Presentation is loading. Please wait.

Presentation is loading. Please wait.

Time to Connect Over IP! Don’t we already? Prepared for:Summer VON Europe 2003 Industry Perspective By: Karl Erik Ståhl President Intertex Data AB Chairman.

Similar presentations


Presentation on theme: "Time to Connect Over IP! Don’t we already? Prepared for:Summer VON Europe 2003 Industry Perspective By: Karl Erik Ståhl President Intertex Data AB Chairman."— Presentation transcript:

1 Time to Connect Over IP! Don’t we already? Prepared for:Summer VON Europe 2003 Industry Perspective By: Karl Erik Ståhl President Intertex Data AB Chairman Ingate Systems AB karl.stahl@intertex.se © 2003 Intertex Data AB 1

2 © 2003 Ingate Systems AB © 2003 Intertex Data AB 2 How do we connect? PSTN GSM 3G Non Real TimeOR Real Time IP XP SERVER

3 © 2003 Ingate Systems AB © 2003 Intertex Data AB 3 VoIP as we have seen it… Proprietary H.323 MGCP SIP Proprietary We’ve got all the protocols:

4 © 2003 Ingate Systems AB © 2003 Intertex Data AB 4 And all the VoIP islands… PSTN But no connectivity between the IP clouds! Europe IP US VPN Tunnel IP Gateway Toll Bypass SOFT SWITCH MGCP

5 © 2003 Ingate Systems AB © 2003 Intertex Data AB 5 Hmm, didn’t we pass this stage… Paper was a very compatible media - So is POTS today… But isn’t it time to move beyond? PSTN emai l printer fax Organization 1 Email system 1 emai l Organization 2 Email system 2 fax

6 © 2003 Ingate Systems AB © 2003 Intertex Data AB 6 We are rapidly moving towards “a single” protocol! An Internet Standard Used for real time person to person IP Communication VoIP, IP Telephony Audio, Video, Data Collaboration Presence, Instant Messaging Lots of activity, ongoing work and development “Everyone” is on the train MCI/Worldcom, Microsoft, Nortel, AT&T, Alcatel, Siemens, Sprint… SIP – Session Initiation Protocol

7 © 2003 Ingate Systems AB © 2003 Intertex Data AB 7 IP Phone IP SOHO LAN Enterprise LAN We have “a single” new network XP PIM …but it is seldom used for person to person communication! Everyone has a connection… Operator Network

8 © 2003 Ingate Systems AB © 2003 Intertex Data AB 8 So there is a big potential! HTTP created the Web SMTP created Email SIP can create universal IP Communication person to person!

9 © 2003 Ingate Systems AB © 2003 Intertex Data AB 9 The Next Big Usage of the Internet! A.Go beyond replacing sections of the PSTN by IP! The PSTN is something to interwork with, not the core to build around! B.Go beyond the “quality” and “services” of the PSTN! The mobile phone world has shown that there is more than “black telephony”! POTS is 50-100 years old! C.Get connectivity out to the end users! Aren’t we there??? THE TICKING BOMB! How do we get there?

10 Everyone has a connection IP Phone PSTN SIP /PSTN Gateway IP SOHO LAN Business LAN SIP Server IAP XP PIM Firewall/NAT problems! DSL Cable MTU Operator network with NAT NAT Firewall NAT So, why don’t we just connect? SIP is the Protocol for IP Communication Person to Person, BUT IT DOES NOT REACH THE EDGE! SIP does not traverse common NATs and Firewalls! And they are still being installed…

11 © 2003 Ingate Systems AB © 2003 Intertex Data AB 11 What is the difference? Typical Internet protocol (SMTP, HTTP…) Internet HOST SERVER SIP (and H.323…) connects person to person Internet PERSON Locate the person - Set up a session - Open real time media streams

12 © 2003 Ingate Systems AB © 2003 Intertex Data AB 12 SIP Firewall Problems Sessions initiated from outside the firewall - OK, open port 5060, but… Media streams on dynamically allocated port numbers - Ooops…  ! Even with public IP addresses inside Firewall Problems:

13 © 2003 Ingate Systems AB © 2003 Intertex Data AB 13 SIP NAT/PAT Problems Where is the device? - Registration/location function Private IP addresses and ports in SIP messages - Rewrite with globally routable addresses IP address and port of media stream has to be modified - NAT engine has to be dynamically controlled Worse with private IP addresses inside NAT & PAT Problems:

14 © 2003 Ingate Systems AB © 2003 Intertex Data AB 14 Suggested Solutions Dynamically controlled Firewall/NATs Midcom: By Firewall Control Proxy UPnP: By the client (Windows) SIP aware Firewall/NATs (SIP Proxy + Registrar) General, handles complex scenarios [Intertex (SOHO), Ingate (enterprise), …] SIP aware Firewall/NATs (SIP ALG – non Proxy) TLS not possible STUN - Can cope with certain types existing NATs SIP clients need to get STUN into their SIP stacks Requires STUN servers on the net Tunnelling - Brings the SIP-client to an operator or a corporate LAN Requires ALG for each client on LAN with own address space IPSec, Proprietary

15 © 2003 Ingate Systems AB © 2003 Intertex Data AB 15 Internet IP Real and Complex Scenarios SIP /PSTN Gateway Complications:  Tight firewalls?  Call transfer?  SIP server on the LAN?  Trusted connections, TLS? XP SIP Server 2 SIP Server 3 SIP Server 4 LAN Firewall/NAT IP Phone SIP TLS Sooner or later: The NAT/Firewall problem needs to be solved where it occurs!

16 © 2003 Ingate Systems AB © 2003 Intertex Data AB 16 Adding General SIP Traversal to a Firewall Important components: Firewall & NAT Dynamic Firewall Engine SIP Proxy SIP Proxy Server, controlling the firewall User Location SIP Registrar, user location information Firewall Control Protocol Communication between SIP Proxy and firewall In the Ingate and Intertex products: You got a SIP server! Use it just for firewall traversal AND/OR as your - SIP Server - Outbound proxy - Inbound proxy What have you got?

17 Firewall/NAT problems! Firewall/NAT SIP transparency! Office or home LAN IP Phone SIP Server PSTN SIP /PSTN Gateway Operator network with NAT Internet NAT Firewall NAT Enterprise LAN DSL Cable MTU DMZ inGate SIParator SIP Enabling the Private Networks inGate Firewall IP Phone IX66 IAP

18 IP Communications Using IP Networks Intranet IP VPN with IP communications Domestic and global IP communications PBX and PSTN – E.164 resolution Customer Premises PBX PSTN Phone Managed Services Router Vmail OSS SIP Phone WorldCom PSTN Dialing Plans Network GWY Conf PSTN Phone IM IN Enterprise Gateway SIP Routing Firewall SIP Server IP VPN Global IP Comm Intranet IP Comm …other… Many call routing options: Private/Public IP address DNS and DNS SRV records SIP aware NAT/PAT servers Henry Sinnreich 4/10/2002 WorldCom Public IP Network

19 IP Communications Using IP Networks PBX PSTN Phone Managed Services Router Vmail OSS SIP Phone WorldCom PSTN Dialing Plans Network GWY Conf PSTN Phone IM IN Enterprise Gateway SIP Routing Firewall SIP Server IP VPN Global IP Comm Intranet IP Comm …other… Integration with existing phones SIP Capable Firewall Ingate and Intertex First through SIT Customer Premises No IP PBX Needed! Enhanced Functionality Enterprise LAN WorldCom Public IP Network

20 Firewall Presence IM Greenwich Edge Proxy DMZ Microsoft Greenwich Home Server: Presence IM Audio Video Data Col. TLS

21 © 2003 Ingate Systems AB © 2003 Intertex Data AB 21 Mixed Environments SIP capable firewalls make the difference!

22 Internet Just Another Internet Service… PSTN SIP /PSTN Gateway DNS SRV DMZ inGate SIParator XP Ingate Linköping LAN IX66 Intertex Stockholm LAN Sweden IX66 FWD Booth #3 USA Sweden IX66 Home Office Users SOHO LAN IX66 XP London Booth #1 Enterprise LAN XP inGate Firewall Booth #2

23 © 2003 Ingate Systems AB © 2003 Intertex Data AB 23 Product Examples – Ingate Systems AB Complete Firewalls Add-on to Existing Firewalls  Firewall & NAT/PAT  SIP Proxy  SIP Registrar Enterprise Products DMZ Existing Firewall SIParator

24 © 2003 Ingate Systems AB © 2003 Intertex Data AB 24 Product Examples – Intertex Data AB IX66 Internet Gate with or without ADSL modem built-in OEM as: Telia SurfinBird Gate PowerBit SafeGate Review at: www.adslguide.org.uk/hardware/reviews/2002/q1/intertex_ix66-edflc.asp SOHO Products

25 © 2003 Ingate Systems AB © 2003 Intertex Data AB 25 The Intertex IX66 Internet Gate A closer look  Firewall & NAT/PAT Router  SIP Proxy and Registrar  DHCP Server and Client  WEB Server for configuration  Smart Card Reader for security applications  Optional 802.11b Wireless Lan  SIP Appliance Control, LAC via expansion port Optional ADSL and Splitter Built-in

26 © 2003 Ingate Systems AB © 2003 Intertex Data AB 26 SIP Capable Firewalls! Ingate Systems AB www.ingate.com Box 10013, Slakthusplan 4 SE-121 26 Stockholm, Sweden CEO Olle Westerberg olle.westerberg@ingate.com Tel +46 8 6007750 Intertex Data AB www.intertex.se Rissneleden 45 SE-174 44 Sundbyberg, Sweden President Karl Erik Ståhl karl.stahl@intertex.se Tel +46 8 6282828 See us in booth 1 & 2!


Download ppt "Time to Connect Over IP! Don’t we already? Prepared for:Summer VON Europe 2003 Industry Perspective By: Karl Erik Ståhl President Intertex Data AB Chairman."

Similar presentations


Ads by Google