SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Information Architecture >> Identity Management

Doing VoIP the right way

Doing VoIP the right way

By:  Leon Erlanger  On: 02 Mar 2006 For: Network World Canada Creator

With the huge number of potential threats and vulnerabilities, will VoIP users soon find themselves plagued by service interruptions and eavesdropping? To date, there have been no devastating, widely publicized attacks on enterprise VoIP systems. Why? Vendors and analysts offer several valid reasons

With the huge number of potential threats and vulnerabilities, will VoIP users soon find themselves plagued by service interruptions and eavesdropping? To date, there have been no devastating, widely publicized attacks on enterprise VoIP systems. Why? Vendors and analysts offer several valid reasons.

Most newer enterprise VoIP solutions are closed systems in which packetized voice is running across the LAN only, and most external traffic is running across the PSTN via a gateway. “If you’re running VoIP on the LAN only, it’s relatively easy to get toll quality and maintain security,” says David Fraley, director of Federal Practice at Gartner. Interoffice traffic is normally running on a protected office-to-office connection, so in many cases securing internal VoIP means hardening your call servers, switches and gateways and protecting them with the right kinds of firewalls and IPS.

Vendors also recommend separating voice from data traffic on the LAN to protect it from malware, eavesdropping, and DoS attacks. Building a separate infrastructure for voice negates the cost benefits of VoIP. However, much of the same kind of protection comes with the 802.1Q features of your switches to put voice and data on separate VLANs, and protecting the intersection points between voice and data VLANs, such as the messaging server, with a voice-aware firewall and/or an IPS.

In fact, VoIP vendors and security experts say it’s best to avoid softphones — phone software that runs on a PC — in favour of IP telephony handsets because softphones make it almost impossible to separate voice from data. Assigning an IP handset’s IP address to its MAC (media access control) address is a good way to help thwart IP address spoofing. Several solutions use digital certificates for device and server authentication, and you can require passwords or PINs to access handsets. Key is encrypting voice-signaling data, VoIP management interactions and, in high security environments, even voice streams.

Challenges ahead

These arguments make a lot of sense today, but what about tomorrow? “At the end of the day, enterprises want to use VoIP to capitalize on international call cost-savings,” says Andrew Graydon, vice-president of technology at BorderWare Technologies. That means replacing PRIs and other PSTN trunking with VoIP trunks in order to route calls to a gateway closer to your international call destination. “As soon as the enterprise opens up VoIP to the Internet, it puts a potentially huge security hole in the network,” Graydon says. Essentially the days of closed corporate VoIP systems are over. He also points out that telcos are changing their internal infrastructure from PSTN over copper to IP over fiber to cut their own costs, and moving to IP-based peering connections with other providers.

Mark Collier, CEO of SecureLogix, agrees. “Once MCI gets 1,000 customers on their VoIP network it will be considerably more difficult to control security threats,” he says.


Sign up for our Newsletters












Print |  Views: 608   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Leon Erlanger Leon Erlanger is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.