Planning VoIP deployments

October 30, 2006, 10:15 AM —  WindowsNetworking.com — 


Digg!


(WINDOWSNETWORKING.COM)
This article discusses management of the VoIP PBX, and proposes that it be treated as another service which should be comprehensively managed by the network administrator. It will demonstrate how Voice connectivity relates to data networks and how to effectively and securely implement a PBX within the context of a network infrastructure.


Convergence



Network administrators now have multiple, varied methods of communication running on their network. Whilst protocols and services such as web and email, SMTP and HTTP, are well understood and the techniques for securing these are widely known and discussed, VoIP understanding is often lacking. With the convergence of voice and data networks comes the convergence of roles within an organisation. IT and Telecoms staff are not distinctly separate and there can be an overlap in roles. This can often lead to misunderstandings by staff who make assumptions about systems that they are not familiar with, in environments they are not used to.



This however does not mean that handling voice and data communications need to be complex and hard to understand. In fact, due to the convergence and the fact that VoIP necessarily uses IP, which is also the basis for our data network, we need not treat VoIP infrastructure any differently than our data infrastructure. By looking at common network setups we will see how easy it is to design a secure and stable VoIP infrastructure by using similar principles to those employed in the design of data networks. The principle example we will discuss here is that of Front End and Back End servers, common in the use of e-mail amongst many other applications.



The entry points


When discussing the security and accessibility of a service within a network, a lot of our focus is on the entry points. Questions we should be asking ourselves include:



Where are our users?

- They are on the Internet, PSTN, Internal Voice and Internal Data networks



Where are our threats?

- Every connection point could pose a threat to the others



What connectivity between servers and services are there?

- Incoming and outgoing VoIP over the Internet from/to the PBX (SIP/H.323/IAX/RTP/etc..)

- Incoming and outgoing calls over the PSTN, via ISDN/T1/E1/POTS

- VoIP clients on the internal data network using the VoIP protocls listed above

- Analogue and digital telephones on the internal voice network



There are other points to consider, but generally we are worried about connectivity, ways in/out of our network and who might be using them. The ideas and techniques employed in the pursuit of data security on IP networks relate directly to a VoIP PBX. Our major added complexity is the fact that the PBX may be the terminating equipment on a telephone line. The consequence of this is that we must treat this device as we would any other such device (such as our border router) exposed to a public network. Therefore, we must not trust traffic at this point and would want to have a firewall and/or intrusion detection system between the device and the rest

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Free books

Essential JavaFX
Get started building rich Web apps quickly with an introduction to the power of JavaFX key features -- scene node graphs, nodes as components, the coordinate system, layout options, colors and gradients, custom classes with inheritance, animation, binding, and event handlers.Enter now!

The Nomadic Developer
Consulting can be hugely rewarding, but it's easy to fail if you are unprepared. To succeed, you need a mentor who knows the lay of the land. Aaron Erickson is your mentor, and this is your guidebook. Enter now!

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

Marketplace