The Cisco® XR 12000 is the first carrier router to offer integrated session border control (SBC) functions. The Cisco XR 12000 Session Border Controller builds on the secure virtualization, continuous system operation, and multiservice scale provided by the market-leading Cisco XR 12000 Series. With the integration of session border control functions into Layer 2 and Layer 3 services provided by the Cisco XR 12000 Series, the Cisco XR 12000 Session Border Controller eliminates the need for overlay networks and standalone appliances. The Cisco XR 12000 Session Border Controller provides an open and flexible architecture for all service provider deployments, whether for peering or for customer access. With its ability to handle unified and distributed signaling deployments, the Cisco XR 12000 Session Border Controller provides superior deployment flexibility to cable, wireline, and wireless service providers. A key element of the Cisco Service Exchange Framework (SEF) which supports IP Multimedia Subsystem (IMS) and non-IMS services, the Cisco XR 12000 Session Border Controller further accelerates network convergence while providing investment protection for the Cisco 12000 Series.
Product and Application Overview
Session border controllers control and manage real-time multimedia traffic flows between IP network borders, handling signaling and media. As part of this job, they perform native IP interconnection functions required for real-time communications such as access control, firewall traversal, bandwidth policing, accounting, signaling interworking, legal intercept, and quality-of-service (QoS) management. With its comprehensive suite of features and high-availability hardware and software, the Cisco XR 12000 Series helps enable a broad range of session border control applications for cable, wireline, and wireless service providers. The Cisco XR 12000 Session Border Controller application incorporates the security, QoS, and secure virtualization capabilities of the Cisco XR 12000 Series to enable support for service provider-to-service provider interconnect and service provider-to-access interconnect for voice over IP (VoIP) and video services.
The Cisco XR 12000 Session Border Controller application takes advantage of the advanced hardware processing capabilities of the Cisco XR 12000 Multi-Service Blade to provide a flexible, scalable, and feature-rich implementation (Figure 1). The integration of Session Border Controller into the Cisco XR 12000 Series routers facilitates the deployment of advanced services that require a combination of Layer 2 and Layer 3 functions (QoS, Security, VPN interconnect, etc ) and session border control functions. The modularity of the Cisco XR 12000 Session Border Controller application and of Cisco IOS® XR Software enables operators to load, configure, turn on, and turn off session border control functions with zero impact to any other control and data plane traffic on the same router. Operators can also partition the Cisco XR 12000 Session Border Controller functions into various logical and virtual routers that can be configured on the Cisco XR 12000 Series Routers.
Figure 1. Cisco XR 12000 Multi-Service Blade
Service Provider-to-Service Provider Interconnect
With the increasing deployment of end-to-end VoIP and IP video, service providers are looking to interconnect directly with IP and minimize time-division multiplexing (TDM)-based handoff to other service provider networks. Direct IP interconnect helps minimize operational and capital expenditures by eliminating back-to-back TDM gateways; it also increases media quality and helps ensure transparency of IP-based services across network borders. The Cisco XR 12000 Session Border Controller provides the following critical functions required for direct IP interconnect without introducing any additional network elements:
• Protocol and media interworking
• Session routing
• Admission control and policing
• Quality monitoring and enforcement
• Media and Signaling Security and Network Address Translation (NAT) mechanisms
• Authentication, authorization, and accounting (AAA)
• Facilitating media transcoding with an external media server
Service Provider-to-Access Interconnect
With the rapid growth in IP telephony and other real-time services such as IP video, service providers are deploying session border control appliances at the provider edge to manage VoIP traffic in different scenarios, including IP-PBX-to-service provider peering, VPN interworking (with multiple sites for the same customer and multiple customers), and enterprise-to-hosted IP telephony interworking, as well as the fast-growing residential IP telephony. The Cisco XR 12000 Session Border Controller builds on Cisco Layer 2 and Layer 3 services and integrates the session border control function by providing the following features:
• Protocol and media interworking
• Session routing
• Hosted NAT and firewall traversal
• Security and AAA
• Intra- and inter-VPN interconnect/optimization
• Facilitating media transcoding with an external media server
For both the service provider-to-service provider and service provider-to-access applications, the innovative architecture of the Cisco XR 12000 Session Border Controller gives a choice of unified or distributed signaling deployment (Figure 2). In the unified deployment model, the Cisco XR 12000 Session Border Controller hosts both media-related and signaling-related functions. In the distributed deployment model, the Cisco XR 12000 Session Border Controller hosts the media-related functions and communicates with an external signaling function over an industry-standard interface based on the H.248 protocol. Cisco's Session Border Controller design allows for either deployment model, using the same hardware and software.
Figure 2. Unified and Distributed Models
Product Highlights
Highest performance and scalability - With 10 Gbps processing capacity for each Cisco XR 12000 Multi-Service Blade, the Cisco XR 12000 Session Border Controller can scale to more than 200,000 simultaneous sessions on a single chassis. With its high-throughput interface into the Cisco XR 12000 switching fabric, the session border controller is designed to not only scale for VoIP sessions but also to support high-bandwidth video sessions.
High availability - The advanced high-availability design of the Cisco XR 12000 Session Border Controller and Cisco XR 12000 Series Routers provides the maximum service availability required for real-time sessions such as VoIP and video. Availability features include:
• No single point of failure
• Ability to load the session border control application independent of other services or traffic on the router
• Active/Standby configuration with active session preservation upon switchovers
• In-service software/maintenance updates
Industry-standard protocols and interfaces - The Cisco XR 12000 Session Border Controller incorporates support for industry-standard protocols for VoIP and video, including Session Initiation Protocol (SIP) and H.323. The Cisco XR 12000 Session Border Controller offers broad support for various SIP- and H.323-based services traversing it. In addition, the Cisco XR 12000 Session Border Controller supports the TISPAN Ia interface, which is based on the H.248 protocol and enables a distributed implementation of session border control signaling and media flow.
Maximum flexibility - The native implementation of session border control on the Cisco XR 12000 Series provides a host of additional capabilities that are not possible with standalone session border control appliances. Service providers can now combine the Layer 2 and Layer 3 services offering with the session border control functions to not only derive the benefits of network convergence, but to also add unique services. Session border control functions can now be applied at a more granular VPN level. Business VPN services can now be combined with business voice and video services. Similarly, network-based security services such as IP Security (IPsec) and firewall can be combined with session border control functions.
Table 1 lists the features of the Cisco XR 12000 Session Border Controller.
Table 1. Feature Summary
Feature
Description
Flexible deployment models
• Unified deployment model: Signaling and media functions are hosted on the Cisco XR 12000 Multi-Service Blade
• Distributed deployment model: Media functions are hosted on the Cisco XR 12000 Multi-Service Blade; a service control interface based on TISPAN Ia interface (H.248) is provided
Redundancy model
• 1:1 Active/Standby model with stateful switchovers in less than 1 sec
SIP support
• Broad support for various SIP-based services; support for RFC 3261, RFC 3262, RFC 2976, RFC 3311, and RFC 3326
H.323
• Fast start, slow start, carrier-ID-based routing, and tech prefixes
Hosted NAT/firewall traversal
• Supports all NAPT traversal schemes and full set of Network Address and Port Address Translations (NAT/PAT). Supports firewall traversal
• Software and hardware support for VoIP-specific malicious attacks complements the security features of the Cisco XR 12000 Series
• Dynamic "whitelisting and blacklisting" with hardware-based detection for attacks in the media plane (RTP/RTCP) and in the signaling plane (SIP, H.323)
Authentication of endpoints
• Performs endpoint authentication by passing authentication messages to a third-party (RADIUS) server using digest authentication
Signaling encryption
• Supports the termination of IPsec and Transport Layer Security (TLS)-encrypted signaling arriving at the session border controller
Bearer interworking
• Native DTMF interworking (RFC 2833 to SIP user info) and the ability to route calls to external media servers for transcoding
VPN interconnect/optimization
• Layer 3 VPN-aware; can provide interconnect and security for sessions between two different VPNs with overlapping address spaces
• Can optimize media flow for sessions on the same VPN
Session routing
• Fully configurable session routing engine integrated into the session border controller
Admission control
• Comprehensive set of functions for admission control
• Connection Admission Control per session, per endpoint, per dialed number, per peer/adjacency, and per VPN to control maximum concurrent sessions, maximum bandwidth, maximum call setup rate, and codec restrictions
Billing records
• Detailed session detail records with either onboard storage in XML format or RADIUS-based billing records
Ordering Information
Table 2 gives ordering information for the Cisco XR 12000 Session Border Controller.
Table 2. Ordering Information
Product Description
Part Number
XR 12000 Multi-Service Blade
XR-12K-MSB
XR 12000 Session Border Control Application RTU
XR-12K-SBC-RTU
XR 12000 Session Border Control H.248 License
XR-12K-SBC-H248
XR 12000 Session Border Control SIP License
XR-12K-SBC-SIP
XR 12000 Session Border Control H.323 License
XR-12K-SBC-H323
Service and Support
Cisco has earned high customer satisfaction ratings for its wide range of support offerings for service providers. Whether the goal is speed to market, maximizing network availability, or enhancing customer satisfaction and retention, Cisco is committed to the success of service providers.