SBC Behind a Firewall
Hi guys!
One of our customers is evaluating wether or not to put its SBC behind a FW.
They want to set the public interfaces of their HA pair inside a DMZ of a perimetral firewall.
What they are trying to acomplish is to make a test configuration using non-production interfaces (putting them behind de FW), afterwards switch the change to the production interfaces.
I don''t see this very appropiate since the SBC is like the firewall of the sip network and it doesn''t need another firewall in front of it. Moreover, I think this is a very unusual scenario and will not only result in problems with RTP, but also will have problems with signalling.