The Fortigate Unit And Voip Security; Sip Nat - Fortinet FortiGate Series Administration Manual

Hide thumbs Also See for FortiGate Series:
Table of Contents

Advertisement

SIP support

The FortiGate unit and VoIP security

SIP NAT

Source NAT (SIP and RTP)
FortiGate Version 4.0 MR1 Administration Guide
01-410-89802-20090903
http://docs.fortinet.com/
Feedback
Like data networks, VoIP networks are vulnerable to many of the same security risks,
including denial of service (DoS) attacks, service theft, tampering, and fraud. Many
conventional firewalls cannot protect VoIP networks from attacks because VoIP is
implemented at both the signaling and media layers. VoIP calls cannot go through these
firewalls unless a range of ports are opened – which exposes the network for unauthorized
access.
The FortiGate unit can effectively secure VoIP solutions since it supports VoIP protocols
such as SIP, MGCP, and H.323, and associates state at the signaling layer with packet
flows at the media layer. Using SIP ALG controls, the FortiGate unit can interpret the VoIP
signaling protocols used in the network and dynamically open and close ports (pinholes)
for each specific VoIP call to maintain security.
The FortiGate intrusion prevention system (IPS) provides another strategic line of
defense, particularly against VoIP network predators. The IPS has deep-packet inspection
capabilities to provide continuous surveillance across multiple network sectors
simultaneously, recognizing network traffic expected within each and alerting network
managers to malicious packets and other protocol anomalies.
The FortiGate unit supports network address translation (NAT) of SIP because the
FortiGate ALG can modify the SIP headers correctly.
This section uses scenarios to explain the FortiGate SIP NAT support.
In the source NAT scenario shown in
through a FortiGate unit with PPPoE. The FortiGate ALG translates all private IPs in the
SIP contact header into public IPs.
You need to configure an internal to external UDP firewall policy with NAT checked and a
SIP-enabled protection profile. For more information about firewall policies, see
Policy" on page
387.
Figure 296: SIP source NAT
217.233.122.132
10.72.0.57
The FortiGate unit and VoIP security
Figure
296, a SIP phone connects to the Internet
217.10.79.9
SIP Server
SIP service provider has a SIP server
and a separate RTP server
Internet
"Firewall
217.10.69.11
RTP Server
507

Advertisement

Table of Contents
loading

Table of Contents