Matt Brunk
Matt Brunk has worked in past roles as director of IT for a multisite health care firm; president of Telecomworx,...
Read Full Bio >>

Matt Brunk | March 24, 2017 |


Do I Need an SBC or Firewall?

Do I Need an SBC or Firewall? Make sure you consider this question as part of your SIP deployment plan.

Make sure you consider this question as part of your SIP deployment plan.

The question of session border controller (SBC) or firewall is one that many IT managers find annoying. Why? First and foremost, isn't the new era of communications supposed to be better, faster, cheaper, and easier to use?

The transition to IP and adoption of SIP hasn't been easy for many businesses. The root causes stem from reluctance to change, remorse over having changed over to hosted or premises-based SIP solutions, and disdain for the technology. Key issues in adoption range from poor implementation practices, improper configurations, and unrealistic expectations.

Whether firewalls are or are not SIP-aware doesn't absolve service providers from responsibility. The real gap is enforcement, since having to invest in new or additional infrastructure will scare some customers away. Which providers mandate that customers use either a session border controller (SBC) and or SIP/UC-aware firewall for their voice or UC deployments? While some do, many don't -- and hence contribute to the unnecessary churn rate that occurs. According to some providers, half of the churn is due to business failures (not that this excuses the other half, which are due to misgivings over the services delivered).

Service providers can point to customer premises issues, as they so often did back in the Bell System days. While this remains an issue, overall -- yes, definitively -- service has improved as have the opportunities (benefits and enhancements). Still, our industry cannot remain static; providers must continue to improve service since the reality of convergence is no longer in question. Singular silos and islands will not fare well in the coming age of software-defined networking (SDN) and network functions virtualization (NFV). In part, SDN/NFV will become the answer to my initial question (as the norm).

As stated in recent documentation from firewall vendor SonicWall:

    "To overcome many of the hurdles introduced by the complexities of VoIP and NAT, vendors are offering Session Border Controllers (SBCs). An SBC sits on the Internet side of a firewall and attempts to control the border of a VoIP network by terminating and re-originating all VoIP media and signaling traffic. In essence, SBCs act as a proxy for VoIP traffic for non-VoIP enabled firewalls. Dell SonicWALL network security appliances are VoIP enabled firewalls that eliminate the need for an SBC on your network."

When it comes to using a firewall capable of supporting SIP trunks, there is an element of effort and due diligence that goes into properly configuring any appliance or service. My intention isn't to debate the technologies, but rather relate the management issues that businesses face and think about how to get them over the proverbial hump.

This is where expectations fall into the discussion -- as in, many businesses do not expect having to make additional investments after their initial IP/SIP deployments. While service providers might present these as, "Oh, by the way," to customers that translates to, "I didn't know."

Can firewalls support SIP and UC? The first key area to look into in answering this is traffic: by volume and application type. Does the appliance have enough processing power to handle all traffic without introducing impactful latency? Is the firewall licensed in such a way that there aren't any operational deficiencies? Does the appliance interoperate with other infrastructure elements as required in your implementation? How much would it cost to use both an SBC and a firewall vs. only using a firewall? And, again, will the standalone firewall meet all needs or will it be deficient in an area that could either be service impacting or leave holes in security?

Communications service providers anticipate that virtual CPE deployments will garner cost benefits and substantial return on investments over three or four years. Until then, many businesses will face market pressures to move to an IP solution that meets their firm's communications needs. Not all perceive that UC is a value-add, and not all think that an all-IP network is reality. Even so, businesses need to still communicate and their solutions must be effective.

Service providers that are proactive and drive the configurations, including premises requirements, will retain customers and improve customer experience. Those that continue to act as if in the The Wild Wild West show will continue to churn customers and damage the industry through negative perceptions about IP/SIP and UC.


April 19, 2017

Now more than ever, enterprise contact centers have a unique opportunity to lead the way towards complete, digital transformation. Moving your contact center to the cloud is a starting point, quick

April 5, 2017

Its no secret that the cloud offers significant benefits to enterprises - including cost reduction, scalability, higher efficiency, and more flexibility. If your phone system and contact center are

March 22, 2017

As today's competitive business environments push workforces into overdrive, many enterprises are seeking ways of streamlining workflows while optimizing productivity, business agility, and speed.

April 20, 2017
Robin Gareiss, president of Nemertes Research, shares insight gleaned from the firm's 12th annual UCC Total Cost of Operations study.
March 23, 2017
Tim Banting, of Current Analysis, gives us a peek into what the next three years will bring in advance of his Enterprise Connect session exploring the question: Will there be a new model for enterpris....
March 15, 2017
Andrew Prokop, communications evangelist with Arrow Systems Integration, discusses the evolving role of the all-important session border controller.
March 9, 2017
Organizer Alan Quayle gives us the lowdown on programmable communications and all you need to know about participating in this pre-Enterprise Connect hackathon.
March 3, 2017
From protecting against new vulnerabilities to keeping security assessments up to date, security consultant Mark Collier shares tips on how best to protect your UC systems.
February 24, 2017
UC analyst Blair Pleasant sorts through the myriad cloud architectural models underlying UCaaS and CCaaS offerings, and explains why knowing the differences matter.
February 17, 2017
From the most basics of basics to the hidden gotchas, UC consultant Melissa Swartz helps demystify the complex world of SIP trunking.
February 7, 2017
UC&C consultant Kevin Kieller, a partner at enableUC, shares pointers for making the right architectural choices for your Skype for Business deployment.
February 1, 2017
Elka Popova, a Frost & Sullivan program director, shares a status report on the UCaaS market today and offers her perspective on what large enterprises need before committing to UC in the cloud.
January 26, 2017
Andrew Davis, co-founder of Wainhouse Research and chair of the Video track at Enterprise Connect 2017, sorts through the myriad cloud video service options and shares how to tell if your choice is en....
January 23, 2017
Sheila McGee-Smith, Contact Center/Customer Experience track chair for Enterprise Connect 2017, tells us what we need to know about the role cloud software is playing in contact centers today.