Overview Models JE404A Key features Based on a security-hardened version of Linux Works in conjunction with existing firewalls Receives SIP signaling directly from Internet Transparently supports NAT; no exposure to threats No special hardware or software at the user end Product overview With the, home office workers, traveling employees, and other authorized users can securely access their company IP telephony system over the Internet, taking advantage of a wealth of communications applications utilizing the Session Initiation Protocol (SIP). Because SIP dynamic port allocation is not recognized by conventional firewalls, the only way to enable these firewalls for SIP traffic is to open the ports that will be used by that traffic. Unfortunately, this action exposes the enterprise to security risks. To mitigate these risks, the HP VCX IP telecommuting module provides SIP-aware security by first monitoring SIP signaling protocols, such as SIP registration and session establishment, as they arrive over the Internet. The module then assigns and manages the appropriate dynamic addresses of users inside the network, and the existing firewall is able to relay SIP signaling to the proper destinations through its UDP or TCP port. Features and benefits Configuration DMZ configuration for business needs: in this DMZ configuration, all traffic passes through the firewall using static UDP and TCP ports opened in the firewall between the Internet and the module and between the module and the enterprise network; SIP clients in the enterprise are configured with the module as their outgoing proxy; the firewall continues to control security, but all SIP traffic is routed to the network through the module Standalone configuration for business needs: the module may be connected to both the enterprise network and the Internet, operating entirely on its own, in parallel with an existing firewall and handling only SIP signaling and media streams; all other traffic passes through the firewall; this setup requires no configuration changes to the existing firewall, but SIP clients on the enterprise network must be configured with the IP Telecommuting Module as their outgoing proxy Bundled package for ease of deployment: the module includes the IBM 3250M2 X-Series server, remote SIP connectivity telecommmuting software, and 10 SIP traversal licenses included in the base package; this out-of-the-box configuration allows for a flexible number of remote users to register, with the added benefit of built-in traversal licenses, which are consumed with each remote call that is established Investment protection Secure Internet access to business networks: enables access to corporate SIP-based IP communications systems from remote locations over the Internet while protecting other enterprise applications from intruders; augments existing firewalls by specifically handling SIP-established IP media sessions while leaving the firewalls to handle other network traffic; internal addresses are concealed from the public Internet, but SIP clients inside the firewall can be reached by public IP addresses Ease of use Easy to use: GUI-driven central management and configuration DA - 13774 Worldwide Version 1 September 3, 2010 Page 1
Overview Easily integrate with the network: because the module is implemented at the enterprise firewall, users at remote locations do not need special hardware or additional software to gain enterprise network access Additional information Optional mobility for telecommuters: optional HP VCX IP telecommuting module allows remote users the full benefit of their corporate IP telephony system without compromising security Optional network management: use the HP Intelligent Management Center (IMC) and Voice Services Manager (VSM) to configure, monitor, and optimize the performance of media servers, gateways, and endpoints; to monitor VoIP traffic; and to control your voice network quality Product architecture Standards-based application: supports advanced telephony and messaging features based on the IETF Session Initiation Protocol (SIP) standards Connect from behind remote Internet: allows SIP-based communications to be established among networks using Network Address Translation (NAT) without disrupting the NAT infrastructure; the module manages SIP messages to enable transparent communications between different networks connecting via the Internet Multi-site architecture: has a highly flexible architecture that eliminates the dependency on any single component for unprecented resiliency and end-to-end survivability; uses Web-based centralized administration, global directory, and global voicemail to seamlessly link VCX systems together to scale the IP-PBX network as the business grows User productivity Web admin interface: enables the administrator to configure remote connectivity configurations through an intuitive administrative GUI; also, listen to and manage voicemail messages for remote telephone extensions using the VCX user portal; remote extensions are treated no different than the regular users who register using the same extension from within the LAN/WAN environment, in terms of using all unified communication capabilities of the VCX IP telephony solution Voice functionality Hunt groups: built-in call distribution provides agent log-in functionality; support for three selectable call-routing algorithms for remote VCX users connected via the HP VCX IP telecommuting module Automatic call distribution: add-on economical call center application that includes five selectable routing algorithms, the ability to capture real-time statistics, as well as support for remote agents in various VCX locations and remote VCX users connected via the HP VCX IP telecommuting module Advanced SIP functionality: SIP proxy, registrar, and traffic in and out without extra proxy; SIP traffic to private IP addresses (NAT/PAT); authentication of SIP users from external RADIUS Remote SIP connectivity: far-end NAT traversal (also symmetric NAT); management includes SNMP, internal log to hard disk, Syslog, and email events Warranty and support 1-year warranty: with advance replacement and 30-calendar-day delivery (available in most countries) Electronic and telephone support: limited electronic and telephone support is available from HP; refer to: www.hp.com/networking/warranty for details on the support provided and the period during which support is available Software releases: refer to: www.hp.com/networking/warranty for details on the software releases provided and the period during which software releases are available for your product(s) DA - 13774 Worldwide Version 1 September 3, 2010 Page 2
Technical Specifications (JE404A) Ports Physical characteristics Mounting Environment Electrical characteristics Safety Emissions Features 2 SATA hard drive bay slots 2 RJ-45 auto-sensing 10/100 ports (IEEE 802.3 Type 10Base-T, IEEE 802.3u Type 100Base-TX); Duplex: half or full 1 serial console port Dimensions Weight 22.01(d) x 17.32(w) x 1.75(h) in. (55.9 x 44 x 4.45 cm) (1U height) 38.03 lb. (17.25 kg) shipping weight Mounts in EIA-standard 19 in. telco rack or equipment cabinet (hardware included) Operating temperature Operating relative humidity Non-operating/Storage temperature Voltage Frequency 95 F to 122 F (35 C to 50 C); 0 to 3,000 ft (0 to 914.4 m) and 50 F to 90 F (10 C to 32 C); 3,000 to 7,000 ft. (914.4 to 2,133 m) 8% to 80%, non-condensing 50 F to 109.4 F (10 C to 43 C); up to 7,000 ft (2,133 m) 100-127 / 200-240 VAC 50 / 60 Hz UL 60950-1; IEC 60950-1; CAN/CSA-C22.2 No. 60950-1-03; NOM-019-SCFI FCC part 15 Class A; CISPR 22; EN 55022; EN 55024; CNS 13438; ICES-003 SIP functionality SIP proxy, registrar, and traffic in and out without extra proxy SIP traffic to private IP addresses (NAT/PAT) TLS encryption Authentication of SIP users from external RADIUS Remote SIP connectivity STUN server Far-end NAT traversal (also symmetric NAT) Management Capacity SNMP, internal log to hard disk, Syslog, email events Concurrent RTP sessions 600 (max.) Recommended max. number of registered SIP users 6,000 Performance SIP connections setup (SIP+RTP) 0.15 s RTP data delay (10 Mbps/100 Mbps) 0.19/0.08 ms Certifications Platform CE, FCC, UL DA - 13774 Worldwide Version 1 September 3, 2010 Page 3
Technical Specifications Notes Services Standards and protocols IBM 3250M2 X-Series server running security-hardened Linux Package contents IBM 3250M2 X-Series server, telecommuting software, and ten concurrent user licenses Refer to the HP website at: www.hp.com/networking/services for details on the service-level descriptions and product numbers. For details about services and response times in your area, please contact your local HP sales office. General protocols RFC 1531 Dynamic Host Configuration Protocol RFC 1541 DHCP RFC 1631 NAT RFC 1945 Hypertext Transfer Protocol -- HTTP/1.0 RFC 2246 The TLS Protocol Version 1.0 RFC 2617 HTTP Authentication: Basic and Digest Access Authentication RFC 2663 NAT Terminology and Considerations RFC 2766 Network Address Translation - Protocol Translation (NAT-PT) RFC 2833 RTP Payload for DTMF Digits, Telephony Tones and Telephony Signals RFC 3261 Session Initiation Protocol (SIP) DA - 13774 Worldwide Version 1 September 3, 2010 Page 4
Accessories HP VCX x3250m2 IP Telecommuting Module accessories License HP Telecommuting Module 10-user License HP Telecommuting Module 25-user License JE300A JE302A To learn more, visit: www.hp.com/networking Copyright 2010 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein. DA - 13774 Worldwide Version 1 September 3, 2010 Page 5