SearchSearch  Log in to check your private messagesLog in to check your private messages  recent posts Recent Posts
Post new topic   Reply to topic
View previous topic Printable version Log in to check your private messages View next topic
Author Message
osiris123dOffline



Joined: Jan 04, 2009
Posts: 20

Status: Offline
Posted: Jun 12, 2009 - 10:29 PM Reply with quote Back to top
I have read that you need SBC's for Cloud Edge services and also to protect from DoS attacks, but I was undering the following

Isn't it possible to initially start out an ITSP with your VoIP servers and have them protected by a firewall? The firewall will protect you from half open TCP SYN attacks, but if someone is just throwing a ton of bandwidth at you not even your Acme Packet SBC is going to be able to stop that.

Am I wrong here?

I looked at OpenSBC, but I don't think it mentions anything about protecting you from DoS Attacks or any kind of security.
View user's profile Send private message
deanOffline
Site Admin


Joined: Dec 13, 2003
Posts: 7868
Location: London
Status: Offline
Posted: Jun 12, 2009 - 11:47 PM Reply with quote Back to top
Quote:
Isn't it possible to initially start out an ITSP with your VoIP servers and have them protected by a firewall?


Yes.

Remember that an SBC is a layer 5 device, an IP based firewall is layer 3.

Layer 3 IP protection will protect against a DoS attack.

That just leaves you requiring something to handle NAT traversal, call timing etc. These days the expression "SBC" can mean pretty much anything that resides on the cloud edge.
View user's profile Send private message
osiris123dOffline



Joined: Jan 04, 2009
Posts: 20

Status: Offline
Posted: Jun 13, 2009 - 03:32 AM Reply with quote Back to top
Quote:
I looked at OpenSBC, but I don't think it mentions anything about protecting you from DoS Attacks or any kind of security.


Just saw that OpenSBC can be installed on the same box as Vyatta. So that solves the firewall concern I had.

I forgot about the NAT Traversal which is the major issue.

But as for call timeing I thought the actual SIP Proxy would be the one that kept up with this since the SIP Proxy will be the one that receives the BYE SIP message?

From reading around it sounds like you can use all these open source VoIP programs for many things and have many different topology scenarios. Like for instance they mention that OpenSBC can be used as a B2BUA, yet I figured you would want your Openser box doing that or Asterisk/Freeswitch. And then with Kamailio/Opensips on their Features page it says "NAT traversal support for SIP and RTP traffic". So it sounds like it would be possible to use that software for your NAT Traversal issues (if you wanted the box sitting on the internet of course).

Thanks for all the info.
View user's profile Send private message
deanOffline
Site Admin


Joined: Dec 13, 2003
Posts: 7868
Location: London
Status: Offline
Posted: Jun 13, 2009 - 02:34 PM Reply with quote Back to top
Quote:
But as for call timeing I thought the actual SIP Proxy would be the one that kept up with this since the SIP Proxy will be the one that receives the BYE SIP message?


But can you guarantee that you will receive that BYE message? SIP is just signalling remember. Really you want to be timing the media stream.

Quote:
OpenSBC can be used as a B2BUA, yet I figured you would want your Openser box doing that or Asterisk/Freeswitch


Openser is just a SIP proxy/registrar. So it can act as a SIP B2BUA only, on it's own.

You can use openSER and RTP proxy together, with NAT traversal, but I don't believe that RTP proxy has support for timing calls.
View user's profile Send private message
osiris123dOffline



Joined: Jan 04, 2009
Posts: 20

Status: Offline
Posted: Jun 16, 2009 - 08:39 PM Reply with quote Back to top
Thanks for the info Dean. Love the Forum
View user's profile Send private message


View previous topic Printable version Log in to check your private messages View next topic

Post new topic   Reply to topic
Forum Rules and Guidelines | About VoIP User | Privacy Policy


All logos and trademarks in this site are property of their respective owner.
Comments and posts are property of the poster, all the rest (c) 2003-2008 VoIP User Limited.

VoIP User Limited is incorporated in England and Wales under Company Number 6694577.

No part of this site may be reproduced without our prior consent.