- Bank Web sites full of security holes
- SCO Group: Its future is all used up
- Maligned feature being added to IPv6
- I returned my iPhone 3G after six days!
- VPNs: Six burning questions
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
We've suggested before that session border controllers (SBC) are necessary within an enterprise network to ensure QoS and security for VoIP and unified communications, and Acme Packet has suggested in a recently published white paper that the need for SBCs is especially acute for Microsoft Office Communications Server (OCS) users. Acme Packet also contends that SBCs are complementary to OCS deployments, and they can improve scalability and reduce total cost of ownership.
As one of the leading SBC providers, Acme Packet has a multi-year history in hundreds of service provider VoIP deployments. Based on the company’s experience, enterprise firewalls are unable to protect the Microsoft OCS edge or core servers. According to Acme Packet “VoIP testing tools operating on any ordinary PC have proven that they can completely disable any popular SIP-enabled firewall (as well as any SIP proxy or PBX) by sending a flood of legitimate or illegitimate SIP messages. These firewalls with SIP Application Layer Gateways (ALG) also have poor topology hiding capabilities. They have been known to expose internal addresses of core SIP servers that are included in SIP message headers.”
Addressing a second issue, Acme Packet points out OCS uses SIP with TLS encryption over TCP and encrypted SRTP for the media. However, SIP PBX vendors have choices in SIP transport protocols (including UDP, TCP, SCTP) choices in signaling and media encryption protocols (including none, TLS, MTLS, IPSec) and choices in DTMF transport (either media or signaling-based). In addition, many installed IP-PBXs still rely on H.323 protocol while others use MGCP or SCCP based endpoints. Therefore, controlling the interoperability of these multiple protocols variations to maximize security and performance between OCS-based SIP protocols, the protocols used by the installed IP-PBX.
Interoperability management between OCS and the IP-PBX should consider:
* Unified dialing plans across multiple, separate IP PBX and OCS deployments.
* Comprehensive security and overload protection for IP PBXs connected to SIP, H.323, MGCP or SCCP-based endpoints.
* The ability to securely bridge heterogeneous IP address spaces.
* Manipulation of telephone numbers, URIs and response codes.
* Transcoding and transrating for a broad range of wireline and wireless codecs.
* Session routing metrics supported for LCR, ENUM, QoS and ASR to minimize costs and maximize session quality.
If the IT manager is knowledgeable regarding Cisco technology, he would have 2 options. Option 1 - Consult...- Anonymous
Partner Content
The Foundry Enterprise Advantage
Foundry Networks, Inc. (NASDAQ: FDRY) is a leading provider of high-performance enterprise and service provider switching, routing, security and Web traffic management solutions. Foundry's customers include the world's premier ISPs, metro service providers, and enterprises.
For further information on Foundry Networks please click here.
Leveraging the Advantages
of a Multi-vendor Network Strategy
Today's enterprise network provides more than simply a technology infrastructure. It's an enabler for the enterprise, supporting mission critical applications, creating operational efficiencies and increasing productivity gains. Foundry Networks provides the ideal foundation for a multi-vendor network.
Click here to view whitepaper!
Comments (2)
Fixing in the articleBy Adam Gaffin on May 5, 2008, 11:01 amThanks for letting us know.
Reply | Read entire comment
bad linkBy Anonymous on April 28, 2008, 11:39 amyou have a bad link A copy of their white paper (including more network diagrams and additional details) is available here.
Reply | Read entire comment
View all comments