List Info

Thread: Question about Firewall...




Question about Firewall...
country flaguser name
United States
2008-03-06 10:55:06
Good afternoon all.

I'm new to SIP-X, but really like what I see.

I have a question about general deployment.  I want to
create an HA  
scenerio, so we're purchasing 2 servers.  My goal was to
have these  
servers reside on the public network, without a firewall, to
avoid the  
need for an SBC.  Does anyone know of any reason why this
would be  
really bad?

I know its not best practice, but are there any major
security holes  
that people know of now that would make this a really bad
idea at this  
point?

If so, can anyone recommend a good (yet inexpensive) SBC?

Thanks
Kris
_______________________________________________
discuss mailing list
discusslist.sipfoundry.org

https://list.sipfoundry.org/mailman/listinfo/discuss
List Archive: http://lis
t.sipfoundry.org/archive/discuss

Re: Question about Firewall...
country flaguser name
United States
2008-03-06 12:19:05
On Thu, 2008-03-06 at 11:55 -0500, Kristian Guntzelman
wrote:
> I know its not best practice, but are there any major
security holes  
> that people know of now that would make this a really
bad idea at this  
> point?

None that we know of.  Are you comfortable running an
ordinary server
without a firewall?

> If so, can anyone recommend a good (yet inexpensive)
SBC?

I don't think there are any inexpensive SBCs at all.

The ITSP bridge that is under development
(http://t
rack.sipfoundry.org/browse/XECS-1014) can probably be
used as
an SBC.

Dale


_______________________________________________
discuss mailing list
discusslist.sipfoundry.org

https://list.sipfoundry.org/mailman/listinfo/discuss
List Archive: http://lis
t.sipfoundry.org/archive/discuss

Re: Question about Firewall...
country flaguser name
United States
2008-03-06 12:58:31
On Thu, 2008-03-06 at 11:55 -0500, Kristian Guntzelman
wrote:
> Good afternoon all.
> 
> I'm new to SIP-X, but really like what I see.
> 
> I have a question about general deployment.  I want to
create an HA  
> scenerio, so we're purchasing 2 servers.  My goal was
to have these  
> servers reside on the public network, without a
firewall, to avoid the  
> need for an SBC.  Does anyone know of any reason why
this would be  
> really bad?
> 
> I know its not best practice, but are there any major
security holes  
> that people know of now that would make this a really
bad idea at this  
> point?
> 
> If so, can anyone recommend a good (yet inexpensive)
SBC?

The sipx-users list would be a much better place to ask....

No, there's no particularly egregious security problem with
sipX itself,
but if you're planning to connect a PSTN gateway to a public
IP address,
and you'll be paying for the calls it sends to the phone
company, you'd
be well advised to keep a very close eye on it.

-- 
Scott Lawrence  tel:+1.781.229.0533;ext=162 or
sip:slawrencepingtel.com
  sipXecs project coordinator - SIPfoundry http://www.sipfound
ry.org/sipXecs
  CTO, Voice Solutions   - Bluesocket Inc. http://www.bluesocket.com/
 
                                           http://www.pingtel.com/

_______________________________________________
discuss mailing list
discusslist.sipfoundry.org

https://list.sipfoundry.org/mailman/listinfo/discuss
List Archive: http://lis
t.sipfoundry.org/archive/discuss

[1-3]

about | contact  Other archives ( Real Estate discussion Medical topics )