Home > Networking Tips > > SIP Firewalls
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


SIP Firewalls


Tom Lancaster
10.16.2003
Rating: -3.85- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Most organizations that have deployed VoIP have only done so internally to date, but many are now looking at giving IP Phones to work-at-home employees with high-speed Internet access. Others have installed large, fast and stable Internet links and are considering Internet-based VoIP trunks between sites.

For these sorts of applications, you'll likely want a full-featured firewall and fortunately, there are a number of full-featured firewalls that support SIP now. They do this by watching the initial signaling messages. Unbeknownst to the VoIP endpoints, the SIP-aware firewall can read the messages and find out which IP and port will be used for the media streams and then permit only those specific connections instead of a large range of UDP ports. This is good.

However, something else you should consider, particularly if you are in a large organization, is implementing some access-controls internally. You should strongly consider this because your IP-based PBX often needs more protection than other servers because it often runs complex code that is tightly integrated with the OS. This means that when the OS vendor releases a service pack it may be some time before the PBX developers verify that the service pack doesn't break any of their code. The result is that you may not be able to patch your IP PBX before a virus or worm is released that takes advantage of a vulnerability.

Even if it is SIP-aware, a full-featured "Internet firewall" may not be appropriate for use internally for a lot of reasons, so consider as an alternative putting your VoIP hosts on a dedicated subnet and using access-control lists on a router.

The problem with regular access-control lists, of course, is that you still need to open a wide range of ports. To fix this, use the Cisco IOS Firewall FeatureSet and CBAC. Normally, with this featureset, you configure it so that it allows certain traffic out, and only responses back in, however, to enable SIP connections to be initiated from either direction, use the following config:

access-list 101 permit udp any any eq 5060
!
ip inspect name mySIP sip
!
interface fa0/1
  ip inspect mySIP in
!
interface fa0/0
  ip inspect mySIP in
  ip access-group 101 in

Obviously, you will of course have to tailor the ACL and interfaces to your own environment.


Thomas Alexander Lancaster IV is a consultant and author with over ten years experience in the networking industry, focused on Internet infrastructure.


Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Voice/data Convergence
Networking Products of the Year 2004
The best of 2004
Elements of VoIP QoS
Telephony 'just another IP application' according to FCC
A significant VoIP benefit - Unified messaging
IP telephony development tools
SPIT, or Spam over Internet Telephony
First Wi-Fi handset makes its debut
Duties of an IP telephony gateway when integrating VoIP and the PSTN
VoIP and NAT

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business

Alcatel-Lucent Network Business Communications Solutions

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts