Enabling Aes Encryption - Polycom HDX 4000 Series Administrator's Manual

Hide thumbs Also See for HDX 4000 Series:
Table of Contents

Advertisement

Administrator's Guide for Polycom HDX Systems

Enabling AES Encryption

8–20
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
AES encryption is a standard feature on all Polycom HDX systems. When it is
enabled, the system automatically encrypts calls to other systems that have
AES encryption enabled.
If encryption is enabled on the system, a locked padlock icon appears on the
monitor when a call is encrypted. If a call is unencrypted, an unlocked padlock
appears on the monitor. In a multipoint call, some connections might be
encrypted while others are not. The padlock icon might not accurately indicate
whether the call is encrypted if the call is cascaded or includes an audio-only
endpoint. To avoid security risks, Polycom recommends that all participants
communicate the state of their padlock icon verbally at the beginning of a call.
Points to note about AES Encryption:
AES Encryption is not supported in Diagnostic Mode.
AES Encryption is not supported on systems registered to an Avaya H.323
gatekeeper.
For Polycom HDX systems with a maximum speed of 6 Mbps for unencrypted
calls, the maximum speed for encrypted SIP calls is 4 Mbps. The maximum
speed for encrypted calls with Security Mode enabled is also 4 Mbps.
HDX systems provide the following AES cryptographic algorithms to ensure
flexibility when negotiating secure media transport:
H.323 (per H.235.6)
— AES-CBC-128 / DH-1024
— AES-CBC-256 / DH-2048
SIP (per RFCs 3711, 4568, 6188)
— AES_CM_128_HMAC_SHA1_80
— AES_CM_256_HMAC_SHA1_80
HDX systems also support the use of FIPS 140 validated cryptography, which
is required in some instances, such as when used by the U.S. federal
government. When the Security Mode setting is enabled, all cryptography
used on the system comes from a software module that has been validated to
FIPS 140-2 standards. You can find its FIPS 140-2 validation certificate here:
http://csrc.nist.gov/groups/STM/cmvp/documents/140‐1/140val‐all.htm#17
.
47
To enable AES encryption:
Do one of the following:
1
— In the local interface, go to System > Admin Settings > General >
Security > Security Settings (select
if necessary).
Polycom, Inc.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents