Application Layer Gateway for SIP Protocol
-
RFC 3261
-
RFC 3581
-
RFC 4566
-
RFC 4475
How SIP ALG Works
-
Inbound request
-
Outbound response
-
Outbound request
-
Inbound response
-
LSN pool IP address and port on behalf of the private client, so that the messages that arrive at this IP address and port from the public network are treated as SIP messages.
-
Public IP address and port on behalf of the public clients, so that the messages that arrive at this IP address and port from the private network are treated as SIP messages.
-
Via
-
Contact
-
Route
-
Record-Route
INVITE adam@10.102.185.156 SIP/2.0 Via: SIP/2.0/UDP 192.170.1.161:62914 From: eve@10.120.210.3 To: adam@10.102.185.156 Call-ID: a12abcde@10.120.210.3 Contact: adam@10.102.185.156 Route: <sip:netscreen@10.150.20.3:5060> Record-Route: <sip:netscreen@10.150.20.3:5060>
-
c= (connection information)This field can appear at the session or media level. It appears in the following format:c=
<network-type><address-type><connection-address>If the destination IP address is a unicast IP address, the SIP ALG creates pinholes by using the IP address and port numbers specified in the m= field. -
m= (media announcement)This field appears at the media level and contains the description of the media. It appears in the following format:m=
<media><port><transport><fmt list> -
a=
(information about the media field)This field can appear at the session or media level, in the following format:a=<attribute>a=<attribute>:<value>
| Inbound Request (from public to private) | To | None |
| From | None | |
| Call-ID | None | |
| Via | None | |
| Request-URI | Replace LSN pool IP address with private IP address | |
| Contact | None | |
| Record-Route | None | |
| Route | None | |
| Outbound Response (from private to public) | To | None |
| From | None | |
| Call-ID | None | |
| Via | None | |
| Request-URI | Replace private IP address with LSN pool IP address | |
| Contact | Replace private IP address with LSN pool IP address | |
| Record-Route | None | |
| Route | None | |
| Outbound Request (from private to public) | To | None |
| From | None | |
| Call-ID | None | |
| Via | Replace private IP address with LSN pool IP address | |
| Request-URI | None | |
| Contact | Replace private IP address with LSN pool IP address | |
| Record-Route | None | |
| Route | None | |
| Inbound Response (from public to private) | To | None |
| From | None | |
| Call-ID | None | |
| Via | Replace LSN pool IP address with private IP address | |
| Request-URI | None | |
| Contact | Retain public IP address, if present | |
| Record-Route | None | |
| Route | None |
Limitations of SIP ALG
-
Only SDP payload is supported.
-
The following are not supported:
-
Multicast IP addresses
-
Encrypted SDP
-
SIP TLS
-
FQDN translation
-
SIP layer authentication
-
TD/partitioning
-
Multipart body
-
SIP messages over IPv6 network
-
Line folding
-
Tested SIP Clients and Proxy Servers
-
SIP Clients: X-Lite, Zoiper, Ekiga. Avaya
-
Proxy Server: openSIPS
LSN SIP Scenario: SIP Proxy Outside the Private Network (Public Network)
SIP Client Registration
Outgoing Calls
Incoming Calls
Call Termination
Call Between Clients in the Same Network
More LSN SIP Scenarios: SIP Proxy Inside the Private Network
-
Configure a static LSN Mapping for the private SIP proxy. For more information, see Configuring Static LSN Maps. Make sure that the NAT port is the same as the port configured in the SIP ALG profile.
-
Configure the SIP Proxy server inside a demilitarized zone (DMZ).
-
Scenario 1—SIP client in the private network registers with the SIP proxy server in the same network. ALG operations are not performed, because the SIP client and SIP proxy server are in the same network.
-
Scenario 2—SIP client in the public network registers with the SIP proxy server in the private network. The REGISTER message from the public SIP client is sent to the NetScaler appliance by using the static LSN mapping configured on the appliance, and the appliance creates a pinhole for further SIP operations.
-
Scenario 3— SIP Incoming call flow. A SIP incoming call is initiated with a SIP INVITE message from the external to the internal network. The NetScaler appliance receives the INVITE message from SIP client C2, which is in the external network, through the static LSN maps configured on the NetScaler appliance.The appliance creates a pinhole and forwards the INVITE message to the SIP proxy. The SIP proxy then forwards the INVITE message to SIP client C1 in the internal network. SIP client C1 then sends 180 and 200 OK messages to the SIP proxy, which in turn forwards the message to SIP client C2 through the NetScaler appliance. When the 200 OK response message sent by internal SIP client C1 arrives at the NetScaler, the SIP ALG performs NAT on the IP addresses and port numbers in the Via, Contact, Route, and Record-Route SIP header fields, and in the SDP fields, replacing them with the LSN pool IP address and port number. The SIP ALG then forwards the response message to SIP client C2 and opens a pinhole in the outbound direction for further SIP communication.
Support for Audit Logs
-
Time stamp
-
Type of SIP message (for example, SIP request)
-
Source IP address and port of the SIP client
-
Destination IP address and port of the SIP proxy
-
NAT IP address and port
-
SIP method
-
Sequence number
-
Whether or not the SIP client is registered
-
Caller’s user name and domain
-
Receiver’s user name and domain
07/19/2013:09:49:19 GMT Informational 0-PPE-0 : default ALG ALG_SIP_INFO_PACKET_EVENT 169 0 : Infomsg: "SIP request" - Group: g2 - Call_ID: NTY0YjYwMTJmYjNhNDU5ZjlhMmQxOTM5ZTE3Zjc3NjM. - Transport: TCP - Source_IP: 192.169.1.165 - Source_port: 57952 - Destination_IP: 10.102.185.156 - Destination_port: 5060 - Natted_IP: 10.102.185.191 - Natted_port: 10313 - Method: REGISTER - Sequence_Number: 3060 - Register: YES - Content_Type: - Caller_user_name: 156_pvt_1 - Callee_user_name: 156_pvt_1 - Caller_domain_name: - Callee_domain_name: -
07/19/2013:09:49:19 GMT Informational 0-PPE-0 : default ALG ALG_SIP_INFO_PACKET_EVENT 170 0 : Infomsg: "SIP response" - Group: g2 - Call_ID: NTY0YjYwMTJmYjNhNDU5ZjlhMmQxOTM5ZTE3Zjc3NjM. - Transport: TCP - Response_code 200 - Source_IP: 10.102.185.156 - Source_port: 5060 - Destination_IP: 192.169.1.165 - Destination_port: 57952 - Natted_IP: 10.102.185.191 - Natted_port: 10313 - Sequence_Number: 3060 - Content_Type: - Caller_user_name: 156_pvt_1 - Callee_user_name: 156_pvt_1 - Caller_domain_name: - Callee_domain_name: -
Configuring SIP ALG
-
Set the following parameters while adding the LSN application profile:
-
IP Pooling = PAIRED
-
Address and Port Mapping = ENDPOINT-INDEPENDENT
-
Filtering = ENDPOINT-INDEPENDENT
-
add lsn appsprofile app_tcp TCP -ippooling PAIRED -mapping ENDPOINT-INDEPENDENT -filtering ENDPOINT-INDEPENDENT
-
Create a SIP ALG profile and make sure that you define either the source port range or destination port range.
add lsn sipalgprofile sipalgprofile_tcp -sipsrcportrange 1-65535 -sipdstportrange 5060 -openViaPinhole ENABLED -openRecordRoutePinhole ENABLED –sipTransportProtocol TCP
-
Set SIP ALG = ENABLED, while creating the LSN group.
add lsn group g1 -clientname c1 -sipalg ENABLED
-
Bind the SIP ALG profile to the LSN group.
add lsn pool p1
Done
bind lsn pool p1 10.102.185.190
Done
add lsn client c1
Done
bind lsn client c1 -network 192.170.1.0 -netmask 255.255.255.0
Done
add lsn appsprofile app_tcp TCP -ippooling PAIRED -mapping ENDPOINT-INDEPENDENT -filtering ENDPOINT-INDEPENDENT
Done
add lsn appsprofile app_udp UDP -ippooling PAIRED -mapping ENDPOINT-INDEPENDENT -filtering ENDPOINT-INDEPENDENT
Done
bind lsn appsprofile app_tcp 1-65535
Done
bind lsn appsprofile app_udp 1-65535
Done
add lsn sipalgprofile sipalgprofile_tcp -sipdstportrange 5060 -openViaPinhole ENABLED -openRecordRoutePinhole ENABLED –sipTransportProtocol TCP
Done
add lsn sipalgprofile sipalgprofile_udp -sipdstportrange 5060 -openViaPinhole ENABLED -openRecordRoutePinhole ENABLED -sipTransportProtocol UDP
Done
add lsn group g1 -clientname c1 -sipalg ENABLED
Done
bind lsn group g1 -poolname p1
Done
bind lsn group g1 -appsprofilename app_tcp
Done
bind lsn group g1 -appsprofilename app_udp
Done
bind lsn group g1 -sipalgprofilename sipalgprofile_tcp
Done
bind lsn group g1 -sipalgprofilename sipalgprofile_udp
Done