Section 4 Firewalls And Nat - NEC Univerge SV9100 Manual

Hide thumbs Also See for Univerge SV9100:
Table of Contents

Advertisement

Network Address Translation (NAT)
Usually, the equipment that your ISP provides (cable modem, ADSL router, etc.)
uses Network Address Translation. This allows several devices to share one public
IP address. The issues relating to the use of NAT are outlined in Firewalls and NAT
below.
VPN
Due to the use of NAT, and non-routable IP addressing, it is necessary to implement
a VPN solution. This is outlined in VPN Tunneling below. (Refer to
Private Network (VPN) Tunnelling on page
QoS
As discussed earlier, it is essential to have some form of Quality of Service
implemented. With Internet based connections, we are not in control of the many
routers, switches and other network hardware that reside between our two VoIP
endpoints. This means that we cannot specify any QoS parameter on these devices.
The only point where the QoS can be controlled is at the VPN or firewall. This allows
VoIP traffic to be prioritized over any other data that is sent out to the Internet. This
helps to maintain reasonable quality speech – but once the data has exited the local
router/cable modem it is at the mercy of the Internet.
When implementing UNIVERGE SV9100 IP over Internet based connections it is
very important that these factors are considered, and that the customer is made
aware that neither the installer nor NEC are held responsible for any quality issues
experienced.
S
4
F
ECTION
IREWALLS AND
The ways in which networks are designed to be secure (firewall, VPN services, proxy
servers, etc.) and integration of NAT create problems for VoIP. This is due in part, to
the endless number of different scenarios for non-real time protocols and their limited
solutions.
4.1
5-6
NAT
Understanding the Infrastructure
The networks in place today look very different than the networks of yesterday. In
the past, only computers and servers were connected to the network. The network
was built to be as a best effort delivery mechanism, where delay and lost of
information between devices was something we dealt with. Today, there is an over
saturation of devices needing to gain access to the IP network. Desktop
computers, fax machines, wireless PDAs, Servers, home appliances, video
servers and now VoIP terminals all are fighting for bandwidth, precedence, and
addresses on this converged network.
5-8.)
Network Design Considerations
Issue 2.0
4.3 Virtual

Advertisement

Table of Contents
loading

Table of Contents