Voice and video in the extranet for employees without VPN

This IBM Sametime® deployment enables you to provide employees Internet access to Sametime services, including voice and video, without a VPN.

The graphic that follows shows a deployment that enables you to provide employees Internet access to Sametime services, including voice and video, without a VPN. You deploy Sametime edge services into the DMZ to enable secure access to Sametime services. The IBM® SIP Edge Proxy Server connects external clients to the Sametime SIP Proxy/Registrar. Both external and internal clients receive a host name for the SIP Proxy/Registrar. For internal clients, this host name should resolve to the IP address of the SIP Proxy/Registrar that is deployed in the corporate intranet, enabling internal clients to connect directly. For external clients, the host name should resolve to the IP address of the IBM SIP Edge Proxy Server deployed in the DMZ. Use an HTTP Reverse Proxy Server or a split-horizon DNS to provide different sets of DNS information to clients based on the source address of the DNS request

Components required:
  • SIP Edge Proxy Server
  • Sametime TURN Server
  • HTTP Reverse Proxy Server
  • Sametime Media Manager (behind firewall, if not already deployed)

Graphic showing a HTTP Reverse Proxy Server, TURN Server, SIP Edge Server deployed in the DMZ.