Media Delivery DMZ

Media Delivery DMZ

Secure Internet Edge for an IP TV streaming special interest channel.

With BEUL to a streaming infrastructure with high reliability

A medium-sized media company needed support in designing and building a streaming infrastructure that would prepare and process TV satellite data and make it available securely via the Internet. The aim was to provide a European special interest channel in Germany.

For this purpose, the existing server and encoder systems should be connected to a newly created internet edge. A two-stage DMZ (De-Militarized Zone) was implemented using Cisco Integrated Services Routers and Palo Alto Firewalls, which allows granular control of access and communication. The reliability was addressed by redundant gateways, failover mechanisms and ISP dual homing.

All systems have been intensively hardened and protected against security incidents. A QoS (Quality of Service) set of rules was also defined to ensure the quality of the real-time data transmitted from the streaming network.

BEUL accompanied the customer in developing the new business area of digital services and supported him in the planning, implementation and test of the solution. We developed an operations manual for professional support and maintenance of the environment including patch and software management.

Motivation

  • Development of a digital service (IP TV streaming offer) by the customer
  • Provision via the Internet must be highly available and secured in terms of information technology

Challenges

  • Controlled policy routing for dual-homed internet connectivity
  • Advanced set of rules for NAT and firewall systems
  • Integration of encoders in QoS mechanisms

Technologies

images/technologien/astra.png
images/technologien/cisco.png
images/technologien/paloalto.png

The project in figures

1
Shared rack in the data center
2
Astra IP Encoder
2
Redundant standby gateways
12
Service and management VMs
150
NAT and firewall rules
60.000
Viewers monthly