Fortigate SIP ALG vs dedicated SBC
Our company wants to migrate our Shoretel phone system from ISDN to SIP trunks, our supplier is pushing us to implement an ingate siparator, of course it does because it adds £10,000 to the project cost!
From what I can see, our Fortigate 300D appliances will be perfectly capable to cover this requirement, the SIP ALG componant will manage all the NAT traversal issues and traffic inspection / IPS on the Fortigate coveres known security issues, added to the fact that in the policy I will only allow traffic to SIP providers datacentre (this is not to be used for our remote clients), I do not see where the possible risk could be. Seeing as both sides of the trunk will be using IP based registration, is there any real risk of hijacking?
From a performance point of view I have zero concerns, I have 300D units (mentioned above) that average 5% cpu and 50% memory usage, I also eliminate a SPOF with the single siparator as the Fortigate units are all active / passive HA.
Is there any real benifit to for me to spend the extra £10,000 on the ingate siparator?