Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
When networks fail, hams to the rescue
Alliance to promote Windows-managed Macs in enterprise
Lockheed Martin gets $89 million to converge DoD distribution networks
Clothes don't make this man: Sweatshirt helps nail Citibank card scammer
Microsoft readies new try for Yahoo
Gartner: Seven cloud-computing security risks
Autonomy, Endeca rate among top enterprise search vendors
Barracuda countersues Trend Micro in patent case
Mozilla's Firefox 3 sets geeky world record
Microsoft SharePoint popularity comes with issues
IBM mainframe acquisition raises antitrust concerns
Diary of a deliberately spammed housewife
Report: Tech giants forming 'patent troll' alliance
Trojan lurks, waiting to steal admin passwords
California enacts cell-phone driving ban
Service Provider Networks / Convergence / Bleeding Edge:

Can we talk? VoIP's firewall challenges

Related linksToday's breaking news
Send to a friendFeedback


One of the interesting nuggets from SuperComm 2002 was the lip service that large service providers are giving voice over IP. Under pressure from direct enterprise sales of VoIP platforms to their best customers, BellSouth and others are now offering or planning to offer managed VoIP services from platforms such as Cisco's AVVID equipment. Providers need to keep an eye out for pesky implementation problems that early adopters have discovered. One such issue is the treatment of VoIP in a secure enterprise environment.

At the crux of the problem is the basic enterprise firewall. VoIP problems occur on phone calls that originate in the outside world - a big problem when waiting for someone to call you back. Outgoing calls, originating from the user's desktop through the firewall, are generally handled by the firewall opening a pinhole through which replies can pass. The pinhole is closed eventually (after the call ends), and no further external packets are allowed through. However, with incoming calls from an external service provider, security issues arise. Until recently, the only way to allow inbound calls was to leave a permanent hole from the outside world to the user's IP phone. Obviously, this violates even the most basic firewall security policies. Compounding the problems with VoIP and firewalls is that VoIP doesn't really work well with network address translation (NAT) (sharing one external IP address among many internal computers). NAT is typically performed by the enterprise firewall, so a further tension exists between those trying to deploy VoIP and those responsible for security.

Advertisement:

Much effort is being devoted to solving these problems, and service providers considering VoIP services should weigh alternate solutions carefully. Selecting the "wrong" approach can lead to calls not being completed or voice quality suffering. One approach is to deploy new voice-aware firewalls that can perform protocol "patches" needed to make VoIP work with NAT. There are two ways to adopt this approach: Discard the existing firewall and replace it with a voice-aware firewall, or deploy the new firewall in parallel with the original and pass all nonvoice traffic to the original for processing.

Another approach is to place an "application gateway" in the existing firewall's DMZ where it can process incoming and outgoing voice streams. In this approach, the application gateway can see both internal NAT address space as well as the global address space and can "patch" VoIP protocol fields as they pass from outside to inside. By adding some simple rules to the existing firewall, a new route can be opened from the outside world to the DMZ-based gateway so inbound calls can be handled. This particular approach, provided by companies such as Jasomi Networks and Acme Packet, is often called a "sidecar solution" because it sends VoIP packets into the DMZ. It is similar to the way enterprises cope with security issues involved with e-mail, FTP, DNS and other applications that cross from the inside to the outside world. The overall result of this type of deployment is that standards-based VoIP systems can use this application gateway and eliminate the need for direct communication between the outside world and each user's desktop phone, thus maintaining secure separation.

VoIP is coming into its own. Enterprises are gleaning functionality and cost improvements, and service providers that do not want to see more erosion of their existing enterprise customers will have to be versed on issues like this as managed VoIP solutions come to market.

RELATED LINKS

Archive of "Bleeding Edge" columns

Briere is CEO and Bracco is President of TeleChoice, the strategic catalyst for the telecom industry. They can be reached at telecomcatalyst@telechoice.com.

More Telecom Catalyst columns

VoIP Analysis and Management Tools Buyer's Guide
Jul. 05, 2008

VoIP Security Products Buyer's Guide
Jul. 05, 2008

Mitel upgrades, integrates, and rebrands the Inter-Tel portfolio
Jul. 02, 2008

The long road for unified communications
Jul. 03, 2008

  1   2   3   4   5   6   7   8   9  10  next 

NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.