Home > Unified Communications Tips > Unified Communications Tech Tip > SIP Firewalls
Unified Communications Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

UNIFIED COMMUNICATIONS TECH TIP

SIP Firewalls


Tom Lancaster
10.16.2003
Rating: -4.25- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Most organizations that have deployed VoIP have only done so internally to date, but many are now looking at giving IP Phones to work-at-home employees with high-speed Internet access. Others have installed large, fast and stable Internet links and are considering Internet-based VoIP trunks between sites.

For these sorts of applications, you'll likely want a full-featured firewall and fortunately, there are a number of full-featured firewalls that support SIP now. They do this by watching the initial signaling messages. Unbeknownst to the VoIP endpoints, the SIP-aware firewall can read the messages and find out which IP and port will be used for the media streams and then permit only those specific connections instead of a large range of UDP ports. This is good.

However, something else you should consider, particularly if you are in a large organization, is implementing some access-controls internally. You should strongly consider this because your IP-based PBX often needs more protection than other servers because it often runs complex code that is tightly integrated with the OS. This means that when the OS vendor releases a service pack it may be some time before the PBX developers verify that the service pack doesn't break any of their code. The result is that you may not be able to patch your IP PBX before a virus or worm is released that takes advantage of a vulnerability.

Even if it is SIP-aware, a full-featured "Internet firewall" may not be appropriate for use internally for a lot of reasons, so consider as an alternative putting your VoIP hosts on a dedicated subnet and using access-control lists on a router.

The problem with regular access-control lists, of course, is that you still need to open a wide range of ports. To fix this, use the Cisco IOS Firewall FeatureSet and CBAC. Normally, with this featureset, you configure it so that it allows certain traffic out, and only responses back in, however, to enable SIP connections to be initiated from either direction, use the following config:

access-list 101 permit udp any any eq 5060
!
ip inspect name mySIP sip
!
interface fa0/1
  ip inspect mySIP in
!
interface fa0/0
  ip inspect mySIP in
  ip access-group 101 in

Obviously, you will of course have to tailor the ACL and interfaces to your own environment.


Thomas Alexander Lancaster IV is a consultant and author with over ten years experience in the networking industry, focused on Internet infrastructure.


Rate this Tip
To rate tips, you must be a member of SearchUnifiedCommunications.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
VoIP Protocols
SIP trunks a no-brainer for VoIP rollouts
Digium's Asterisk PBX does God's work at Midwest church
Microsoft's Real-Time Codec (RTC) for VoIP optimization
Is there a difference between VoIP and IP telephony?
VoIP for the globe-trotting frequent traveler
SIP tutorial
Springer Handbook of Speech Processing
Top 10 VoIP tips for 2007
Push-to-talk implementation using SIP protocol
IP PBX eases VoIP transition for gas company

Unified Communications Tech Tip
Social networking and discussion forums for the enterprise
Streaming Cisco's IP Communicator to an HP thin client
Demystifying unified communications deployment strategies
Presence management and security
Presence: SIMPLE versus XMPP
Four factors driving videoconferencing
Consider IBM Lotus SameTime for UC, not just Microsoft OCS
An introduction to SIP, part 1
What's the value of unified communications?
The benefits and challenges of presence within unified communications

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
G.711  (SearchUnifiedCommunications.com)
G.729  (SearchUnifiedCommunications.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Communications Solutions for Business: Collaboration, Cell Phone Access, and IP Telephony
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts