... and I never put a sip server interface directly on the internet.

If I have that much infrastructure I need to connect to I'd get a commercial
SBC or firewall that is SIP capable to do that, so I can truly protect it
and manage it.

Exposing a PBX to every nook and cranny of a network with multiple
interfaces creates a management and security task for something that should
obviously be in place that is designed to do just that.

That being said, I think you will see things discussed on how/why to
implement multiple network cards in 'post 4.4', and would encourage you to
take part in that discussion.

Let's all keep sight of the fact that sipx is, at the core, a replacement
for the corporate PBX. It is NOT a security device. While support for TLS is
being built in, and the fact that it requires authorization for placing
outbound calls, in no way makes it more or less secure as the OS you run it
on. I've seen linux servers get rootkits, with a whole lot of security and
tools to prevent those ickies implemented on them. Firewalls are not a bad
idea, no, wait, they are an awesome idea.

On Thu, Oct 28, 2010 at 7:22 AM, Michael Picher <[email protected]> wrote:

> I can see the usefulness of that...
>
> If I were going to that level I guess I'd just use a firewall to control
> access to SSH and also to block any unneeded ports.
>
> Hopefully we'll get at that point in version 5.0.  Again, you're not the
> first to ask for it, but usually somebody wants to stick one leg of the
> server on the internet to avoid NAT...
>
> Mike
>
>
> On Thu, Oct 28, 2010 at 5:55 AM, Abdul Mayat <[email protected]>wrote:
>
>>
>> Content-Type: text/plain;
>>  charset="utf-8"
>> Content-Transfer-Encoding: 8bit
>> Organization: SipXecs Forum
>> In-Reply-To: <AANLkTimRWx5+i0YDNUQyyvkq18o3J=_
>> [email protected]>
>> X-FUDforum: 08063afcdd00a6e76393c5b9527381e8 <53807>
>> Message-ID: <[email protected]>
>>
>>
>>
>> Hi Michael,
>>
>> Its not a requirement driven by throughput or resiliency...
>>
>> Its a common setup in enterprise environments for servers to
>> be connected to a private network for management and admin
>> (backups, updates, monitoring etc) and then have servers
>> connected to a separate public or private network for
>> applications.
>>
>> Maybe one of the redhat guy's can confirm this?
>>
>> Seems like we should have a config setting in the
>> application to allow the admin to explicitly set the IP
>> address of the box...which in fact we do with the initial
>> setup script, so still not sure why the application would
>> bind to the wrong address...
>>
>> If there is enough interest, maybe I'll give this a try and
>> report back what breaks...!
>>
>> Abdul
>>
>>
>>
>> _______________________________________________
>> sipx-users mailing list
>> [email protected]
>> List Archive: http://list.sipfoundry.org/archive/sipx-users/
>>
>
>
>
> --
> There are 10 kinds of people in this world, those who understand binary and
> those who don't.
>
> [email protected]
> blog: http://www.sipxecs.info
> call: sip:[email protected] <sip%[email protected]>
>
> _______________________________________________
> sipx-users mailing list
> [email protected]
> List Archive: http://list.sipfoundry.org/archive/sipx-users/
>



-- 
======================
Tony Graziano, Manager
Telephone: 434.984.8430
sip: [email protected]
Fax: 434.326.5325

Email: [email protected]

LAN/Telephony/Security and Control Systems Helpdesk:
Telephone: 434.984.8426
sip: [email protected]

Helpdesk Contract Customers:
http://support.myitdepartment.net
_______________________________________________
sipx-users mailing list
[email protected]
List Archive: http://list.sipfoundry.org/archive/sipx-users/

Reply via email to