Snom 4S NAT Filter Manuel utilisateur

snom 4S NAT Filter
Admin Manual
snom 4S
NAT Filter
Version 2.09

snom technology AG • 3
snom 4S NAT Filter Version 2.09
© 2004 snom technology Aktiengesellschaft. All Rights Reserved.
This document is supplied by snom technology AG for information purposes only to licensed
users of the snom 4S NAT lter and is supplied on an “AS IS” basis, that is, without any
warranties whatsoever, express or implied.
Information in this document is subject to change without notice and does not represent any
commitment on the part of snom technology AG. The software described in this document
is furnished under a license agreement and may be used only in accordance with the terms
of that license agreement. It is against the law to copy or use this software except as
specically allowed in the license. No part of this document may be reproduced, republished
or retransmitted in any form or by any means whatsoever, whether electronically or
mechanically, including, but not limited to, by way of photocopying, recording, information
recording or through retrieval systems, without the express written permission of snom
technology AG.
Legal Disclaimer
snom offers the software described in this manual for both open source operating systems
as well as licensed operating systems. Whenever software that has been used under GPL
or LGPL licensing conditions has been used by this product you can download the sources
from http://www.snom.com/downlad/gpl/snom_ossdk or purchase a disc from snom for a
nominal fee under the ordering code snom SDK CD.

snom technology AG • 3
Table of Contents
1 Overview ..........................................................5
1.1 Applications ...................................................................... 6
1.2 Features ........................................................................... 6
2 Architecture .....................................................9
2.1 The NAT Filter and SIP........................................................ 9
2.2 NAT ............................................................................... 10
2.2.1 How does NAT work?..............................................................................................................................................11
2.2.2 Symmetrical RTP............................................................................................................................................................11
2.2.3 Signalling SIP.......................................................................................................................................................................11
2.2.4 Media RTP...................................................................................................................................................................................12
2.2.5 Classication of User Agents....................................................................................................................12
2.2.6 Probing Media Paths.................................................................................................................................................13
2.2.7 The Role of the NAT Filter..............................................................................................................................13
2.2.8 Optimizing the Media Path for Symmetrical NAT..................................................14
2.3 Filter Behaviour ............................................................... 15
2.3.1 Registering without UA Support..........................................................................................................15
2.3.2 Registering with UA Support.....................................................................................................................16
2.3.3 RTP Relay....................................................................................................................................................................................18
2.4 Scaling and Redundancy ................................................... 20
2.5 Detecting the right NAT Filter ............................................ 21
2.6 Requirements on User Agents............................................ 21
2.6.1 Non NAT-Aware User Agents.....................................................................................................................22
2.6.2 STUN/ICE-Aware User Agents................................................................................................................22
2.7 Dening the Maximum Session Time .................................. 22
3 Installation.....................................................23
3.1 Windows......................................................................... 23
3.2 Linux ............................................................................. 28
4 Conguration..................................................31
4.1 Logging In ...................................................................... 31
4.2 Port Binding .................................................................... 31
4.3 System Settings .............................................................. 33
4.3.1 Logging...........................................................................................................................................................................................33
4.3.2 Preparing Recovery ...................................................................................................................................................34

4 • Contents
[ S N O M 4S NAT FI L T E R ]
snom technology AG • 5
4.3.3 General Outound Proxy......................................................................................................................................34
4.3.4 Media Ports ..............................................................................................................................................................................34
4.3.5 Media Relay.............................................................................................................................................................................35
4.3.6 Controlling Routing ....................................................................................................................................................35
4.3.7 Multiple 2xx Handling............................................................................................................................................36
4.3.8 Trusted Addresses.......................................................................................................................................................36
4.3.9 Maximum Packet Size...........................................................................................................................................37
4.3.10 Silence Suppression.................................................................................................................................................37
4.3.11 Connection Oriented Media.........................................................................................................................37
4.3.12 Removing Headers......................................................................................................................................................38
4.3.13 Codec Control......................................................................................................................................................................38
4.3.14 Web Server Integration......................................................................................................................................38
4.4 Timeout Settings ............................................................. 40
4.4.1 Register Timeouts........................................................................................................................................................41
4.4.2 Call Timeouts........................................................................................................................................................................42
4.5 Security Settings ............................................................. 43
4.6 Outbound Proxy List......................................................... 45
4.7 System Information ......................................................... 46
4.8 Server Log...................................................................... 46
4.9 Trace.............................................................................. 47
4.10 Call History ..................................................................... 48
4.11 Current Ports .................................................................. 49
4.12 Currently Handled UA ....................................................... 50
4.13 Memory Statistics ............................................................ 50
5 Checklist for Installation ................................51
5.1 Linux ............................................................................. 51
5.2 Windows......................................................................... 51

4 • Contents
[ S N O M 4S NAT FI L T E R ]
snom technology AG • 5
1 Overview
Network address translation (NAT) is a reality today. There
have been many discussions about the evil and the good of this network
topology and the replacement by IP version 6. However, operators and
business that want to offer VoIP services today and they must address
the problem.
The snom 4S NAT Filter enables non-NAT aware devices to
operate in private networks. The lter operates typically on a public IP
address. Non-NAT aware devices are automatically refreshed; NAT-aware
devices that operate behind symmetrical NAT may self-refresh their
bindings using the built-in STUN server of the lter, which is operating
on the same address as the SIP application. Devices on public Internet
traverse the lter without changes or refreshes. By supporting Interactive
Communications Establishment (ICE), the number of calls that must go
through the lter can be minimized.
The product also offers recording capabilities (depending on
the licensing). Through a separate management interface, operators
can dene numbers and patterns that are silently recorded. Users may
explicitly request the recording of a call by pressing a key on the phone,
in this case the whole call will be recorded (even parts of the call before
pressing the key). The lter records in a compressed format where only
the voice part of the conversation is recorded in highly-compressed audio
format (13.2 kBit/s). By using the snom 4S recording studio, operators
can manage very large numbers of calls and for example forward them
per Email to the users or authorities.
The snom 4S NAT Filter is a session border controller. However,
we do not like the term “session border”, because the program does
not control sessions nor is it on the border of a call. It does also not
translate signalling, e.g. from SIP to H.323 or to MGCP. If all user agents
are fully NAT-compliant or on public Internet, the lter can transparently
be removed from the network without changing of the call ows or
functionality. Also, the lter does not interfere with unknown applications.
This is tremendous advantage against session borders controllers that
operate on the application level.
1.

6 • Overview
[ S N O M 4S NAT FI L T E R ]
snom technology AG • 7
[ S N O M 4S NAT FI L T E R ]
1.1 Applications
The lter can be used in the following scenarios:
• Corporations. Corporations which operate their infrastructure be-
hind NAT and/or rewalls can talk to the public Internet through the
lter.
• Operators. Operators offer the NAT traversal feature to their cus-
tomers. Using the scalability feature of the lter, the operation of
large networks becomes possible.
• Record specic calls for legal purposes. In many countries, opera-
tors must provide the possibility to record certain calls on request.
The lter can perform this task.
• Recording can be used for legal proong (brokers, etc). The lter is
fully compliant with other SIP equipment and can for example put
between a PSTN gateway and SIP phones.
1.2 Features
The lter offers powerful features based on modern VoIP
technology:
• The built-in RFC3261-compliant SIP proxy makes additional exter-
nal SIP logic superuous and simplies the system setup.
• A built-in RFC3489-compatible STUN server for single IP addresses
allows client to self-refresh their bindings
• Support for instant messaging, presence and all other SIP-compli-
ant applications.
• Rich logging features allow easy maintenance.
• Recording functions based on number lists and expressions offer a
exible way of ltering out information.
• Recordings can be saved in WAV le format (the data rate is 6 MB
per hour).
• Almost stateless operation allows the lter to be used in server
farms. This offers a tremendous scalability and redundancy making
the product suitable for large operators.
1.

6 • Overview
[ S N O M 4S NAT FI L T E R ]
snom technology AG • 7
[ S N O M 4S NAT FI L T E R ]
• Both http and https as web interface for simple access from
anywhere on the Internet.
• The lter supports Interactive Connectivity Establishment (ICE).
User agents that support this feature will optimize the media path
for the shortest possible delay.
• Media relay is established using connection-oriented media. User-
agents that are not NAT-aware inherently support this feature. This
makes the operation of the NAT lter backward compatible.
• User-Agents may self-refresh their bindings. With this feature,
bindings can be kept alive even when IP addresses are changed
dynamically and when the user agent is temporarily available from
the outside.
• Call-alive polling. During calls, the lter checks if the call is still
alive and terminates the call if this should not be the case. With this
feature, charging users for broken calls can be avoided.
• Reliable and unreliable transport layers. The lter supports both
UDP and TCP transport layers. Full TLS support will be added soon.
• To- and From-Headers may be changed for calls. The lter talks to a
web application server to get this information.
• Simple request-routing feature. The web application server can
also change the request-URI. This makes simple routing possible,
which can be used e.g. for least cost routing.sually, the lter acts as
stateless proxy. That means, by default it just forwards the packets
and does not change the content of the attachments or the headers
themselves. That means, the lter will not interfere with applications
(instant messaging, presence, weather report, etc).
There are three exceptions to this rule:
• The rst exception is a REGISTER request. When a user agent tries
to register and needs the support of the lter, the lter will set up
a local data structure representing the user agents. It will make
sure that the connection to the user agents stays alive. It will also
make sure that requests that are destined to the user agents will be
forwarded properly.
• The second exception is a SDP attachment. The lter checks if the
user agent needs support (or must be recorded) and will in that case
add a local contact to the SDP that can be used for media relay.
1.

8 • Overview
[ S N O M 4S NAT FI L T E R ]
snom technology AG • 9
• The third exception occurs when the lter queries a web server for
routing information. In this case, it will send a provisional response
to stop the UAC from repeating messages.
These three exceptions make sure that all user agents will work
behind NAT, no matter what NAT-type or how many NAT-levels are being
used. If user agents support ICE, they will automatically nd the shortest
media path to the other party (peer-to-peer).
Also, please make sure that you have the necessary administrator
rights to run Windows services.
1.

8 • Overview
[ S N O M 4S NAT FI L T E R ]
snom technology AG • 9
2 Architecture
2.1 The NAT Filter and SIP
In the SIP architecture, the lter acts as the rst proxy that is
contacted by user agents. There are two ways to make sure that the
relevant trafc gets routed trough the lter:
• User agents can be set up to use the lter as outbound proxy. When
using this method, all SIP trafc will ow through the lter, weather
it is destined to the operator or not. That means that also service for
calls outside of the operator’s domain may be serviced by the lter.
However, by redirecting all outgoing trafc of the lter to a proxy
the operator can make sure that the authentication, authorization
and accounting (AAA) requirements for requiring the service are
fullled.
• User agents resolve the lter though the RFC3263 DNS resolving
process. That means that only the trafc that is destined to the
operator’s domain will use the service of the NAT Filter. However,
users might be annoyed if they place a call to a domain that does
not properly support NAT services. In this case, the lter can also
redirect the trafc to another proxy for AAA.
We recommend using the rst alternative and only choose the
second alternative if it is too difcult to provision the user agents with the
outbound proxy or there are concerns about providing service for foreign
operators.
Usually, the lter acts as stateless proxy. That means, by default
it just forwards the packets and does not change the content of the
attachments or the headers themselves. That means, the lter will not
interfere with applications (instant messaging, presence, weather report,
etc).
There are three exceptions to this rule:
• The rst exception is a REGISTER request. When a user agent tries
2.

10 • Architecture
[ S N O M 4S NAT FI L T E R ]
snom technology AG • 11
[ S N O M 4S NAT FI L T E R ]
to register and needs the support of the lter, the lter will set up
a local data structure representing the user agents. It will make
sure that the connection to the user agents stays alive. It will also
make sure that requests that are destined to the user agents will be
forwarded properly.
• The second exception is a SDP attachment. The lter checks if the
user agent needs support (or must be recorded) and will in that case
add a local contact to the SDP that can be used for media relay.
• The third exception occurs when the lter queries a web server for
routing information. In this case, it will send a provisional response
to stop the UAC from repeating messages.
These three exceptions make sure that all user agents will work
behind NAT, no matter what NAT-type or how many NAT-levels are being
used. If user agents support ICE, they will automatically nd the shortest
media path to the other party (peer-to-peer).
2.2 NAT
Network Address Translation (NAT) is a reality in today’s networks.
Many operators save IP addresses by providing only one IP address for a
number of devices, sometimes companies. Firewall manufacturers make
NAT a feature by performing inspection of packets that go though NAT.
Even for IPv6 networks, the fundamental problem will remain as there will
also be a need for rewalls and private networks.
The Session Initiation Protocol (SIP) has neglected this problem
in the beginning. However, in some recent RFC there have been useful
proposals how to deal with the problem. This document shows how the
snom 4S lter can be used to solve the problems.
Although snom also makes user agents, the snom 4S lter works
with most SIP user agents from other companies. The requirements on
these user agents are described below.
If you want to use the lter just for recording purposes, you don’t
need to bother about NAT. The lter also works when no NAT is present.
2.
Autres manuels pour 4S NAT Filter
4
Table des matières
Autres manuels Snom VoIP






















