18. - SIP - Firewall NAT and SBC

 

Issues to Address

Protection of your network is vital if connected to the internet, Private addressing on the internal network can cause problems when using SIP through a NAT (network address translation service), NAPT also introduces another set of problems and finally SIP has a firewall to content with.

 

Firewalls

Corporate and personal firewalls are usually placed at the wedge of the network to act as a perimeter device that can permit traffic leaving and entering thenetwork, usually all traffic originating from within a network is allowed out and traffic from outside is allowed in, firewalls usually allow traffic such as HTTP and SMTP to enter the network, firewalls that are not SIP aware will probably block all SIP traffic and it may be the case that the RTP packets will be blocked as well.

 

NAT

Private addressing on the internal network can cause problems wueh using SIP through a NAT

Full-cone NAT

image.png

Restricted Cone NAT

image.png

Port Restricted NAT

image.png

 

NAT Symmetric

image.png

 

NAPT Introduces another set of problemsimage.png

Problems with NAT are caused because of the hostile environment made for the lack of standardize behaviors and controls in NATs solutions.

STUN (Simple Transversal of UDP)

How it works

Problems

image.png

image.png

image.png

TURN (Traversal Using Relays around NAT)

image.png

 

Interactive Connectivity Establishment (ICE)

image.png


UPnP

image.png

image.png


RTP Problem

 

Solving the RTP problem

 


Revision #3
Created 7 May 2023 05:19:36 by Cesar Gzz
Updated 7 May 2023 06:15:05 by Cesar Gzz