Am Montag, 20. August 2018, 13:22:30 CEST schrieb Kevin Olbrich:
I browsed the files but was unable to find one using Kamailio as SBC without exposing the Asterisk core.
Most examples indeed expose the node and let media flow directly ( https://www.kamailio.org/events/2017-KamailioWorld/Day1/08-David.Casem-Build ing-A-Global-VoIP-Network.pdf - interesting solution with e/iBGP which we would also be able to deploy).
There was just a single presentation that I was able to locate that had the proxy only on the edge: https://www.kamailio.org/events/2017-KamailioWorld/Day2/15-Sebasitan.Damm-An ti-Fraud-With-HTables.pdf At least it looks like they are located behind the SBC.
After the research my impression is, that co-locating the B2BUA with the Edge-Proxy and firewall-ing it, seems best practice. We will try to add some security by bridge-firewalling and BGP.
If anyone has a hint for a presentation with high-security edge-proxy, I would appreciate it. Thank you. [..]
Hi Kevin,
here you find a (older) presentation about a setup with private asterisk and kamailio as network edge. This is the one that we build back in the days at 1&1, slide 19 has a schematic diagram of the setup:
https://skalatan.de/archive/presentations/kamailio-world-2013-presentation.p...
Best regards,
Henning