|
SIP trunking
Session Initiation Protocol (SIP) is the predominant signaling protocol in new unified communications deployments and is the favored method for interconnecting enterprise and service provider networks. By replacing legacy TDM-based telephony infrastructure with SIP-based solutions and converging interactive voice, video and unified communications (UC) onto a common IP backbone, enterprises can consolidate equipment and trunks, streamline operations, and improve collaboration and worker productivity.
An open, standards-based protocol, SIP allows organizations to avoid vendor lock-in and choose from a broad selection of communications solutions and suppliers. Many telecommunications service providers now offer SIP trunking services - flexible, cost-effective alternatives to traditional TDM trunks for PSTN origination/termination - as well as other SIP-based services like hosted conferencing and contact center solutions. SIP also enables direct VoIP peering between enterprise sites and simplifies the introduction of enhanced communications applications, such as unified communications.
Enterprise, universities and government organizations are using SIP and H.323 (an earlier generation IP protocol) to interconnect IP PBX islands and enable end-to-end IP communications for voice, conferencing, messaging and collaboration applications.
Compelling benefits of SIP trunking
|
|
Recognized independent experts describe the economic and other benefits that are driving adoption of SIP trunking. Interviews with Yankee Group, J Arnold Assoc., Ovum.
|
Acme Packet E-SBCs enable enterprises to leverage SIP trunks for connectivity to the PSTN and other enterprise communications equipment so the enterprise can:

- Prevent fraud and service theft, and guard against malicious attacks
- Accelerate service deployment by mitigating service interoperability issues
- Ensure high availability by rerouting sessions around equipment or facility failures
- Optimize performance by balancing loads across trunks
- Save money by implementing least cost routing across service providers
- Ensure high availability by protecting against denial of service attacks and system overloads
- Overcome multi-vendor interoperability issues
- Enable protocol interworking with legacy systems
- Ensure compliance with E911 and other regulations
- Implement unified dial plans and 4/5 digit internal dialing with rich call control functionality
- Optimize service quality by enforcing QoS and access control policies
- Improve quality by eliminating unnecessary IP-to-TDM conversions and exploiting high-fidelity codecs
Our E-SBCs are compliant with SIPconnect, a SIP Forum initiative that builds on existing IETF standards to define a method for interconnection between IP PBXs and VoIP service provider networks. SIPconnect specifies a reference architecture, required protocols and features, and implementation rules necessary for seamless IP connectivity between IP PBXs and VoIP service providers.
Enterprises are deploying SIP-based communications networks and connecting to service provider SIP trunk services for a range of applications, including:
- Voice communications—connectivity to PSTN and native IP telephony services
- Hosted services—audio and video conferencing, unified communications, contact center outsourcing, call recording
- Video communications—Interactive point-to-point or multipoint collaboration, including high definition sessions
- Business-to-business connectivity—enterprises can “federate” with suppliers and business partners to improve productivity and enhance business processes
All these applications can be converged onto a single, IP-based communications network.
ChallengesLike any new technology deployment, transitioning to a SIP-based network for voice, video and unified communications requires careful design and planning. Organizations often encounter challenges that are beyond the scope of conventional network firewalls, routers and gateways, including:
- Security—protecting communications resources and traffic from attacks, fraud, eaves-dropping and other threats
- Interoperability—connecting multi-vendor UC servers, IP-PBXs, endpoints and interfacing with SIP trunking services can be complicated by protocol incompatibilities, locally administered IP addresses and differing codecs and encryption techniques
- Reliability—handling latency-sensitive traffic with high priority and maintaining network availability and high service quality during busy periods
- Compliance—enabling emergency service routing and call recording in order to comply with government regulations
- Cost management—routing calls in cost effective manner and capturing session data for accounting, traffic management and planning
Acme Packet E-SBCs let businesses enjoy all the benefits of an end-to-end SIP network without sacrificing security, interoperability, reliability or compliance.
BenefitsOur SBCs mediate the differences in the various networks as well as provide security, quality and cost control at the ingress and egress of those networks. Our Net-Net SBCs are designed to satisfy the critical security, service reach maximization, SLA assurance, cost management and regulatory compliance requirements to enable IP trunking for enterprises. SecurityIn IP networks, critical resources can be exposed to external parties, thus elevating the risks of denial-of-service (DoS), eavesdropping and other malicious attacks. To protect critical service elements, such as IP PBXs, SIP proxies, Automatic Call Distributors (ACDs) and application servers in the network, our unique Net-SAFE security architecture helps organizations build trusted and secure borders. Our security features protect user and corporate privacy and ensure network availability.
Hardware-based packet filtering and access control |
- Prevents DoS and DDoS attacks on the SBC and enterprise core infrastructure
- Prevents unauthorized access
- Malicious sources are detected and isolated
|
Dynamic trust management |
- Classify devices or users as trusted, untrusted or malicious based on signaling behavior
- Trusted user traffic is prioritized over untrusted user traffic
|
Dynamic, signaled NAPT and back-to-back signaling |
- Deep packet inspection of signaling messages strips out confidential information
- Hides IP layer (layer 3) and signaling topologies (layer 5) from attack
- Allows architectural and topology changes in the core without affecting interfaces from external parties
|
Encryption (TLS, IPsec, SRTP) |
- Protects user privacy
- Increases scalability by aggregating encrypted connections and offloading processing from the core
|
Programmable header manipulation |
- Removes confidential signaling information
- Signature matching for intrusion detection and virus/worm/malware scanning
|
Signaling rate limiting |
- Prevents overload of IP PBX, SIP proxy and other signaling elements
|
LDAP interface for employee authentication and authorization |
- Prevents fraud
- Reduces cost by leveraging existing database
|
VPN separation |
- Secure separation of enterprise traffic to different service providers or on internal network
|
Intrusion detection protection and reporting |
- Provides protection against and awareness of unknown security threats and suspicious behavior
- Monitors potential security breaches while limiting false positives
|
Per-session media bandwidth policing |
- Prevents media-based DoS attacks
- Prevents bandwidth theft
| Service reach maximizationAll IP networks are not the same. They use different signaling, encryption or transport protocols, codecs or overlapping IP address spaces and dial plans. To allow calls to cross from one VoIP network to another, our Net-Net SBCs mediate between heterogeneous networks and maximize the reach of applications, allowing organizations to increase their addressable user base and accelerate deployments.
Multiservice architecture with application virtualization |
- Partition and dedicate resources to specific applications
- Reduces the number of network elements
- Allows for unique application profiles and signaling options
- Fine-grained traffic, security and QoS controls
|
Interworking signaling (SIP, H.323), encryption (TLS, IPsec) and transport (TCP, UDP, SCTP) protocols |
- Maximizes number of networks for interconnection
- Eliminates need to change service core
- Freedom to make changes in core network and mediate differences at ingress and egress
|
Protocol normalization and repair including programmable header manipulation |
- Increased vendor interoperability
- Accelerated time-to-market
|
SIPconnect compliance |
- Eliminates need for IP PBX or SIP proxy compliance
- Ensures service provider interoperability
|
Number normalization and response code translations |
- Allows heterogeneous networks to interconnect without changing core elements
|
Overlapping IP address domain mediation and VPN bridging |
- Directly interface to multiple VPNs to minimize equipment costs
- Supports connections to external networks using overlapping private address space
- Secure separation and bridging of traffic
- Speeds integration of merged entities
|
Transcoding and filtering of fixed line and mobile codecs |
- Increases service reach through codec normalization
- Optimize network resources
| SLA assuranceWith growing VoIP call volumes, interconnecting enterprise PBXs to service provider VoIP networks can lead to oversubscribed and burdened networks that impact users. Our Net-Net SBCs provide call admission control, load balancing and QoS marketing and reporting features that deliver assured service quality and network availability during abnormal busy periods or network events.
Flexible call admission control: policies defined by session agent constraints, bandwidth and QoS metrics |
- Prevents network overload
- Increases network availability
|
Session agent load balancing |
- Ensures uptime and availability during peak call times
|
QoS marking (ToS, DiffServ, MPLS) |
- Enables priority treatment of VoIP traffic
|
QoS reporting (jitter, delay, packet loss, MOS) |
- Determines quality of session from a media perspective
- Provides data for SLA reporting
- Aides network optimization
- Accelerates identification and resolution of problems
|
Answer Seizure Ratio (ASR) reporting |
- Determines quality of session from signaling perspective
- Provides data for SLA reporting
- Speeds time to identify and isolate problems for resolution and network optimization
| Regulatory compliancePublic safety and law enforcement regulations for traditional phone networks are being applied to VoIP networks around the world. Our Net-Net SBCs deliver call routing and replication features and interfaces for regulatory compliance for IP interactive communications.
Emergency session identification and breakout routing and admission control exemption |
- Enables priority treatment for emergency sessions
|
Call recording interfaces for external provisioning and post call processing systemsx |
- Facilitates selective or complete capture of call information, eliminating the need for additional components, reducing costs and complexity
- Reduces the number of devices for call recording, eliminating costs and decreasing complexity
| Cost managementVoIP and other IP interactive communication services are designed to reduce expenses for enterprises. Yet inefficient network utilization and fraud can ruin the intended cash flow benefits. Our Net-Net SBCs deliver call routing, bandwidth policing and accounting features to help ensure the most cost-effective usage of an organization’s network, and the use of ENUM can reduce costs by keeping calls and transfers on-net via SIP trunking.
Flexible routing policies: least cost routing, ASR-based, codec-based, etc. |
- Enables cost-effective PSTN termination
- Enables traffic grooming and optimizes call routing
- Unifies dial plans across IP PBXs and sites
|
ENUM (electronic numbering) |
- E.164 phone number routing decisions based on external ENUM database
- Enables VoIP calls to remain IP end-to-end, avoiding costly and unnecessary PSTN termination and call degradation due to media conversion
|
Bandwidth policing |
- Protects against bandwidth theft
|
Accounting via call detail records (CDRs) or RADIUS |
- Supports traffic planning and performance management
- Fraud prevention
|
Session timers |
- Prevents fraudulent and stranded calls
- Enables audit trails for fraud detection
|
|