SIP Trunking The Provider s Perspective



Similar documents
How To Support An Ip Trunking Service

PETER CUTLER SCOTT PAGE. November 15, 2011

SIP Trunking Configuration with

Presenter. Zane Ryan. Director Dot Force

Customer Guide. BT Business - BT SIP Trunks. BT SIP Trunks: Firewall and LAN Guide. Issued by: BT Business Date Issue: v1.

Securing SIP Trunks APPLICATION NOTE.

Session Border Controllers in Enterprise

Security & Reliability in VoIP Solution

White Paper. avaya.com 1. Table of Contents. Starting Points

Best Practices for Securing IP Telephony

SIP Trunking with Microsoft Office Communication Server 2007 R2

Network Connection Considerations for Microsoft Response Point 1.0 Service Pack 2

Voice Over IP and Firewalls

SIP-based VoIP Deployment in Taiwan

A Brief Overview of VoIP Security. By John McCarron. Voice of Internet Protocol is the next generation telecommunications method.

VoIP / SIP Planning and Disclosure

How To Understand The Purpose Of A Sip Aware Firewall/Alg (Sip) With An Alg (Sip) And An Algen (S Ip) (Alg) (Siph) (Network) (Ip) (Lib

Concepts of SIP Trunking A series of tutorials on the Session Initiation Protocol

VPLS lies at the heart of our Next Generation Network approach to creating converged, simplified WANs.

APPLICATION NOTE. SIP Trunking Connectivity, Security and Deployment Scenarios. Introduction

Recommended IP Telephony Architecture

Hosted PBX Platform-asa-Service. Offering

Application Note Patton SmartNode in combination with a CheckPoint Firewall for Multimedia security

Jive Core: Platform, Infrastructure, and Installation

Contents. Specialty Answering Service. All rights reserved.

Author: Seth Scardefield 1/8/2013

Connecting MPLS Voice VPNs Enabling the Secure Interconnection of Inter-Enterprise VoIP

Table of Contents. Confidential and Proprietary

Course 4: IP Telephony and VoIP

OpenScape Session Border Controller Delivering security, interoperability and cost savings to the enterprise network border

Wave SIP Trunk Configuration Guide FOR BROADVOX

VoIPon Solutions Tel: +44 (0) Ranch Asterisk VoIP Solution

An Introduction to SIP

nexvortex SIP Trunking Implementation & Planning Guide V1.5

SIP (Session Initiation Protocol) Technical Overview. Presentation by: Kevin M. Johnson VP Engineering & Ops

EarthLink Business SIP Trunking. ININ IC3 IP PBX Customer Configuration Guide

The need for bandwidth management and QoS control when using public or shared networks for disaster relief work

SSVP SIP School VoIP Professional Certification

VoIP Trunking with Session Border Controllers

IP Telephony Basics. Part of The Technology Overview Series for Small and Medium Businesses

Voice over IP Basics for IT Technicians

Vega 100G and Vega 200G Gamma Config Guide

EarthLink Business SIP Trunking. NEC SV8300 IP PBX Customer Configuration Guide

EarthLink Business SIP Trunking. NEC SV8100 IP PBX Customer Configuration Guide

Benefits of Using a Demarcation Device When Integrating Legacy Voice, SIP Trunks and Microsoft OCS R2

Dialogic. BorderNet Products Interwork and Connect Seamlessly and Securely at the Network Edge

Configuring a Mediatrix 500 / 600 Enterprise SIP Trunk SBC June 28, 2011

IVCi s IntelliNet SM Network

Voice over IP (VoIP) Basics for IT Technicians

Indepth Voice over IP and SIP Networking Course

Requirements of Voice in an IP Internetwork

Which VoIP Architecture Makes Sense For Your Contact Center?

VoIP Resilience and Security Jim Credland

Communications Transformations 2: Steps to Integrate SIP Trunk into the Enterprise

VoIP Application Note:

ThinkTel ITSP with Registration Setup Quick Start Guide

VOIP Security Essentials. Jeff Waldron

CVOICE Exam Topics Cisco Voice over IP Exam # /14/2005

One Cloud Cisco UK Service Annex to the General Service Schedule BT reference number...

What is an E-SBC? WHITE PAPER

MINIMUM NETWORK REQUIREMENTS 1. REQUIREMENTS SUMMARY... 1

LAN Planning Guide LAST UPDATED: 1 May LAN Planning Guide

Hands on VoIP. Content. Tel +44 (0) Introduction

IP Telephony Deployment Models

Curso de Telefonía IP para el MTC. Sesión 1 Introducción. Mg. Antonio Ocampo Zúñiga

How SIP for Enterprise Powers Unified Communications

Firewall-Friendly VoIP Secure Gateway and VoIP Security Issues

BT Hosted IPT (VoIP)

Convergence Technologies Professional (CTP) Course 1: Data Networking

nexvortex Setup Template

SIP trunks Deployment note

AT&T IP Flex Reach/ IP Toll Free Configuration Guide IC 3.0 with Interaction SIP Proxy

Enabling NAT and Routing in DGW v2.0 June 6, 2012

Business Continuity protection for SIP trunking service

CompTIA Convergence Examination Objectives

PREPARED FOR ABC CORPORATION

Connecting Your Enterprise With Asterisk: IAX to Carriers. Dayton Turner Voxter Communications

SITEL Voice Architecture

Release the full potential of your Cisco Call Manager with Ingate Systems

Ingate Firewall/SIParator SIP Security for the Enterprise

SIP, Security and Session Border Controllers

IP PBX. SD Card Slot. FXO Ports. PBX WAN port. FXO Ports LED, RED means online

Allstream Converged IP Telephony

SIP Trunking and Voice over IP

Threat Mitigation for VoIP

Application Notes. Introduction. Contents. Managing IP Centrex & Hosted PBX Services. Series. VoIP Performance Management. Overview.

NEWT Managed PBX A Secure VoIP Architecture Providing Carrier Grade Service

SIP Trunking DEEP DIVE: The Service Provider

Troubleshooting Voice Over IP with WireShark

VOIP TELEPHONY: CURRENT SECURITY ISSUES

EarthLink Business SIP Trunking. Toshiba IPedge Customer Configuration Guide

VitalPBX. Hosted Voice That Works. For You

Configuration of Applied VoIP Sip Trunks with the Toshiba CIX40, 100, 200 and 670

Transcription:

SIP Trunking The Provider s Perspective Presented by Pete Sandstrom, CTO BandTel

Advanced SIP Session Overview 1. Open Systems Interconnection Model (OSI) is more than a model 2. Quality of Service (QoS) IP Peering 3. SIP Trunking so what is it? 4. SIP Trunking Security 5. SIP Trunking CPE Architectures 6. The ITSP The Architecture Special Services and Features

1. Open Systems Interconnection (OSI) Understanding Where You Are

SIP is a Fully-Featured Protocol

RTP Carries SIP over UDP/IP/etc.

2. QoS and the Internet The Economics of IP peering- why it works in North America Tier I/II space- It is over provisioned and it is Managed

QoS and the Internet: The Economics of IP peering and why it works in North America IP NET A Tier N data retransmit IP NET B Tier N -1 NET-A dropping packets makes NET-B retransmit, and lowers NET-B s throughput. That s lost revenue for NET-B. End User Bandwidth Rigorously Limited In North America, we see a great call: Packet Delay: < 100 msecs Packet loss < 4% Jitter < less then 10 msecs

QoS and the Internet: It is over provisioned and managed MPLS MPLS INTERNET MPLS MPLS

3. SIP Trunking: So what is it? SIP trunking means X voice paths to Y stations where Y/X > 1; generally the ratio would be 4-10 SIP trunking competes economically, and generally beats T1 trunking cost wise to the PBX. Hosted VoIP can t scale, either economically or technically, so doesn t fit needs of the enterprise

SIP Trunking Basic Features SIP Trunking Applications: Bandwidth QoS provided via SIP-Aware Firewall (SAFW) and or MPLS Security provided via SAFW and ITSP POP Border Controllers and Proxies 411 Directory Assistance 911 Services Access Dialing- Local, DID, 800, 1+, and 011+ dialing Converge- Allows enterprise bulk traffic to merge with VoIP traffic

4.SIP Trunking Security and Reliability LAN VoIP Design- Need to Ensure Enterprise LAN is Correctly Designed for VoIP (i.e. a SIP-Aware Firewall Needs to be in Place) CPE Protection- SIP-Aware Firewall that allows L5 Security (i.e. no L2 pinholes) Requires ITSP MD5- or IP Authentication for Account Authorization ITSP Should Split Media and Signaling to Different Redundant Locations, Making Taps Virtually Impossible ITSP Must Have Secure POPs That Can Fend Off all Outside Attacks: - DoS (Denial of Service) - Registration Spoofing - IP Spoofing (source-route bridging spoofing) - Eavesdropping - SPIT (Spam over Internet Telephony)

SIP Trunking Security, Reliability - Hot Spots Hot Spot: The ITSP Demarc MPLS The Backbone Hot Spot: The CPE Demarc Internet

Now back to getting serious 5. SIP Trunking CPE Architectures Type 1 Dedicated IP Pipe for VoIP Type 2 Merged MPLS-Pipe with LER Tagging VoIP Type 3 Merged IP pipe with SIP-Aware Firewall (SAFW) Type 4 Separate IP Pipe for VoIP with Existing Non-SIP Firewall and SIP-Aware Firewall (SOFW) Type 5 Merged IP Pipe with Incumbent Non-SIP-Aware Firewall, No DMZ Port and SIP-aware Firewall Type 6 Looks like Type 5 but Merged IP Pipe with Incumbent Non-SIP-Aware Firewall, No DMZ Port and SIP-Aware Firewall Type 7 Merged IP Pipe with Incumbent Non-SIP-Aware Firewall with a DMZ Port Type 8 Merged IP Pipe with Incumbent Non-SIP-Aware Firewall

Type 1 Dedicated IP Pipe for VoIP 1- The IP pipe is dedicated to VoIP so no QoS arrangements are needed with the carrier. 2 - No firewall is needed as there are no LAN connections with other enterprise devices. 3 - This is a common architecture for dedicated media gateway deployments.

Type 2 Merged MPLS-Pipe with LER Tagging VoIP 1 VoIP and enterprise data share the same IP pipe. MPLS tags the VoIP as the highest priority via the LER-Label Edge Router. 2 The SAFW handles all SIP addressing transformation issues between the LAN and WAM demarc. 3 Architecture offers full QoS for VoIP. 4 Excellent utilization of IP pipe resources.

Type 3 Merged IP pipe with SIP-aware Firewall (SAFW) 1 VoIP and bulk enterprise share the same IP pipe. 2 The SAFW-SIP-Aware Firewall handles all the QoS issues by prioritizing VoIP traffic over the bulk enterprise network. 3 The SAFW handles all SIP addressing transformation issues between the LAN and WAM demarc. 4 Architecture offers partial QoS for VoIP (no inbound UDP QoS). 5 Excellent utilization of IP pipe resources.

Type 8 Merged IP Pipe with Incumbent Un-SIP-Aware Firewall 1 VoIP and bulk enterprise share the same IP pipe. 2 QoS is not realized for VoIP since there is no QoS feature in the SAFE. 3 The UA handles all SIP addressing transformation issues between the LAN and WAN demarc via SIP NAT transversal features and/or by using STUN-Simple Transversal of User datagram protocol with an external STUN server. 4 The USAFW security is breached by having ports opened for SIP UDP traffic. 5 Full utilization of incumbent IP pipe for VoIP realized. 6 Architecture does not scale well for anything beyond a few VoIP calls. 7 This is architecture is suited only for hosted VoIP services with a small number of end-user stations in the LAN space.

6. The ITSP behind the SIP Trunk Getting to the ITSP proxy Resiliency in the event of failure Load to the ITSP proxy (dynamic routing to) When an ITSP element fails (real-time dynamic fault switchover) Getting to the PSTN- PSTN carrier options

VoIP Network Architecture: N-Plus

Special ITSP Services for SIP Trunkers Online Traffic monitoring (TotalView) Online Billing Traffic re-routing (Total Reroute) Silent Running Bandwidth Conservation

Completed Call Percentages

Real-Time Call Activity

Accounting History

ITSP Summary SIP Trunking Competes- and beats T1 Trunking on price and features QoS- SAFW and or MPLS needed for bandwidth QoS SIP CPE Architecture- critical for creating a secure clear call The ITSP Behind the SIP Trunk- an architecture is needed SIP Security private or public, it can be made secure

Questions?

About BandTel Headquartered in Newport Beach, California, BandTel is a leading worldwide provider of SIP Trunking services. The company is dedicated to ensuring its customers and partners alike have access to the most reliable, end-to-end VoIP service available on the market today. Its N-Plus network architecture is designed to solve the throughput and redundancy problems on high-capacity SIP-based networks and eliminate any single point of failure. Currently servicing customers worldwide, including Call Centers, Enterprise customers and IVR providers. BandTel continues to develop strong partnerships with leading carriers and telecommunications companies, including Global Crossing, XO Communications, Level 3, Qwest Communications, Verizon Business, ArbiNet, and Primus.

For More Information About SIP Trunking Visit BandTel s New SIP Trunking Resource Center www.bandtel.com