firewall® Creating a Common Data and VoIP LAN for SIP-Trunking over the Internet
SIP Trunking Provider Public Internet PSTN GW SIP System Remote Users Data & VoIP LAN with QoS SIP Trunk over Internet Ingate Firewall® Firewall Demarcation point and bringing SIP communication to the LAN IP PBX Data LAN Soft Clients and Multimedia Terminals

15 Ingate SIParator® Used with Existing Firewall for SIP Trunking Service over Internet
SIP Trunking Provider Public Internet PSTN GW SIP System Remote Users Data & VoIP LAN SIP Trunk over Internet Ingate SIParator® Firewall Demarcation point and bringing SIP communication to the LAN IP-PBX Data LAN Soft Clients and Multimedia Terminals

16 SIP Trunking Provider Network
Managed SIP Trunk Connected to Separate Enterprise VoIP LAN in Operator’s Space SIP Trunking Provider Network Public Internet GW PSTN SIP System No Remote Users! Provider: Security Warning! Managed SIP Trunk Firewall Enterprise: Security Warning! IP-PBX In enterprises where the VoIP LAN is logically separated from data LAN, it is possible to directly connect to a managed SIP Trunking service over a separate pipe (Nobody would even consider connecting such VoIP LAN directly to a SIP Trunking Service Provider offering his service on open Internet!). There are however security issues in addition to the restrictions in features a separate VoIP LAN introduces… (no remote users, no PC softphones, no multimedia handsets, etc.) Data LAN VoIP LAN Will Service Provider issue IP addresses to every Phone? No Soft or Multimedia Clients! ?? UC?

17 SIP Trunking Provider Network
Managed SIP Trunking with SBC Adapting SIP to NAT:ed Space of the Enterprise LAN SIP Trunking Provider Network Public Internet GW PSTN SIP System No Remote Users! Enterprise: Do we dare let the Service Provider have full access to our LAN? Managed SIP Trunk Firewall IP-PBX If the SIP Trunking service provider has a Session Border Controller (SBC), he can enable the VoIP service in the same address space as the enterprise data LAN, and connect his service over a managed separate pipe to create an enterprise Data and VoIP LAN. Will the customer however dare let the Service Provider have a direct access to his LAN? Consider that there are LANs of other customers connected to the same SBC… Other customers VoIP& Data LAN

18 SIP Trunking Provider Network
Ingate SIParator® Used with Existing Firewall for Managed SIP Trunking Service SIP Trunking Provider Network Public Internet GW PSTN SIP System Remote Users Managed SIP Trunk Firewall Ingate SIParator® IP-PBX Demarcation point and SIP communication via both WAN pipes. Data & VoIP LAN Soft Clients and Multimedia Terminals

19 SIP Trunking Provider Network
Ingate Firewall® Creating a Common Data and VoIP LAN for Managed SIP Trunking Service SIP Trunking Provider Network Public Internet GW PSTN SIP System Remote Users Managed SIP Trunk Ingate Firewall® IP-PBX Demarcation point and SIP communication via both WAN pipes. Data & VoIP LAN Soft Clients and Multimedia Terminals

20 SIP Trunking Provider Network
SIP Trunking Over on a Dedicated Access, with a Central SBC doing Far End NAT Traversal through NAT/FW SIP Trunking Provider Network GW Public Internet PSTN SIP System No Remote Users! Far end NAT traversal through NAT/FW by keep alive packets etc. from Operator SBC. Dedicated access for QoS. Does not work with all NATs & Firewalls. No PBX SIP normalization. Firewall Customer NAT/FW IP-PBX VoIP& Data LAN

21 SIP Trunking Provider Network
Ingate SIParator® Used with Existing Firewall for Managed SIP Trunking Service SIP Trunking Provider Network Public Internet GW PSTN SIP System Remote Users No far end NAT traversal workaround required. Managed SIP Trunk Firewall Ingate SIParator® IP-PBX Demarcation point and SIP communication via both WAN pipes. Data & VoIP LAN

22 SIP Trunking Provider Network
Ingate Firewall® Creating a Common Data and VoIP LAN for Managed SIP Trunking Service SIP Trunking Provider Network Public Internet GW PSTN SIP System Remote Users No far end NAT traversal workaround required. Managed SIP Trunk Ingate Firewall® IP-PBX Demarcation point and SIP communication via both WAN pipes. Data & VoIP LAN

23 SIP Trunking Provider Network
SIP Trunking Over a Dedicated or Internet Access, with a Central SBC doing Far End NAT Traversal through CPE NAT SIP Trunking Provider Network GW Public Internet PSTN SIP System No Remote Users! Far end NAT traversal through CPE router by keep alive packets etc. from Operator SBC. Dedicated access for QoS. Does not work with all NATs & Firewalls. No PBX SIP normalization. Firewall ADSL NAT Router IP-PBX VoIP& Data LAN

24 SIP Trunking Provider Network
SIP Trunking Over on an Internet Access, using an Ingate/Intertex CPE (Firewall/SIParator) with ADSL SIP Trunking Provider Network GW Public Internet PSTN SIP System Remote Users No far end NAT traversal workaround required. Separate Internet data access is optional. Combined Data & VoIP Service with QoS possible. ADSL FW with E-SBC ADSL 2+ Annex A/B/M Built in E-SBC with SIP NAT/Firewall Traversal, QoS and SIP normalization. Firewall IP-PBX VoIP & Data LAN

25 Two Ways to Provide a SIP Trunk
Over a Managed Line Over the Public Internet PSTN Public Internet SIP Trunking Provider Network GW SIP System Data & VoIP LAN IP- PBX SIP Trunk over Internet Firewall PSTN SIP Trunking Provider Network GW Public Internet SIP System Managed SIP Trunk Firewall Offering SIP trunking over a “managed pipe” has become very popular, especially among ITSP’s also supplying the Internet access. SIP trunking over Internet is more economical but relies upon sufficient bandwidth being available between the Firewall and the SIP Trunking Service Provider. IP- PBX Data & VoIP LAN

26 SIP Trunking plug-and-play Step 1 – Address provisioning
A. Connect Your Ingate according to the picture B. Type MAC address and IP address of the Ingate unit. D. Press Next and the tool will automatically provide an IP address to the Ingate. C. Select a password. No password is set default. The following two pages show the configuration of the Ingate while installing a SIP trunk. The Ingate Startup Tool with preconfigurations is being used. E. When done the SIP Trunking tool can be launched. Status information

27 SIP Trunking plug-and-play Step 2 – Trunking configuration
A. Select ITSP from drop down menu and provide necessary account information C. Select SIParator type (only available for SIParators). D. DNS servers to use. Optional E. Optional to add and remove prefixes. B. Select IP PBX brand & IP address on your internal network. F. Configure external inter-face using DHCP or static IP Preconfigurations for a number of ITSP’s and IP-PBX’s are stored in the Startup Tool. In this example Bandtel and ShoreTel are shown. The whole configuration of the Ingate and installation of the SIP trunk should therefore not require much more more than 15 minutes! G. Configure netmask for the internal network H. When done, the tool will generate a configuration based on your input and you will automatically be redirected to the Ingate and only need to apply the configuration and you are done!

28 Please contact me at any time:
Steve Johnson President Mail & SIP: Mobile: Direct:


Download ppt "Solutions for SIP Trunking"

Similar presentations


Ads by Google