Border Gateway - Application Specification
The Newport Networks Border Gateway (BG) application provides media control at IP to IP interconnect, peering, and access locations. The Border Gateway application can be hosted on any of Newport Networks platforms (See separate data sheets for platform details). The Border Gateway can be controlled by a Newport Networks Border Controller or may be controlled directly by third party SoftSwitch using an H.248 ia profile interface. Key capabilities provided by the BG are:
- The ability for SIP and H.323 controlled media to traverse corporate, consumer and core network NAPT and firewall devices.
- Quality of Service enforcement using media session policing to prevent users from exceeding their negotiated session bandwidth.
- Border media security protecting the core network, customers, and service revenue.
- Regulatory compliance providing Lawful Intercept of media.
The BG can offer from capacities of under 1,000 concurrent calls to 160,000 concurrent calls per chassis depending upon the hosting platform.
See Release 5.x specifications.
Security
Network Address and Port Translation (NAPT) provides media topology hiding and ensures connectivity to networks that use private or un-routable addressing schemes. Randomized port allocation prevents malicious media access through port scanning attacks. Policing of RTCP as well as RTP streams is performed to ensure that users only pass traffic in their RTP stream.
Quality of Service
Media Policing prevents fraudulent or faulty sessions from exceeding agreed bandwidths, protecting the QoS of other clients. Media policing is performed per media flow within a session. The policing policy is passed to the BG via the H.248 link on call setup.
DiffServ Code Point (DSCP) re-marking enables media flow differentiation based on a quality policy to be enforced on a per-user and per-session basis
Carrier Grade
Multiple instances of the BG application may be deployed within a chassis in non redundant or redundant configuration.
In redundant mode the BG is deployed on active/stand by processor pairs. Failure of one processor or application results in the hot stand by taking over with no loss of data.
The BG application supports physical link aggregation (802.3-2002) providing link resilience and load balancing. In addition, the LAGs themselves can be resilient. This provides additional protection against network outages by routing traffic via alternative LAGs if the primary LAG or hosting network equipment fails. This provides optimal network resilience with the flexibility to adapt to individual network supported scenarios.
The BG supports the secure traversal of corporate and network based firewalls and NAT devices, without deploying additional customer premise equipment or replacing existing firewalls and NAT devices.
Regulatory
The BG application acts as part of a Lawful Intercept solution providing media intercept. When used in conjunction with a Newport Networks Border Controller, a turnkey Lawful Intercept solution can be provided intercepting all required signalling and media paths and providing Handover Interfaces that are fully compliant with local regulatory requirements.
Standards
The Newport Networks BG complies with the architectural requirements of the 3GPP IMS and ETSI TISPAN standards. At the subscriber edge of the core network, the BG provides the TISPAN Access to Core Border Gateway Function (A/C-BGF) capabilities. At interconnect points, the BG provides the TISPAN Interconnect Border Gateway Function (I-BGF).
IPv6 support has been added to the Border Gateway to enable support of IPv6 media and also interworking between IPv4 and IPv6 media connections. This will allow interworking of applications between traditional IP networks and the latest architectures supporting IPv6 addressing, such as some wireless access networks and will give operators a greater reach for their services.
Key Features
Security
- Access Control including signalling control of media pinhole firewall (using Newport Networks BC or 3rd party Softswitch)
- Network topology hiding using NAPT at layer 3 and 5
- Customer address hiding - Route stripping
- DoS protection
- Policing of RTP and RTCP on a per-session basis
Quality of Service
- Policing on per-session basis
- Re-mapping of ToS bits and DiffServ codepoints based on:
- SIP quality parameter
- Media type and codec in signalling
- Static mapping table
Carrier Grade Resilience
- Application can run in active /hot standby mode
- Link aggregation (802.3-2002) for resilience and load balancing
Regulatory
- Turnkey Lawful Intercept solution when used in conjunction with Border Controller
- Lawful Interception compliant to (CALEA and ETSI). National variants supported include, but are not limited to: USA, Canada, UK, Germany and Italy
Connectivity
- Layer 2 VLAN tagging (802.1q and 802.1p)
- Optional external control from Call Agents/Softswitches using the H.248 protocol (ia profile)
Management
- Operational configuration and monitoring using a web-based Graphical User Interface (GUI)
- Full configuration and monitoring using an advanced CLU
- Alarm and Trap element management using SNMPv3
- Full ICMP support
Call Processing
- Up to 50,000 concurrent calls per CPU
- Up to 70 calls per second per CPU
IETF MIDCOM Compliance
- Fully compatible with the MIDCOM architecture
3GPP & ETSI TISPAN Compliance
- C-BGF (Core Border Gateway Function) capabilities
- I-BGF (Interconnect Border Gateway Function) capabilities
Signalling Compliance
- H.248v3
- ETSI TISPAN ES 283 018 (Ia profile)
Transport Compliance
- RFC 791 - Internet Protocol
- RFC 768 - User Datagram Protocol
- RFC 793 - Transmission Control Protocol
|