SIP support
The FortiGate unit and VoIP security
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
429
•
The FortiGate unit and VoIP security
Like data networks, VoIP networks are vulnerable to many of the same security risks,
including denial of service (DoS) attacks, service theft, tampering, and fraud. Many
conventional firewalls cannot protect VoIP networks from attacks because VoIP is
implemented at both the signaling and media layers. VoIP calls cannot go through these
firewalls unless a range of ports are opened – which exposes the network for
unauthorized access.
The FortiGate unit can effectively secure VoIP solutions since it supports VoIP protocols
such as SIP, MGCP, and H.323, and associates state at the signaling layer with packet
flows at the media layer. Using SIP ALG controls, the FortiGate unit can interpret the VoIP
signaling protocols used in the network and dynamically open and close ports (pinholes)
for each specific VoIP call to maintain security.
The FortiGate intrusion prevention system (IPS) provides another strategic line of
defense, particularly against VoIP network predators. The IPS has deep-packet inspection
capabilities to provide continuous surveillance across multiple network sectors
simultaneously, recognizing network traffic expected within each and alerting network
managers to malicious packets and other protocol anomalies.
SIP NAT
The FortiGate unit supports network address translation (NAT) of SIP because the
FortiGate ALG can modify the SIP headers correctly.
This section uses scenarios to explain the FortiGate SIP NAT support.
Source NAT (SIP and RTP)
In the source NAT scenario shown in
, a SIP phone connects to the Internet
through a FortiGate unit with PPPoE. The FortiGate ALG translates all private IPs in the
SIP contact header into public IPs.
You need to configure an internal to external UDP firewall policy with NAT checked and a
SIP-enabled protection profile. For more information about firewall policies, see
.
Figure 272: SIP source NAT
10.72.0.57
SIP Server
Internet
217.233.122.132
RTP Server
217.10.79.9
217.10.69.11
SIP service provider has a SIP server
and a separate RTP server
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...