44cd9543058d327eabbfe9ffbe1272fc.ppt
- Количество слайдов: 44
The IX 78 for SMB Deployments both for Hosted SIP Services and SIP Trunking Intertex Data AB, March 2012 © 2012 Intertex Data AB 1
What’s in the IX 78? Ø Ø Ø Ø Ø ADSL 2+ modem with Annex A/B/M (24 Mbps DS, 3 Mbps US), or Ethernet WAN (VLAN capable) Triple play and various routing configuration possibilities Router with any port, any service capability and 4 -5 port Ethernet Switch Wireless 802. 11 b/g as Access Point (3 SSID for separate WLANs) Business Firewall Advanced Qo. S for voice, IP-TV etc. VPN (IPsec with certificate handling) TR-069 and proprietary flexible provision system and in addition to Vo. IP things like Ø 2 FXS ports for analog telephones and FAX with T. 38 support Ø FXO port: Real SIP/PSTN gateway + Fallback on WAN loss there are outstanding features enabling new applications and services Ø Unique support for standard SIP phones and soft clients on the LAN and WLAN Ø SIP Trunking of PBXs – unequalled interoperability list Let’s have closer look Ø SIP Proxy, Registrar and PBX-like functionality what can be achieved! and more… © 2012 Intertex Data and Ingate Systems 2
SIP is the Most Important Protocol, but… A common Network and common Protocols changed our lives: SMTP gave us global email! HTTP gave us the WEB! IMS SIP is the Internet standard for Live IP Communication: The next step of Internet usage! Find each other and do something in real time. Telephony being just one application. However, SIP does not traverse the common NATs and firewalls* separating the LANs from the Internet . (SIP based) Internet email FW * Live IP Communication Requires: - Locate the person - Set up a session - Open real time media streams © 2012 Intertex Data and Ingate Systems FW LAN web FW FW LAN
We Need a Future of Live All IP Connectivity! IMS Global IP Connectivity Vo. IP++ All SIP Services In the world of Unified Communication and global IP-communication, SIP must be used as general as SMTP for email and HTTP for the Web! © 2012 Intertex Data and Ingate Systems
The Intertex & Ingate SIP Architecture To get general NAT/Firewall SIP traversal: Firewall & NAT Router ü Dynamic NAT & Firewall Engine Used for NAT/Firewall traversal and also as: ü SIP Proxy Server, capable of routing - Outbound proxy to/from various address spaces (NAT) - Inbound proxy - SIP Server ü The routing SIP Proxy Server controls - PBX (The SIP Switch) the media through the NAT & Firewall Most of for user location ü SIP Registrar these elements used when SIP Trunking information User SIP ü B 2 BUA invoked in addition when required Proxy Location UA | © 2012 Intertex Data and Ingate Systems 5
The Many Faces of the IX 78 In addition to being a router, a firewall, a wireless access point, an ADSL modem etc. , the IX 78 has several SIP and Telephony related functions: Ø SIP ATA device (2 FXS ports, 1 FXO port) ØSIP E-SBC Gateway for hosted services – LAN and WLAN SIP devices have global SIP connectivity IX 78 for Hosted SIP Services Ø SIP Trunking E-SBC – Connecting IP PBXs directly to operator’s SIP Telephony Services ØUnique SIP support including proxy and registrar, various Vo. IP network architectures supported, advanced SIP and Telephony routing, built in PBX All these functions can be used together and at the same time! © 2012 Intertex Data and Ingate Systems 6
Ordinary Voice IADs – Good for Telephony Replication… Telephone ports (FXS) on the CPE is a popular way to deploy IP telephony. By logically placing the SIP clients on the outside of the NAT/Firewall, unreliable work-around methods like STUN, TURN and ICE become unnecessary. However, this only gives POTS replication, often even stopping general SIP based services! Internet The 5060 SIP-port is just grabbed on the outside to the FXS ports! Lower level SIP ALGs often cause problems and do not handle more than basic scenarios. Often problems with, or total lack of: • SIP to the LAN or Wi. Fi • Calls between SIP clients on LAN • Calls between internal ATA ports and LAN clients • Call transfers, 3 -party calls, etc. • Using SIP generally over the Internet (Operator “took all the SIP”) (Users must not be deprived of general SIP-functionality!) © 2012 Intertex Data and Ingate Systems 7
Intertex’ IADs are SIP Capable NAT/Router/Firewalls IMS Internet SIP No battery draining of Wi. Fi mobile phones, otherwise caused by keep-alive packets* inhibiting sleep mode. * Work-around methods for SIP NAT-traversal like STUN, TURN, ICE and Far End NAT Traversal use frequent keep-alive packets to keep holes in the NAT/Firewall open. § Problems solved where they occur § Wired or wireless SIP clients (phones, soft clients, PDAs) § No special requirements on the SIP Client – Just standard SIP All Intertex CPEs have a SIP Proxy based SIP aware Firewall/NAT § General, can handle complex call scenarios and all SIP services § Additional functionality available (SIP server, PBX functionality etc. ) © 2012 Intertex Data and Ingate Systems 8
Full Support for all SIP Applications SIP offers so much more than just telephony Go beyond POTS replacement! © 2012 Intertex Data and Ingate Systems 9
The Many Faces of the IX 78 In addition to being a router, a firewall, a wireless access point, an ADSL modem etc. , the IX 78 has several SIP and Telephony related functions: Ø SIP ATA device (2 FXS ports, 1 FXO port) ØSIP E-SBC Gateway for hosted services – LAN and WLAN SIP devices have global SIP connectivity Ø SIP Trunking E-SBC – Connecting IP PBXs directly to operator’s SIP Telephony Services IX 78 for SIP Trunking ØUnique SIP support including proxy and registrar, various Vo. IP network architectures supported, advanced SIP and Telephony routing, built in PBX All these functions can be used together and at the same time! © 2012 Intertex Data and Ingate Systems 10
SIP-Trunking for the IX 78 Connecting IP PBXs to Operators’ SIP Services Ø The era of replacing T 1/E 1/PRI lines for IP connections to operators’ SIP telephony services has begun. Ø Most IP PBXs require SIP traversal of the enterprise firewall and some special additions. Ø Intertex’ sister company Ingate has taken the SIP-Trunking lead. http: //www. ingate. com/SIP_Trunk_UC_Summit_LA_2010. php ØIX 78 can enable E-SBC (Enterprise Session Border Controller) functions for SIP Trunking IX 78 includes the same SIP Trunking functionality as the Ingate Enterprise line of E-SBCs!
IX 78 E-SBC Enterprise Line of E-SBCs § Ingate Firewalls and SIParators® – E-SBC § From 50 to 3 000 simultaneous calls (with media) § Used in a wide variety of SIP Trunking installations § NAT/Firewall traversal § Superior SIP Normalization § Multi level security, incl. SIP IDS/IPS § Qo. S (Quality of Service) 150/400/1000 Calls* § Failover configurations 500/700/900 Mbit/s 40 000/80 000/160 000 Packets/s Ingate IX 78 for operator volume deployments 1800/3000/8000 Calls* 4 500/ 5 000 Mbit/s 300 000/500 000/900 000 Packets/s Software Firewall/SIParator ® 25 - 10 000 Calls* 50 Calls* 200 Mbit/s 30 000 Packets/s 50 Calls* 90 Mbit/s 10 000 Packets/s Can be installed on a virtual machine or natively x 86 Linux Servers (industry-standard PC architecture) *) Calls = Concurrent RTP Sessions = SIP Trunks 12
Confirmed Interoperability: Ingate & Intertex SIP Trunk Providers IP-PBXs § Nexvortex § 360 Networks § Nuvox § Airespring § O 1 § AT&T § One Communications § Band. Tel § Paetec § Bandwidth. com § Primus § Broadvox § RNK Telecom § BT (British Telecom) § Skype § Cablevision § TDC § Cbeyond § Telavox § Cellip § Tele 2 § Comm Partners § Tele Pacific § Cordia Corporation § Teletek § Deltacom § Telia. Sonera § Excel Switching § Toplink § Gamma Telecom § Tritel § GEOS § Vo. EX § Global Crossing § Voice Flex § IP-Only § Vo. IP Unlimited § Nectar § Voxbone § Level 3 § Voxitas § Netlogic § Xelo. Q § Netsolutions More in pipeline. . . Compliant with Carrier Equipment § Acme Packet § Broadsoft § Genband § Sonus SIP Trunk § Sylantro § SER § NSN More in pipeline… © 2012 Intertex Data and Ingate Systems § Aastra/Ericsson MX One § Adtran UC Server § Digium/Asterisk § Avaya Aura § Avaya IP Office § Avaya SES/CM § Avaya QE § Brekeke § Broadsoft § Cisco § Fonality § HP/3 Com -VCX § Innovaphone § Interactive Intelligence § Iwatsu § LG Nortel § Microsoft OCS § Mitel § NEC / Sphere § Nortel BCM § Nortel SCS § Objectworld § Panasonic § Samsung § SER § Shoretel § Siemens § SIP-Gear § Swyx More in pipeline. .
The IP-PBX Trunk Must Meet Service Provider Trunk PSTN SIP Trunking Provider Network. GW Why may an IX 78 be required to connect a PBX? 1) NAT/Firewall Traversal – Must NAT to same address space! 2) Basic SIP and Network Interoperability - E. g. Authentication, Registrations, UDP/TLS/TCP, Dynamic IP address, etc. SIP System 3) SIP Repair - E. g. Call Transfer, Fragmented packets, Bugs, etc. 4) Features - E. g. Remote Users, Administration (remote and local) 5) Security - E. g. Will LAN be opened? Is the PBX designed to be public? SIP Trunk 1) 2) 3) 4) 5) IX 78 IPPBX 2) 3) 4) 5) SIP Trunk Interface Modern IP-PBXs are of this type. Media goes directly between phone and SIP Trunk. PBX with system phones IPPBX Few PBXs are of this type. Asterisk with firewall (IPtables /NETfilter) can be compiled and configured this way, but requires a lot. Vo. IP & Data LAN only PBX Type 1 Signaling: Media: PBX Type 1. 5 PBX Type 2
Intertex IX 78 Simply Presents the SIP Trunking Service on the Customer’s Protected Combined Vo. IP & Data LAN, Ready for any PBX to Use Public Internet SIP Trunking Provider SIP System GW PSTN Remote Users IP-PBX Intertex IX 78 Demarcation point of service and bringing SIP communication to the LAN Firew all Data & Vo. IP LAN Soft Clients and Multimedia Terminals © 2012 Intertex Data and Ingate Systems 15
… or from an Extra IP Connection, still in Parallel with an Existing, non SIP Aware Firewall Public Internet SIP Trunking Provider SIP System GW PSTN Remote Users IP-PBX Intertex IX 78 Demarcation point of service and bringing SIP communication to the LAN Firew all Data & Vo. IP LAN Soft Clients and Multimedia Terminals © 2012 Intertex Data and Ingate Systems 16
… or the Intertex IX 78 can be the Company Firewall, presenting the Customer with a Protected Combined Vo. IP & Data LAN, Ready to use! Public Internet SIP Trunking Provider SIP System GW PSTN Remote Users Intertex IX 78 Demarcation point of service and bringing SIP communication to the LAN IP-PBX Data & Vo. IP LAN Soft Clients and Multimedia Terminals © 2012 Intertex Data and Ingate Systems 17
…and the IX 78 can Support Many WAN Layer 2 and Layer 3 Architectures with Qo. S Separated WAN Interfaces (inherited from it’s triple play capabilities) E. g. Telia Internet IMS IP-TV Vo. D PVC 1 IP-TV Vo. IP IMS Vo. D VLAN 1 PVC 3 PVC 2 ADSL E. g. B 2 VLAN 3 VLAN 2 Virtual LANs (VLAN) Ethernet Private Virtual Circuits Vo. IP E. g. BT Internet IMS IP-TV Vo. D WAN 1 WAN 2 Ethernet IP-TV Vo. D Internet Priority 2 Vo. IP Priority 3 IMS Vo. IP Priority 1 WAN 3 IP Qo. S Separated Subnets ADSL or Ethernet IP Level Qo. S The Intertex IX 78 Supports All of these Architectures! © 2012 Intertex Data and Ingate Systems 18
Proposed Setup for the DOCSIS Network PSTN Easy and advantageous installation using advanced WAN SIParator mode SIP Trunk Provider G W Public Internet SIP System Ø Plug in existing firewall to Ethernet port 4 on the IX 78 (bridged connection to the WAN) CMTS Bridge for Existing NAT/ Firewall (non SIP aware) Cable Modem IX 78 E-SBC IPNAT/ PBX Firew all Data & Vo. IP LAN Ø IX 78 WAN SIParator will handle Qo. S (backing off firewall’s data traffic if required) Ø WAN SIParator 2 – requires two IP addresses, one for the firewall, another for the IX 78 Ø WAN SIParator 1 – requires only one IP address, shared between the IX 78 and the firewall Ø DHCP or fixed WAN IP address(es)
SIP Trunking Made Easy Installation Wizard © 2012 Intertex Data and Ingate Systems 20
SIP Trunking in Proxy Mode or B 2 BUA Mode Ø Proxy Mode § IP-PBX talks to Service § Registration/Authentication model must match § Little configuration in the IX 78 § Service credentials in the PBX Ø B 2 BUA Mode (Proxy still doing the basics) IPPBX § IP-PBX only talks to the IX 78 § Wider separation between PBX and Service § Service Credentials only in the IX 78 § More SIP Normalization possibilities (e. g. REFER) § Any new operator service platform only requires IX 78 reconfiguration (the PBX configuration can remain) © 2012 Intertex Data and Ingate Systems IPPBX 21
Trunk-side Parameters (B 2 BUA Mode) © 2012 Intertex Data and Ingate Systems 22
PBX-side Parameters (B 2 BUA Mode) © 2012 Intertex Data and Ingate Systems 23
Registration, Call Routing, Caller. ID (B 2 BUA Mode) © 2012 Intertex Data and Ingate Systems 24
The Many Faces of the IX 78 In addition to being a router, a firewall, a wireless access point, an ADSL modem etc. , the IX 78 has several SIP and Telephony related functions: Ø SIP ATA device (2 FXS ports, 1 FXO port) ØSIP E-SBC Gateway for hosted services – LAN and WLAN SIP devices have global SIP connectivity Ø SIP Trunking E-SBC – Connecting IP PBXs directly to operator’s SIP Telephony Services ØUnique SIP support including proxy and registrar, various Vo. IP network architectures supported, advanced SIP and Telephony routing, built in PBX All these functions can be used together and at the same time! © 2012 Intertex Data and Ingate Systems 25
Add SIP Clients, Use as Basic PBX, Move on to Full PBX There are many PBXs out there that do not allow Soft Clients, Remote Users or Standard SIP Phones. ted ntegra si umber N Registrar Remote Users PBX with non-SIP phones Soft Client Wi. Fi Mobile PBX Retire the old PBX…
The PBX – Simple and Capable Administrator’s Overview and Configuration © 2012 Intertex Data and Ingate Systems 27
The PBX – The things you need Personal Settings
Ready and In Use! Ø IX 78 E-SBC used in volume by Sweden’s incumbant Telia. Sonera in SIP Trunking Services: § Over ADSL (built-in ADSL modem, multiple PVC) § Over Managed Internet ”Prolane” service (IP Qo. S) § Over Fiber LAN (multiple VLANs) Ø Others in progress Ø Ingate products are used in a wide variety of SIP Trunking installations Ø Ready and used for more than POTS Replacement § Vo. IP++ = Global IP Connectivity & All types of SIP services § Multimedia and Unified Communications Ø Element Managemen System - i. EMS (more later) § Basics available now – Continously extended – Adaptions to operator requests § i. EMS will later also be used for Ingate’s larger products § More managed services via the i. EMS (SIP Trunking, PBX, Firewall, VPN) © 2012 Intertex Data and Ingate Systems 29
Performance and Call Handling Capacity Ø Over 50 simultaneous calls (20 ms voice packets) carrying media Ø Call rate of 8 calls/s in proxy mode and 3 calls/s in B 2 BUA mode. (way above the requirement to support 24 or 50 simultaneous calls) Ø Up to 255 registrations. SIP end-points can be more. Ø CPU Usage: © 2012 Intertex Data and Ingate Systems 30
From Conventional Services Over New Wires Telephony TV Internet to The Multimedia LAN New terminals (PCs, Mobile Phones etc) will handle everything and must get all the accesses with Reliability and Quality. It’s time to get it together and add more! © 2012 Intertex Data and Ingate Systems 31
Advanced Triple Play Architecture IMS and Vo. IP Services for ALL Terminals over ALL Pipes! The Multimedia LAN Internet IMS Vo. IP IP-TV TR-069 All services must be available to multimedia terminals! – Over controlled high Qo. S pipes as well as the Internet. Application Innovation Requires it! Vo. D VLANs or ADSL Virtual Circuits WLAN Internet The Multimedia LAN PDA Telepresence © 2012 Intertex Data and Ingate Systems Lots of new CPE requirements to meet
IX 78 Architecture and Functionality A user attractive architecture for multimedia services and terminals. Plug-in compatible CPE, without changed network architecture! t! Ø All services on different WAN-pipes made available to all terminals on a single LAN / WLAN • • All Qo. S advantages preserved from the conventional port the based architecture Network clouds may be NATed or in the public address space Firewall protection on all WAN pipes (PVCs, VLANs etc. ) Qo. S based routing, in addition to traditional address based routing lly ly Ø Special IP TV requirements • • • u IGMP proxy for multicast IP-TV, with fast leave and multi- to unicast conversion , b o RTSP proxy for Vo. D (Video on Demand) tt nstreams Horsepower and intelligent packet dropping to maintain priority on critical video a yw n Ma Ø Full SIP Based Live IP Communication Support • • n to few a a re i do y! t Much more than POTS replication via FXS ports ali Full support for SIP on LAN and globally, without unreliable work-around methods on Qo. S applied to all SIP signaling and media – No client setup required cti n SIP clients can use either Quality Assured operator service or the Internet. SIP communication can be separated and routed fu P universally, with best Qo. S on each network SI e Support for all SIP services (not just telephony) qu Equal treatment and full connectivity between telephony ports (FXS), LAN or WLAN connectediclients as well as outside clients un SIP and IMS supported over the Vo. IP and IMS pipe as well as over the Internet and routeds i globally h t as h tex r e Int y l On © 2012 Intertex Data and Ingate Systems 33
Powerful Provisioning Systems Use standardized TR-069 and TR-104 or Intertex’ provisioning - easy to integrate with existing customer handling system § Initial automated configuration to get up and running THEREAFTER: § Continued Configuring – New or updated settings easily distributed § Firmware Upgrade – The CPE can look for new firmware releases and upgrade itself § Customer Purchases – Software options, licenses and even hardware accessories, can be ordered and delivered from IG Shop. Provisioner sells to his customer as usual. Unlocking of subsidized CPE can also be sold this way. © 2012 Intertex Data and Ingate Systems ch wit PS. SI etc le, b Ca 34
The SIP Trunking Installation Wizard Ø jkjjk
Element Management System – The i. EMS Ø Functions for Provisioning, Monitoring, Reporting, Diagnostics, Logging, Debugging, Support, Configuration and Upgrade. Available now with basic functionality. Ø Will handle both Ingate and Intertex Firewalls and SIParators. Ø Highly scalable, runs on PC servers under the Linux OS. Ø HTTPS/SOAP interface to the IX 78. Can read and write all configuration parameters, as well as asynchronous reporting by the device (like SNMP traps). Ø Web based secure access to the i. EMS. Customized portals for operators, installers and customers, for the purpose of administration, management and usage. Ø The i. EMS has northbound interfaces for integrating with the operator’s OSS and Fault Management systems, using XML-RPC and/or SOAP. © 2012 Intertex Data and Ingate Systems 36
i. EMS – CDRs with Call Quality Metrics © 2012 Intertex Data and Ingate Systems 37
Billing – CDRs for Efficient Processing Now also with Video Call Metrics and Pipe Used! CDRs with Call Quality Metrics – View from i. EMS (our TR-69 management system) © 2012 Intertex Data and Ingate Systems
i. EMS Interfaces OSS, Fault Management, etc. XML-RPC (or SOAP) (GET/SET/EVENTS) Northbound API WEB GUI DB DB DB Southbound API WAN CPE CPE <? xml version="1. 0"? > <method. Call> <method. Name>set. Trunk</method. Name> <params><param><struct> <member><name>version</name><value>1. 0</value></member> <member><name>ems</name><value><struct> <member><name>username</name><value>installer</value> <member><name>password</name><value>foobar 123</value></ </struct></value></member> <member><name>service</name><value><struct> <member><name>registrar</name><value>sip. intertex. se</ <member><name>proxy</name><value>proxy. intertex. se</value </struct></value></member> <member><name>trunk</name><value> <array><data> <value><struct> <member><name>identity</name><value>5162809890</val <member><name>password</name><value>foobar</value></membe </struct></value> <value><struct> <member><name>identity</name><value>5162809895</val <member><name>password</name><value>barfoo</value> </struct></value> </data></array> </value></member> CPE </struct></params> </method. Call> CPE CPE © 2012 Intertex Data and Ingate Systems 39
Technology and Competence "Intertex specialises in the development of communication and security products. “ "Extensive experience of real-time and application programming as well as analogue and digital hardware design. " Anders Business Awards: v Challenger of the Year 1995 v Rookie of the Year 1996 v The Award of Electronics 1997 v The Golden Mouse 1998 v Trippel A (AAA) 1999 and 2000 v Editor's Choice Networking EXHardware 2002 v World of ADSL Golden Award 2002 v Internet Telephony Product of the Year 2003 v Communication Solutions – P. of the Year 2003 v European IST Prize 2004 v Internet Telephony Product of the Year 2004 v Pulver 100, numerous v Internet Telephony Editors’ Choice Award 2006 v Best in Test Mikrodatorn 2006 v Internet Telephony Product of the Year 2007, 2008 © 2012 Intertex Data and Ingate Systems 40
SIP Capable Firewalls and SIParators® Thank You! Ingate Systems Inc. Intertex Data AB www. ingate. com Contact: Steve Johnson steve@ingate. com sip: steve@ingate. com Tel: +1 603 883 6569 Mob: +1603 557 7918 www. intertex. se Contact: Karl Stahl karl. stahl@intertex. se sip: kalle@intertex. se Tel: +46 8 12205629 Mob: +46 70 7254532 © 2012 Intertex Data and Ingate Systems 41
Making the E-SBC do it – WAN Quality IP Network Ø Connects to High Quality OVCC Network and the Internet (If you wish) Ø Handles Multimedia and Data (If you wish) with advanced Qo. S Ø Connects via DSL (IX 78 only) or Ethernet (VLAN tagged or not) Extra High Quality WAN Interface over PVC or VLAN Ethernet Or hook it into a separate Ethernet Interface Ø Classified traffic (Teleprecense, Voice…) takes the fine pipe © 2012 Intertex Data and Ingate Systems
Making the E-SBC do it – Classify Traffic Ø Outgoing calls shall take the right pipe (Incoming – signaling and media - stays where it came in) Ø Classifying in the E-SBC Outbound Proxy is a good way Devices Registered to own registrar/PBX OVCC MSP 1 Registered Devices registered to Internet connected ITSP Ø Classified traffic (Telepresence, Voice…) takes the quality pipe Ø Can also classify based on other criteria, e. g. IP address, DSCP bits, protocol from device © 2012 Intertex Data and Ingate Systems
Making the E-SBC do it – Qo. S, Prioritization Ø Quality of Service setup can be easy (default in the IX 78) Ø Or detailed as in the Ingate line © 2012 Intertex Data and Ingate Systems
44cd9543058d327eabbfe9ffbe1272fc.ppt