IP AddressingVLAN Separation
Using specific IP addressing and VLAN separation is a weak security technique to limit access to the voice network from other areas of the campus network or from outside. By using IP addresses that you do not advertise or route to the outside, you can limit the chances of having your IPT devices attacked. RFC 1918 addresses are an obvious choice for such addressing. These nonroutable addresses can be put on a set of dedicated VLANs used only for the IPT network.
This security benefit does have some merit because you are essentially quarantining the IPT system as discussed in Chapter 8. The issue comes down to the accessibility of this quarantined network. Because an entire organization usually takes advantage of IPT, this means that the VLANs and IP addresses used for IPT must be reachable by almost everyone. Although most users will not harm the network, it wouldn't be difficult for an individual with access to both networks (data and voice) to launch attacks.
This is compounded by PC-based phone software. Although an IPT network can use dedicated IP phones, it can also use a software-based IP phone running on a user's desktop. This application offers significant mobility advantages for the user, so it will likely be a desirable feature. Because the PC resides on the "data" side of the network, it must reach the voice network, which becomes a conduit for attack and flooding.
The best benefit of the separation is the capability of easily filtering the IPT network at security choke points (see Chapter 12, "Designing Your Security System"). Because all the dedicated IPT devices use the same IP ranges, you can filter these addresses or choose not to advertise them to certain areas of your network or the outside.
Although this separation doesn't offer a strong security benefit, it is useful to accomplish other networking objectives. The main benefit is that quality of service (QoS) features can easily be applied to the VLAN used by the IPT network.
As IP phones advance, they will start to perform more of the functions of a PC, and likewise, PCs are starting to take on more of the characteristics of IP phones. As a result, this kind of separation is reasonable only in the short term, but for many organizations it is providing some benefit as they wait for vendors to implement cryptographic protections for phone conversations.
Continue reading here: Note Kgv
Was this article helpful?